The digital advertising ecosystem—an opaque, multi-billion-dollar labyrinth that quietly governs what advertisements appear on websites and which invisible entities harvest telemetry from everyday mobile apps—has long operated behind a wall of obscurity. While transparency data has technically existed in semi-public files, it has traditionally been locked away or too fragmented for standard security professionals, let alone everyday consumers, to parse.
Enter DecryptAds, a powerful, free-to-use web intelligence platform designed to scrape, aggregate, and cross-reference foundational adtech transparency files. Launched at decryptads.com, the service transforms raw, siloed data into actionable intelligence, offering unprecedented visibility into the hidden commercial and geopolitical partnerships driving the modern web.
The platform continuously harvests and correlates four critical registry files:
ads.txt: Declares authorized digital sellers and data brokers permitted to monetize or harvest data from a specific website.
app-ads.txt: Extends this disclosure framework to mobile applications and smart TV platforms.
buyers.json / sellers.json: Explicitly identifies the corporate entities buying, selling, or reselling ad inventory across individual publisher ecosystems.
By indexing these files and applying rigorous security analytics, DecryptAds bridges a critical gap in digital hygiene. Co-founded by Zach Edwards—chief research officer at DecryptAds and threat researcher at security firm Infoblox—alongside two other industry veterans, the tool views adtech not merely through a marketing lens, but from an aggressive cybersecurity perspective. It is purpose-built to uncover supply-chain vulnerabilities, malicious ad injections (malvertising), geopolitical exposure, and the sprawling networks of AI-generated content farms ("slop sites") that plague contemporary search engines.
Chronology
The development and deployment of DecryptAds arrive at a pivotal moment in internet history, catalyzed by compounding legislative shifts and escalating cyberthreat vectors:
Pre-2022: Adtech transparency files like ads.txt are widely adopted by publishers to prevent domain spoofing, but the data remains decentralized. Security analysts lack a unified tool to cross-examine these files against global exchange registries, leaving a massive blind spot regarding who actually controls ad supply chains.
2022–2024: Following the geopolitical fallout of Russia’s invasion of Ukraine, numerous Western sanctions target prominent Russian financial institutions. Concurrently, state-level data privacy laws begin to take effect in the United States—most notably in California, Oregon, Texas, and Vermont—forcing opaque data brokers to legally register their operations and consumer-harvesting practices.
Mid-2026 (July): Security researchers from Bitsight expose a widespread threat involving cheap Chinese-manufactured H96 TV streaming sticks. These devices covertly rent out residential internet connections to strangers while simultaneously spoofing mobile devices to click on malicious ads hosted on AI-generated content farms run by the Fengwo Group.
August 2026: DecryptAds officially launches its public platform, introducing advanced analytical modules including "Geo-Risk" tracking, a Legal Dossier lookup engine, a "Quiet Removals Feed," and an API designed for integration with AI security automation frameworks. This launch immediately equips researchers with the ability to map complex supply-chain overlaps—such as linking the dormant Fengwo Group domains to active Russian Yandex ad networks.
Supporting Data
The depth of insight provided by DecryptAds is best illustrated by its exhaustive indexation of major mainstream properties, niche military publications, and global software applications.
The ESPN Supply-Chain Footprint
A baseline query for the sports media giant espn.com on DecryptAds reveals an astonishing array of commercial partners: 143 ad partners and 19 registered data broker domains declared within its ads.txt and app-ads.txt files. Cross-referencing these entries with state-level data broker registries indicates that nearly half of these entities actively harvest precise geolocation data from visitors who do not employ ad-blocking software. Furthermore, three distinct brokers explicitly admit to gathering deep device fingerprints and sensitive personal attributes.
DecryptAds features a specialized "Geo-Risk" warning system that flags adtech partners headquartered in high-risk jurisdictions—primarily China and Russia—as well as intermediary financial havens with close ties to both, such as Cyprus and the United Arab Emirates (UAE).
ESPN’s International Links: DecryptAds flags that espn.com maintains commercial relationships with four entities based in Russia, China, or the UAE. Among them is Between Digital, an adtech firm listing a New York address but thoroughly unmasked by DecryptAds as a Russian enterprise. Its publisher financial offers are processed directly through Alfa Bank, Russia’s largest private commercial bank and a primary target of U.S. sanctions enacted in 2022.
U.S. Military Publications: A security audit of premier U.S. defense news websites—including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com—reveals a shared reliance on Between Digital, alongside multiple entities in the UAE and the corporate secrecy haven of Panama. In total, DecryptAds indicates that Between Digital extracts advertising and tracking telemetry across approximately 55,000 partner websites.
