Executive Overview
Navigating the modern internet is an exercise in invisible surveillance. Every website visit and mobile app interaction triggers a silent, complex auction where user data is harvested, packaged, and monetized by an opaque network of advertising platforms, brokers, and intermediaries. While much of this transactional infrastructure is technically semi-public, it has historically remained locked behind walled gardens or buried within unstructured text files, far out of reach for the average web user and poorly understood even by cybersecurity professionals.
That dynamic is shifting dramatically with the launch of DecryptAds, a powerful, free investigative service designed to scrape, correlate, and demystify the vast data ecosystems underpinning digital advertising. Co-founded by Infoblox threat researcher and chief research officer Zach Edwards alongside a team of privacy advocates, DecryptAds bridges the long-standing gap between adtech and cybersecurity.
By systematically analyzing foundational transparency files—such as ads.txt, app-ads.txt, and sellers.json—the platform provides an unprecedented lens into the digital supply chain. It equips security teams, privacy advocates, and investigators with the tools needed to expose hidden data brokers, flag geo-political risk factors, track malicious "malvertising" campaigns, and uncover the sprawling networks of AI-generated content farms that plague the contemporary web.
Detailed Chronology of the Adtech Transparency Crisis
To understand why DecryptAds represents a watershed moment for digital privacy, one must look at how the adtech ecosystem evolved and why its oversight mechanisms failed.
The Rise of Programmatic Advertising and Transparency Files
For over a decade, digital advertising shifted from direct publisher-advertiser negotiations to automated programmatic auctions. While this model scaled monetization, it also introduced massive fraud vectors, domain spoofing, and unauthorized ad reselling. In response, the Interactive Advertising Bureau (IAB) introduced ads.txt (Authorized Digital Sellers) in 2017, followed by app-ads.txt for mobile and connected TV (CTV) applications, and eventually sellers.json to map out intermediaries.
These initiatives were designed to let publishers declare who is authorized to sell their ad inventory. In theory, an advertiser could check a site’s ads.txt file to verify legitimacy. In practice, however, these files grew exponentially into bloated, unmanageable lists containing hundreds or even thousands of entries. Because they existed as isolated text files across millions of domains, cross-referencing them manually was practically impossible. Bad actors quickly realized that nobody was policing these disclosures.

The Emergence of DecryptAds
Recognizing that supply-chain integrity issues rarely manifest within a single, isolated file, Edwards and his co-founders built DecryptAds to continuously ingest, parse, and correlate these declarations at scale. Launched to address chronically underserved security and privacy use cases, the platform transforms raw programmatic breadcrumbs into actionable intelligence dossiers.
Rather than viewing adtech through a purely commercial lens, DecryptAds approaches it from an adversarial perspective. The platform exposes structural anomalies—such as broken cross-references between ads.txt and sellers.json, cloned declaration sets across completely unrelated domains, and systemic quiet removals—transforming hidden digital plumbing into transparent, searchable data paths.
Supporting Context, Metrics, and Technical Analysis
The practical applications of DecryptAds reveal a staggering web of international risk, data brokerage, and programmatic conflicts of interest across some of the world’s most popular digital destinations.
The ESPN Ecosystem: Data Brokers and Geolocation Tracking
A baseline query for mainstream properties highlights the sheer volume of hidden partners embedded in standard web traffic. A search for the sports network espn.com reveals 143 ad partners and 19 registered data broker domains declared within its ads.txt and app-ads.txt files.
Recent state-level privacy legislation in California, Oregon, Texas, and Vermont has forced data brokers to register if they buy or sell consumer data originating from those states. Leveraging this emerging transparency, DecryptAds reports that nearly half of ESPN’s listed data brokers actively collect precise geolocation data from visitors who do not employ ad-blocking software. Furthermore, multiple brokers explicitly disclose the collection of device fingerprints and sensitive personal information, illustrating how passive media consumption feeds the broader data-broker economy.
Geopolitical Risk and Sanctions Evasion
One of DecryptAds’ most critical features is its automated flagging of "geo-risk" entities—advertising firms operating out of jurisdictions like Russia, China, or countries with close financial and political alignments to them, such as Cyprus and the United Arab Emirates (UAE).

