Unmasking the Adtech Supply Chain: Inside DecryptAds and the Hidden Dangers of Digital Tracking
![]()
By Tech & Cyber Security Desk
For millions of internet users, navigating the modern web often feels like walking through a digital minefield. Every click, scroll, and app launch triggers an invisible, complex machinery designed to harvest personal information and serve targeted advertisements. Determining who is actually responsible for displaying these ads—or who is vacuuming up sensitive data from mobile and smart TV applications—has historically been an exercise in frustration.
While much of this operational data is technically semi-public, it has traditionally been locked away behind walled gardens, siloed across massive advertising platforms, and rendered practically unparseable for the average consumer or security researcher.
That paradigm is beginning to shift dramatically. A powerful, free-to-use new platform called DecryptAds has emerged to scrape, parse, and correlate this fragmented adtech data. By translating dense, machine-readable disclosures into transparent, accessible insights, the service is giving privacy advocates, threat researchers, and journalists an unprecedented window into the entities that track everyday internet users.
1. Main Facts: The Anatomy of DecryptAds
At its core, decryptads.com functions as a continuous intelligence-gathering engine. It systematically crawls and aggregates public-facing disclosure files that websites and mobile applications are required—or choose—to publish. These foundational files include:
ads.txt(Authorized Digital Sellers): A standardized text file published by website operators that publicly lists all authorized digital advertising partners, programmatic vendors, and data brokers permitted to buy ad space or harvest telemetry from the site.app-ads.txt: The mobile and smart TV equivalent ofads.txt, extending publisher transparency ecosystems into downloaded applications and connected television interfaces.buyers.jsonandsellers.json: Machine-readable cryptographic files published by ad exchanges that identify the business entities buying, selling, or reselling ad inventory across the digital ecosystem.
The platform was built by a trio of founders, including Chief Research Officer Zach Edwards, who also serves as a threat researcher at cybersecurity firm Infoblox. According to Edwards, the service was born out of a glaring market necessity: individual disclosure files are practically useless in isolation. Only by aggressively cross-referencing and correlating these datasets across the global web can security professionals begin to map the sprawling, interconnected advertising supply chain.
"It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards explains. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

2. Chronology: The Evolution of Ad Transparency and Supply Chain Blind Spots
To understand why DecryptAds is a watershed development, one must look at how the digital advertising ecosystem evolved from a straightforward buyer-seller market into a hyper-complex, opaque marketplace.
The Rise of Programmatic Advertising and Disclosures
In the early days of the web, advertising was largely negotiated directly between publishers and brands. As the internet scaled, automated programmatic bidding took over, introducing networks of intermediaries, ad exchanges, demand-side platforms (DSPs), and supply-side platforms (SSPs). By the mid-2010s, ad fraud and domain spoofing—where bad actors masqueraded as premium publishers to steal ad revenue—cost the industry billions.
In response, the Interactive Advertising Bureau (IAB) introduced ads.txt in 2017, followed later by app-ads.txt and sellers.json, to bring cryptographic and declarative accountability to the programmatic supply chain. While these files were public, parsing thousands of sprawling text entries to find structural anomalies, hidden ownership ties, or sanctioned entities required custom scripting and immense computing power—resources typically reserved for major ad tech conglomerates or elite threat intelligence teams.
The Emergence of DecryptAds
Recognizing that bad actors were exploiting this visibility gap, Edwards and his co-founders developed DecryptAds to automate the heavy lifting. By continuously ingesting, indexing, and mapping these files against geopolitical databases, corporate registries, and state-level data broker disclosures, the platform transformed raw data dumps into actionable intelligence.
The service arrives at a critical juncture. As state-level privacy legislation—such as landmark laws in California, Oregon, Texas, and Vermont—begins forcing data brokers to publicly register their operations, tools like DecryptAds bridge the gap between regulatory compliance and technical verification.
3. Supporting Data: Inside the Numbers
The practical applications of DecryptAds become starkly evident when running deep-dive queries on major digital properties. The platform’s findings expose a startling disconnect between mainstream web consumption and the sheer volume of hidden third-party data collection.
The ESPN Case Study
A search on DecryptAds for the major sports network espn.com reveals a staggering web of partnerships: the site declares 143 ad partners and 19 registered data broker domains across its ads.txt and app-ads.txt files.