Opera Browser: The popular Opera web browser, which has been majority-owned by Chinese firm Kunlun Tech since 2016 (though maintaining operational headquarters in Oslo, Norway), exhibits an extensive international footprint. DecryptAds profile data for opera.com details 27 registered data brokers, spanning 15 in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. These entities represent just 7% of the total adtech partners declared in Opera’s transparency files.
Exposing AI Slop and Malvertising Syndicates
By utilizing DecryptAds’ Legal Dossier lookup, researchers can trace the true ownership and historical aliases of malicious domains. For example, investigating the dormant Fengwo Group domain medicalbeautyhub.com—associated with the H96 streaming stick ad-fraud scheme—reveals a shared seller ID (1674071) with a gaming site, which in turn bridges to seller ID 103488000. Pivoting on this secondary identifier uncovers hundreds of active, low-quality gaming and utility websites operating within Russia’s Yandex ad network, confirming coordinated infrastructure designed to bombard unsuspecting web users with low-grade advertising and potential malware payloads.
Official Responses
As of publication, the implications of these findings have prompted close scrutiny across the cybersecurity community, though corporate stakeholders have been slow to respond publicly.
When contacted for comment regarding its corporate ties, cross-border payment processing through sanctioned entities like Alfa Bank, and its extensive footprint across U.S. military news portals, Between Digital and its founder did not immediately respond to inquiries from security journalists. KrebsOnSecurity noted that updates will be provided should formal statements be issued.
Industry experts emphasize that the adtech industry has historically relied on "security by obscurity," where bad actors are quietly excised without public accounting. Speaking on the launch of DecryptAds, Zach Edwards highlighted the systemic failure of self-policing within the advertising ecosystem:
"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public. The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."
Edwards further stressed that traditional adtech approaches must evolve to prioritize national security and user privacy:
"It’s an adtech tool but we’re trying to approach adtech from a security perspective. It’s really built for a lot of privacy and security use cases that have been dramatically underserved… Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files."
Implications
The deployment of DecryptAds and the revelations it unearths carry profound implications for national security, corporate compliance, and individual digital sovereignty.
Supply-Chain Fragility and Malvertising
Modern cyberattacks frequently bypass hardened enterprise perimeters by exploiting the "greased rails" of programmatic advertising. While high-traffic publishing destinations like major news outlets employ dedicated engineering resources to filter out malicious ad insertions (malvertising), the explosion of automated, AI-generated content farms ("slop sites") has created a haven for threat actors. These low-quality sites rarely invest in brand-safety tools, allowing malicious zero-click payloads, phishing schemes, and malware distributors to target unsuspecting users who stumble onto the pages via organic search engine results.
Edwards points out that solving this crisis requires transparency regarding the Supply Chain Object (SCO)—structured, server-side data attached to bid requests that tracks every intermediary handling an ad impression. Because major ad networks routinely withhold SCO data from public view, tracking the precise origin of a malvertising campaign remains exceptionally difficult.
Beyond desktop and mobile web browsing, the push by major digital platforms to drive users toward native mobile applications and smart TV integrations is fundamentally driven by data collection rather than user experience. Mobile apps afford corporations the ability to bypass traditional browser-level protections, harvesting granular telemetry, location histories, and behavioral metrics that can be monetized, resold, or—increasingly—utilized to train large language models without explicit, informed consumer consent.
Actionable Defense for Users and Organizations
Given the expansive web of data brokers, foreign ad networks, and hidden trackers exposed by platforms like DecryptAds, security experts argue that comprehensive ad blocking is no longer merely a matter of user preference, but an essential cybersecurity hygiene practice.
For Desktop Users: Open-source tools such as uBlock Origin Lite or script-control extensions like NoScript provide robust, auditable protection against unwanted telemetry and malvertising.
For Mobile Users: Ecosystems like iOS can utilize tools such as Adblock Plus, while Android users can leverage privacy-focused browsers supporting advanced content filtering.
For Network-Level Protection: Technically proficient users can deploy hardware-level solutions, such as a Raspberry Pi running Pi-hole, transforming local network routing to act as a DNS sinkhole that blocks advertisements and tracking requests across every connected device in a home or small office.
Ultimately, tools like DecryptAds democratize threat intelligence, providing the visibility necessary to hold an unaccountable adtech industry transparently accountable for the digital surveillance economy it sustains.