Navigating the modern digital landscape has become an increasingly hazardous endeavor. Every click, scroll, and tap is monitored, analyzed, and monetized by an opaque network of advertising technology (adtech) companies and data brokers. For years, the foundational architecture of this multi-billion-dollar surveillance economy has remained hidden behind walled gardens, deliberately obscure naming conventions, and fragmented data files. Consumers and security professionals alike have long struggled to answer a fundamental question: Who is actually tracking us, and where is our data going?
Enter DecryptAds, a powerful, free, and publicly accessible intelligence service engineered to bring radical transparency to the dark corners of the advertising ecosystem. Launched to bridge a massive gap in cybersecurity and data privacy, DecryptAds continuously scrapes, indexes, and cross-references the public-facing files that websites and mobile applications use to declare their commercial relationships.
By analyzing interconnected datasets—including ads.txt, app-ads.txt, and buyers.json/sellers.json files—DecryptAds exposes complex supply-chain webs, highlights high-risk international entities based in geopolitical flashpoints, uncovers quiet punitive removals by major ad exchanges, and charts the explosive growth of artificial intelligence-generated "slop" websites. In an era where digital threats are increasingly weaponized via programmatic advertising, tools like DecryptAds are transforming how privacy advocates, threat hunters, and enterprise security teams map and neutralize supply-chain risks.
Detailed Chronology & Mechanics of Ad Transparency
To understand the scale of the problem DecryptAds was built to solve, one must first examine the decentralized documents that govern the programmatic advertising market. Historically, web publishers and app developers used ad-declaration files primarily for revenue protection—ensuring that programmatic buyers could verify they were purchasing authentic ad inventory from legitimate sellers rather than spoofed domains. However, security researchers have recognized that these very same files serve as an exhaustive blueprint of corporate surveillance capitalism.
The Anatomy of Adtech Disclosures
DecryptAds automates the collection and synthesis of three critical, publicly available file types:
ads.txt (Authorized Digital Sellers): Maintained on web servers, this text file lists every adtech company, intermediary, and data broker authorized to sell or monetize a specific website’s ad inventory.
app-ads.txt: The mobile and smart-TV counterpart to ads.txt, designed to eliminate domain-spoofing and unauthorized inventory reselling within application ecosystems.
buyers.json and sellers.json: Standardized JSON endpoints published by supply-side platforms (SSPs) and ad exchanges that disclose the real identities, business names, and identifiers of the entities buying, selling, or reselling ad space across the global market.
Individually, these files are dense, unwieldy, and largely impenetrable to the untrained eye. Furthermore, threat actors and unscrupulous ad networks frequently manipulate them. As the project’s documentation notes, supply-chain integrity issues rarely announce themselves neatly in a single file; instead, they manifest as broken cross-references, cloned declaration sets across unrelated domains, and phantom supply paths that appear in server-side bid logs without ever being authorized by the publisher.
The Genesis of DecryptAds
Recognizing these systemic blind spots, Zach Edwards—Chief Research Officer for DecryptAds and a prominent threat researcher at security firm Infoblox—teamed up with two co-founders to build a centralized intelligence engine.
"It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards explains. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."
By cross-referencing these data streams, DecryptAds allows analysts to pivot from a single suspicious website to a sprawling transnational network of data brokers, shell companies, and high-risk foreign entities in a matter of seconds.
Supporting Context & Metrics: Unpacking the Data
The depth of insight provided by DecryptAds is starkly illustrated when applied to mainstream web properties and high-profile targets. Far from being isolated entities, major digital platforms are deeply entangled with massive webs of tracking intermediaries.
The ESPN Case Study
A search within DecryptAds for the major sports network espn.com reveals a startling baseline: its ads.txt and app-ads.txt files declare relationships with 143 distinct ad partners and 19 registered data broker domains.
This granular visibility is increasingly attainable due to a shifting regulatory landscape. Four U.S. states—California, Oregon, Texas, and Vermont—have recently enacted legislation mandating that data brokers publicly register if they purchase or sell consumer data originating within their borders. By cross-referencing these registrations with adtech disclosures, DecryptAds discovered that nearly 50% of ESPN’s listed data brokers collect precise geolocation data from visitors who do not utilize ad blockers. An additional subset openly discloses the harvesting of device fingerprints and sensitive personal attributes.
Geopolitical Risk and Sanctioned Entities
One of DecryptAds’ most critical functions is its Geo-Risk classification engine. The platform automatically flags advertising firms headquartered in high-risk jurisdictions—most notably Russia and China—as well as offshore financial and political hubs with deep ties to those nations, such as Cyprus and the United Arab Emirates (UAE).
The platform’s deep-dive dossiers frequently unearth troubling corporate alignments. For example, DecryptAds flags Between Digital, an adtech firm listing a corporate address in New York City, as fundamentally Russian-operated. Historical documentation shows that Between Digital processes publisher payouts through Alfa Bank, Russia’s largest private commercial bank, which was placed under sweeping U.S. financial sanctions following the 2022 invasion of Ukraine.
Despite these ties, DecryptAds reveals that Between Digital’s tracking and ad-serving infrastructure is embedded across approximately 55,000 partner websites, including prominent U.S. military news portals such as armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com.