Crucially, because of newly enacted state data-broker transparency laws, DecryptAds can cross-reference these entries against actual regulatory filings. The platform reports that nearly half of those registered data brokers are actively collecting precise geolocation data from ESPN visitors who do not employ ad-blocking technology. Furthermore, three distinct brokers explicitly disclose that they collect device fingerprints and sensitive personal information from users.
High-Risk Ad Partners and Geopolitical Exposure
One of DecryptAds’ most innovative features is its "Geo-Risk" scoring system, which flags advertising firms based in adversarial or high-risk jurisdictions—such as Russia and China—as well as offshore financial hubs with close political and economic ties to those nations, including Cyprus and the United Arab Emirates (UAE).
For example, DecryptAds notes that espn.com partners with four advertising entities tied to Russia, China, or the UAE. Among them is Between Digital, an adtech firm that lists an official corporate address in New York. However, DecryptAds’ dossier unmasks the company as a Russian entity, detailing how its publisher payouts are processed through Alfa Bank, Russia’s largest private commercial bank, which was placed under sweeping U.S. sanctions following the 2022 invasion of Ukraine.
The footprint of Between Digital extends far beyond sports media. A search across top U.S. military-focused news websites—including Army Times, Air Force Times, Defense News, Navy Times, Marine Corps Times, and Federal Times—reveals that all of them permit Between Digital to serve advertisements and track readers. According to DecryptAds telemetry, Between Digital collects ad data across approximately 55,000 partner websites.
Furthermore, auditing Between Digital’s app-ads.txt files exposes hundreds of domains dedicated to simple, ad-heavy mobile web games. Edwards points out that Between Digital lists itself as both a publisher and a reseller on roughly two-thirds of its portfolio. "It means they are basically playing both sides of the bidding equation," Edwards warns, noting that this creates inherent conflicts of interest and channels client ad spend into owned-and-operated infrastructure.
Similar deep-dives yield eye-opening statistics regarding popular consumer software. The Opera web browser, which remains widely used globally, has been majority-owned and controlled since 2016 by the Chinese technology firm Kunlun Tech (though its operational headquarters remain in Oslo, Norway). DecryptAds’ profile for opera.com uncovers 27 registered data brokers collecting information, including 15 partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. While these entities represent just 7% of the total adtech partners declared by Opera, the sheer geopolitical diversity of the data collection apparatus highlights the borderless nature of modern telemetry harvesting.
4. Official Responses and Industry Dynamics
As DecryptAds exposes these sprawling networks, the platform is also shedding light on systemic shortcomings within the advertising industry’s self-policing mechanisms.

The "Quiet Removals" Phenomenon
When major ad networks suspect that a specific partner is engaging in fraudulent traffic generation, unauthentic clicks, or malvertising, standard industry protocol often involves quietly purging the offender from sellers.json lists. However, ad exchanges routinely execute these bans without issuing public disclosures or alerting upstream publishers.
To counteract this, DecryptAds features a dedicated Quiet Removals Feed. This feed aggregates and correlates historical changes in sellers.json files across multiple ad exchanges, allowing researchers to track when and where bad actors are being quietly excised from the ecosystem.
"The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public," Edwards explains. "The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone."
The Threat of Malvertising and AI "Slop"
The opacity of the ad supply chain directly fuels two of the web’s most pervasive modern plagues: malvertising (malicious advertisements designed to distribute malware or drive users to phishing landing pages) and AI-generated content farms (often referred to as "AI slop").
Edwards notes that sophisticated malvertising attacks rarely manifest on high-traffic, premium domains like ESPN or major news outlets, as those organizations employ robust, enterprise-grade security tools to vet third-party ad code. Instead, malicious actors target the booming underground economy of AI-generated content farms—blogs churning out machine-written articles on home improvement, recipes, and consumer technology solely to capture search engine traffic.
"None of these slop AI content farms are paying for that kind of protection," Edwards says. "They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads."
In July, security researchers at Bitsight uncovered a sprawling operation involving popular H96 TV streaming sticks. When users were not streaming media, these devices were quietly renting out internet connections to strangers and spoofing themselves as mobile phones to click on ads hosted across AI slop networks operated by the China-based Fengwo Group. DecryptAds legal dossiers successfully linked these dormant AI slop domains to specific seller IDs embedded within Russia’s Yandex ad system, proving the cross-border syndication of low-quality, high-risk programmatic revenue streams.

5. Implications and Recommended Defense Strategies
The launch of DecryptAds and the broader unmasking of adtech supply chain vulnerabilities carry profound implications for national security, corporate compliance, and individual privacy.
When government personnel, military contractors, and corporate executives visit routine news or utility websites, they expose themselves to surveillance and potential zero-click exploitation channeled through unvetted programmatic ad feeds. Edwards argues that solving this crisis requires transparency far beyond basic text files. Specifically, he advocates for the broader industry adoption and sharing of Supply Chain Objects (SCOs)—structured data attached to server-side bid requests that reveal every intermediary, seller, and buyer involved in an ad impression.
Without access to SCO data, security teams can witness a malicious redirection or payload delivery but remain completely blind to the exact financial pathway that funded the attack.
How Users Can Protect Themselves
Given the pervasive surveillance baked into modern advertising networks, security experts agree that manual tracking prevention is virtually impossible without technical intervention. Consumers and professionals looking to harden their digital footprint should consider the following layered defense strategies:
- Deploy Robust Browser Extensions: For standard desktop and laptop web browsing, uBlock Origin Lite is widely recommended as a lightweight, open-source, and actively maintained ad blocker. On mobile platforms, uBlock Origin functions effectively with Firefox on Android devices, while Adblock Plus serves as a viable alternative for iOS users on iPhones and iPads. Power users can integrate custom blocklists from EasyList (
easylist.to) to aggressively strip out tracking scripts. - Network-Level Ad Blocking (Pi-hole): For technically inclined users seeking comprehensive protection across all connected devices in a home or office, setting up a low-cost Raspberry Pi running Pi-hole creates an effective network-wide DNS sinkhole. This approach automatically blocks ad domains and tracking telemetry at the router level for smart TVs, IoT devices, and computers alike.
- Exercise Extreme Caution with Mobile and Smart TV Apps: Mobile applications are primary vectors for deep telemetry harvesting, device fingerprinting, and precise geolocation tracking. Whenever possible, users should bypass dedicated mobile apps and interact directly with web services via a hardened browser. Furthermore, users should audit smart TV apps and mobile downloads against research databases like DecryptAds to understand their underlying data-sharing relationships.
As regulatory pressure mounts and forensic tools like DecryptAds continue to shine a harsh light into the darkest corners of the adtech ecosystem, the era of unbridled, invisible tracking may finally be facing a reckoning.
