Executive Overview
For decades, the digital advertising supply chain has operated as an opaque, walled garden. Navigating the labyrinth of programmatic ad exchanges, real-time bidding (RTB) platforms, and data brokers has traditionally required specialized enterprise tooling or deep forensic auditing. For ordinary consumers, privacy advocates, and even corporate security teams, identifying who is funding a malicious ad campaign or harvesting personal data from a smartphone app has been an exercise in frustration.
This landscape shifted dramatically with the public debut of DecryptAds (decryptads.com), a powerful, free-of-charge intelligence platform designed to scrape, parse, and correlate ad technology disclosures. Developed by a team of industry veterans—including Chief Research Officer and Infoblox threat researcher Zach Edwards—DecryptAds approaches the chaotic world of advertising technology through a dedicated security and privacy lens. By systematically analyzing publicly declared files such as ads.txt, app-ads.txt, sellers.json, and buyers.json, the service provides unprecedented visibility into the hidden commercial partnerships that sustain modern websites and mobile applications.
The platform’s launch arrives at a critical juncture. As threat actors increasingly weaponize digital advertising networks to distribute malware, deploy zero-click payloads against high-value targets, and monetize the explosive growth of low-quality, AI-generated "content farms," the need for supply-chain integrity has never been more urgent. DecryptAds provides the necessary connective tissue to cross-reference fragmented data sets, exposing high-risk geographic entities, quiet vendor removals, and complex corporate proxies that jeopardize enterprise and national security alike.
Detailed Chronology & Mechanics: How DecryptAds Works
To understand the value proposition of DecryptAds, one must first examine the decentralized disclosures established by the Interactive Advertising Bureau (IAB). Websites and app developers use standardized text files to declare which entities are authorized to buy and sell their digital ad inventory.
ads.txt(Authorized Digital Sellers): Publicly lists all adtech companies, intermediaries, and data brokers permitted to run advertisements or harvest data from a specific website.app-ads.txt: The mobile and smart-TV counterpart toads.txt, governing inventory and data collection within smartphone and connected-device applications.sellers.json/buyers.json: Structured JSON files maintained by supply-side platforms (SSPs) and ad exchanges that detail the specific corporate entities buying, selling, or reselling ad inventory.
Individually, these files offer limited utility. However, DecryptAds continuously scrapes these registries, processing and cross-referencing the data to construct a comprehensive relationship graph for individual domains and applications.
The Security Paradigm Shift
Speaking on the platform’s core mission, Zach Edwards noted that the tool was born out of a collective realization that traditional adtech data is only useful when aggregated into a holistic view. "It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards explained. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

According to the platform’s documentation, supply-chain vulnerabilities rarely manifest within a single, isolated file. Instead, they present as broken cross-references between ads.txt and sellers.json registries, cloned declaration sets deployed across completely unrelated domains, and shadow supply paths that appear in bid logs without ever being authorized by the publisher. DecryptAds automates the grueling task of uncovering these discrepancies, offering researchers an application programming interface (API) to automate queries and feed actionable intelligence into modern analytical systems.
Supporting Context & Metrics: Case Studies in the Wild
The practical application of DecryptAds yields startling insights into how major digital properties integrate with questionable international networks and data brokers.
The ESPN Ecosystem and State-Level Data Broker Disclosure
A search for the high-traffic sports network espn.com on DecryptAds reveals an intricate commercial web encompassing 143 distinct ad partners and 19 registered data broker domains listed across its primary and application-level authorization files.
This transparency is bolstered by progressive state legislation. Four U.S. states—California, Oregon, Texas, and Vermont—have enacted laws requiring data brokers to officially register if they buy or sell consumer information originating from their residents. DecryptAds’ parsing reveals that nearly half of ESPN’s declared data brokers harvest geolocation data from visitors who do not employ ad-blocking technologies, while another three explicitly disclose the collection of device fingerprints and sensitive personal attributes.
Geo-Risk, Sanctioned Entities, and Military Targeting
One of DecryptAds’ most vital features is its Geo-Risk dashboard, which flags advertising partners headquartered in high-risk jurisdictions—such as China and Russia—or in strategic financial hubs with close ties to both, including Cyprus and the United Arab Emirates (UAE).
For instance, DecryptAds identifies that espn.com maintains partnerships with four entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm maintaining a nominal New York office. However, DecryptAds’ dossier unmasks Between Digital as a Russian operation whose publisher payout offers are processed directly through Alfa Bank, Russia’s largest private commercial bank. Alfa Bank was heavily sanctioned by the United States government in 2022 following the Kremlin’s invasion of Ukraine.