- The Case of Between Digital: DecryptAds flags several advertising entities connected to espn.com that trace back to high-risk jurisdictions, including Between Digital. While the firm lists a formal corporate address in New York, DecryptAds’ deep dossier reveals it to be a Russian enterprise. Its publisher financial offers route directly through Alfa Bank, Russia’s largest private commercial bank, which was placed under sweeping U.S. sanctions following the 2022 invasion of Ukraine.
- U.S. Military Websites: Security audits extending across major U.S. military-focused news portals—including
armytimes.com,airforcetimes.com,defensenews.com,navytimes.com,marinecorpstimes.com, andfederaltimes.com—demonstrate that these trusted defense publications similarly permit Between Digital, alongside entities in the UAE and the corporate secrecy haven of Panama, to serve ads and track military-adjacent users. According to platform data, Between Digital currently collects advertising telemetry across approximately 55,000 partner websites.
Moreover, examining Between Digital’s app-ads.txt portfolio uncovers hundreds of lightweight web-based mobile games. Edwards notes that Between Digital acts as both a publisher and a reseller on roughly two-thirds of its own portfolio, playing both sides of the bidding equation. This structural overlap creates glaring conflicts of interest, allowing ad networks to preferentially route client ad spend toward owned-and-operated infrastructure.
The Opera Browser and International Reach
The Opera web browser, despite maintaining its operational headquarters in Oslo, Norway, has been majority-owned and controlled by the Chinese firm Kunlun Tech since 2016. A DecryptAds profile of opera.com exposes 27 registered data brokers, featuring 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine—representing just seven percent of the total adtech partners declared in the browser’s ecosystem files.
Official Statements and Investigative Insights
Industry experts emphasize that the adtech industry’s lack of centralized policing has allowed bad actors to operate with impunity, hiding behind opaque corporate structures and silent administrative changes.
The Threat of "Quiet Removals"
When ad networks suspect a partner of generating fraudulent, unauthentic clicks or serving malicious ads, standard industry protocol often involves quietly purging the offender from sellers.json files without public notification.
"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," explains Zach Edwards. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."
To counteract this information vacuum, DecryptAds features a Quiet Removals Feed, aggregating and correlating seller deletions across multiple ad exchanges to unmask bad actors who attempt to scrub their reputations silently.

Malvertising, Smart TV Streaming Sticks, and AI "Slop"
Recent joint investigations—such as those by security firm Bitsight into popular H96 TV streaming sticks—demonstrated that compromised consumer hardware was quietly renting out internet connections and spoofing mobile phones to click on ads across automated, AI-generated content farms ("slop websites").
These AI-generated content networks—which churn out low-quality, machine-written articles on home improvement, recipes, and consumer tech—rarely invest in enterprise-grade brand safety or ad-verification tools. Instead, they act as greased rails for malvertising, serving malicious payloads, phishing redirects, and zero-click exploits directly to unsuspecting users who stumble upon them via search engines.
Edwards warns that traditional security measures often fail because organizations look in the wrong places:
"A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis."
Future Outlook: Remediation and Defense Strategies
Fixing the systemic rot within programmatic advertising will require deeper cooperation and data-sharing from major ad tech conglomerates. Specifically, industry reformers argue that platforms must broadly expose the Supply Chain Object (SCO)—structured metadata attached to server-side bid requests that details every intermediary, reseller, and ultimate buyer involved in an ad transaction. Without visibility into the SCO, tracing the origin of a malvertising payload remains an uphill battle.
In the interim, security professionals and privacy advocates agree that individual users and corporate defenders must take proactive steps to mitigate risk.

Practical Defensive Measures
-
Global Ad and Tracker Blocking:
- Desktop Browsers: Utilizing robust, open-source extensions like uBlock Origin Lite remains one of the most effective methods to starve data brokers of telemetry and prevent malvertising delivery.
- Mobile Browsers: Firefox on Android supports advanced extension architectures, while iOS users can rely on utilities like Adblock Plus or leverage custom blocking lists from repositories like easylist.to.
- Script Control: Power users may employ tools like NoScript to restrict unapproved JavaScript execution, though this requires ongoing manual curation.
-
Network-Level Defense (Pi-hole):
For technically proficient users, deploying a low-cost Raspberry Pi running Pi-hole creates a centralized DNS sinkhole. By routing local network traffic through a Pi-hole, households and small offices can block ads and tracking domains across every connected device—including smart TVs and IoT appliances—at the hardware level. -
Skepticism Toward Mobile Apps:
Major web destinations increasingly pressure users to install dedicated mobile apps under the guise of an "improved user experience." In reality, these applications serve as frictionless pipelines for continuous behavioral surveillance, precise geolocation harvesting, and automated opt-ins for generative AI training sets. Whenever possible, security-conscious users should interact with web services directly through a hardened browser rather than installing proprietary mobile applications.
By democratizing access to programmatic supply chain data, tools like DecryptAds are shifting the balance of power, transforming opaque adtech black boxes into transparent maps that expose who is tracking you, where your data is flowing, and who profits from the digital shadows.