Moreover, querying Between Digital’s app-ads.txt footprints uncovers hundreds of low-quality, ad-supported mobile minigames. Edwards points out that Between Digital frequently lists itself as both a publisher and a reseller on roughly two-thirds of its portfolio:
"It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest."
Similar opaque webs surround major software products. The popular Opera web browser, which has been majority-owned by Chinese firm Kunlun Tech since 2016 while maintaining operational headquarters in Oslo, Norway, features an opera.com profile on DecryptAds listing 27 registered data brokers. These include 15 partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine—representing just 7% of the total adtech partners declared in its supply files.
Legal Dossiers and the "AI Slop" Ecosystem
Another powerful feature of the platform is its Legal Dossier lookup, which aggregates domain registration histories, historical ownership aliases, and cross-platform relationships. This capability has proven vital in tracking the convergence of hardware exploits, malicious mobile apps, and programmatic fraud.
Recent investigations by security firm Bitsight exposed a line of popular H96 TV streaming sticks that quietly commandeered residential internet connections to run proxy networks and spoof mobile devices. When idle, these devices simulated mobile traffic to click on ads hosted across networks of automated, low-quality websites generated by artificial intelligence—colloquially known as "AI slop." Bitsight linked these landing pages directly to the Chinese entity known as the Fengwo Group.
A DecryptAds legal dossier on one such dormant Fengwo Group domain, medicalbeautyhub.com, revealed that it shared a seller ID (1674071) with a seemingly unrelated gaming site, giacoloredstones.com. Pivoting on a secondary seller ID (103488000) uncovered hundreds of active websites integrated into Russia’s Yandex ad network, endlessly churning out low-grade content designed purely to farm ad impressions from compromised hardware.
Official Statements & Industry Challenges
The adtech industry has long relied on obscurity to self-police—or rather, to avoid policing altogether. DecryptAds seeks to disrupt this status quo by introducing accountability mechanics that expose how ad networks handle internal fraud.
The "Quiet Removals" Phenomenon
According to Edwards, when major ad exchanges suspect a partner of generating fraudulent, unauthentic clicks or serving malvertising payloads, they rarely issue public warnings or transparency reports. Instead, they engage in quiet removals, silently excising the offending party from their sellers.json files.
"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards explains. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone."
To combat this intentional information blackout, DecryptAds features a dedicated Quiet Removals Feed. This tool continuously monitors and correlates sellers.json drop-offs across multiple ad exchanges, giving security analysts a unified view of actors quietly being blacklisted by individual platforms.
Malvertising, AI Content Farms, and the Supply Chain Object
Malvertising—the injection of malicious code or phishing redirects into legitimate ad units—remains a pervasive vector for malware distribution. However, Edwards notes a significant shift in where these attacks manifest. High-traffic mainstream destinations like espn.com or huffpost.com invest heavily in automated ad-verification and filtering technologies to block malicious code.
"None of these slop AI content farms are paying for that kind of protection," Edwards says. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads."
These automated blogs—spanning topics from home improvement and recipes to automotive care—frequently act as staging grounds for zero-click exploits targeting government personnel and enterprise workers.
To definitively solve the malvertising crisis, Edwards argues that the broader adtech industry must overhaul how it shares technical telemetry, specifically concerning the Supply Chain Object (SCO). Attached server-side to bid requests, the SCO details every intermediary, reseller, and ultimate buyer involved in an ad transaction. Without industry-wide exposure of SCO data, tracing the exact origin of a malicious payload remains nearly impossible for outside defenders. To assist researchers in automating these complex queries, DecryptAds provides an open Application Programming Interface (API) designed for integration with modern AI and threat-hunting platforms.
Future Outlook & Consumer Defense Strategies
As the surveillance economy grows increasingly automated and weaponized, relying on regulatory enforcement or self-regulation by ad networks is insufficient. For individuals seeking to protect their privacy and mitigate security risks, proactive defense is essential.
Security experts overwhelmingly endorse comprehensive ad and tracker blocking as the single most effective countermeasure against both invasive profiling and malvertising vectors. Depending on user preference and platform architecture, several robust tools exist:
Desktop & Laptop Browsers:uBlock Origin Lite serves as an open-source, highly efficient, and well-maintained choice for major browsers. For Firefox users, it offers deep integration across both desktop and Android mobile environments.
Apple Ecosystem (iPhone & iPad):Adblock Plus provides reliable mobile protection, while advanced users across platforms can leverage custom blocking lists from repositories like easylist.to.
Aggressive Script Blocking: Extensions like NoScript offer granular control by blocking all unapproved JavaScript execution, though they require active user management to ensure web pages render correctly.
Network-Level Defense: For technical enthusiasts, hardware-based blocking via a low-cost Raspberry Pi running Pi-hole creates a centralized DNS sinkhole. This approach protects every connected device on a local home network without requiring individual browser plugins.
The Mobile App Trap
Consumers must also remain acutely aware of the risks posed by mobile applications and smart-TV software. Many prominent digital services aggressively push users to download dedicated mobile apps under the guise of an "improved user experience." In reality, these applications serve as frictionless conduits for expansive telemetry collection, cross-device tracking, and unauthorized data harvesting—including the ingestion of user data to train large language models.
When given the choice, interacting with services directly through a hardened web browser remains the privacy-conscious alternative. For those curious about the underlying networks powering their favorite apps and websites, public intelligence platforms like DecryptAds offer an unprecedented window into the hidden machinery of the modern web.