The proliferation of such high-risk entities extends into sensitive national security sectors. A search across premier U.S. military news properties—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveals that all of these publications authorize Between Digital to serve advertisements and track users. They also share space with entities based in the UAE and the ownership-secrecy haven of Panama. According to DecryptAds, Between Digital actively collects advertising telemetry across approximately 55,000 partner websites.
Pivoting on Between Digital’s app-ads.txt file exposes hundreds of simple, web-based mobile games interrupted by frequent ad breaks. Edwards points out that Between Digital’s own filings list the company as both a publisher and a reseller on roughly two-thirds of its portfolio. "It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure," Edwards warned, highlighting an inherent structural conflict of interest.
The Opera Browser Footprint
Similarly, the popular Opera web browser—which has been majority-owned by the Chinese firm Kunlun Tech since 2016, despite maintaining its operational headquarters in Oslo, Norway—reveals a vast, international data-harvesting apparatus. Opera.com’s DecryptAds profile identifies 27 registered data brokers collecting user telemetry, including 15 partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These entities represent just 7% of the total adtech partners enumerated within Opera’s authorization files.
Legal Dossiers and the Fengwo Group Investigation
DecryptAds features a specialized Legal Dossier lookup tool. Although individual searches require several minutes to execute, they yield extensive genealogical data regarding domain ownership, registration timelines, historical aliases, and underlying corporate cross-connections.
This feature proved invaluable in dissecting recent threats uncovered by security firm Bitsight. Researchers discovered that a popular brand of budget TV streaming sticks, known as H96, covertly rented out idle consumer internet connections to third-party proxy networks. When not being leveraged to stream pirated media, these devices spoofed mobile phone identifiers to simulate ad clicks on automated, AI-generated "slop" websites.
Bitsight tied this malicious infrastructure to the Fengwo Group, a Chinese entity that operated both the malicious mobile applications embedded in the H96 hardware and the network of low-quality advertising landing pages. A DecryptAds legal dossier lookup on a dormant Fengwo Group domain (medicalbeautyhub.com) revealed that it shared a seller ID (1674071) with an unrelated gaming site (giacoloredstones.com), which in turn linked to a secondary seller ID (103488000). Pivoting on that second identifier exposed hundreds of active websites integrated into Russia’s Yandex advertising system, pumping out low-grade utility games designed to bombard users with ads.

Quiet Removals and Industry Blind Spots
A pervasive issue within digital advertising is the opaque handling of bad actors. When ad networks suspect an advertiser of generating fraudulent clicks or distributing malvertising, they frequently remove the offender from their approved sellers.json lists quietly, offering no public disclosure or industry-wide warning.
To combat this, DecryptAds introduced a Quiet Removals Feed, which correlates seller removals across disparate ad exchanges. "The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards observed. By tracking when a seller ID vanishes overnight across multiple exchanges, the feed provides researchers with a vital telemetry stream to map out malicious actors attempting to launder their corporate reputations.
Official Statements and Industry Perspectives
The architects of DecryptAds emphasize that traditional cybersecurity defenses are fundamentally blind to adtech-driven vectors unless security teams begin treating ad data as critical threat intelligence.
"A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis," Edwards stated.
The proliferation of malvertising—the injection of malicious code or phishing redirects into legitimate ad networks—has increasingly migrated away from high-traffic, heavily monitored destinations like ESPN or HuffPost. Premium publishers maintain rigorous validation teams and automated filters to catch malicious inventory. Conversely, the rapidly expanding ecosystem of AI-generated content farms bypasses such precautions entirely.
"None of these slop AI content farms are paying for that kind of protection," Edwards noted. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads."

To truly eliminate malvertising and supply-chain fraud, Edwards argues that major ad networks must embrace deeper transparency regarding the Supply Chain Object (SCO). Attached server-side to programmatic bid requests, the SCO details every intermediary, reseller, and final buyer involved in an ad impression. Without server-side access to the SCO, security analysts can observe a malicious zero-click redirection in the browser, but remain utterly incapable of tracing the financial transaction back to the malicious buyer.
Future Outlook and Recommendations for Users
As digital surveillance expands and the adtech supply chain grows increasingly weaponized by state-sponsored threat actors and criminal syndicates, reliance on self-regulation by advertising platforms is a failing strategy. Securing one’s digital footprint requires proactive defense measures at multiple layers of the technology stack.
Practical Mitigation Strategies
- Deploy Robust Ad Blocking at the Browser Level:
- For desktop and laptop users utilizing standard web browsers, uBlock Origin Lite serves as an open-source, highly efficient ad-blocking tool.
- Mobile users on Android can leverage Firefox combined with uBlock Origin, while iOS users on iPhones and iPads can rely on Adblock Plus or configure custom rulesets sourced from communities like
easylist.to.
- Implement Network-Level Ad Blocking (Pi-hole):
- For advanced, scalable protection across every device connected to a local household or office network, technical users should consider deploying a Raspberry Pi running Pi-hole. Configured as a local DNS sinkhole, it intercepts ad and tracker requests at the network router level before they ever reach individual endpoints.
- Exercise Extreme Caution with Mobile Apps and Smart TVs:
- Mobile applications are frequently utilized by platforms not merely to improve user experience, but to bypass browser-based privacy protections, harvest granular telemetry, and enroll users in biometric or large language model (LLM) training datasets. Whenever possible, interact with services via a secured browser rather than dedicated mobile or smart-TV applications.
- Audit Vendors via Intelligence Platforms:
- Enterprise security teams, journalists, and privacy researchers should leverage DecryptAds to perform proactive reconnaissance on corporate vendors, app partners, and web properties to ensure they are not inadvertently exposing internal networks to high-risk foreign jurisdictions or compromised adtech supply chains.
Ultimately, tools like DecryptAds democratize an arena of cyberspace that has remained hidden in plain sight for far too long. By turning the adtech industry’s own mandatory disclosures against the forces of opaque tracking and malicious monetization, researchers now possess the visibility required to bring accountability to the digital wilderness.
