The Adtech Mirror: New Tool ‘DecryptAds’ Exposes the Hidden Supply Chain of Online Tracking

For decades, the digital advertising ecosystem has operated behind a veil of complexity. While billions of advertisements flash across our screens every day, the mechanisms behind them—the data brokers, the resellers, and the silent trackers—have remained largely opaque. For the average user, determining who is harvesting their mobile app data or which entity is serving a potentially malicious ad on a trusted website has been a near-impossible task.

That era of enforced ignorance is coming to an end. A powerful new, free service called DecryptAds has launched with a singular mission: to scrape, correlate, and demystify the vast, convoluted web of adtech declarations. By transforming dense, technical files into accessible intelligence, DecryptAds is providing security researchers, privacy advocates, and concerned citizens with a window into the digital supply chain.

The Technical Foundation: Decrypting the ‘Ads.txt’ Ecosystem

At the heart of the modern advertising industry are three specific files that websites and apps are expected to publish to maintain transparency: ads.txt, app-ads.txt, and sellers.json. These files act as a "who’s who" of the advertising world, listing which companies are authorized to sell or resell a publisher’s ad space.

However, these files were never designed for human readability, nor were they meant to be viewed in isolation. They are frequently cross-referenced by ad exchanges to verify inventory, but until now, there has been no centralized, user-friendly way for the public to analyze them at scale.

"It’s an adtech tool, but we’re trying to approach adtech from a security perspective," explains Zach Edwards, Chief Research Officer for DecryptAds and a veteran threat researcher at Infoblox. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

The service works by continuously scraping these public declarations across the web. It then maps the relationships between entities, allowing users to see not just a single list of partners, but the entire, sprawling network of brokers that stand between a user and their digital privacy.

Chronology: From Obscurity to Transparency

The development of DecryptAds arrives at a pivotal moment in internet history.

  • 2017–2020: The introduction of the ads.txt standard by the Interactive Advertising Bureau (IAB) was intended to curb domain spoofing and ad fraud. While it succeeded in standardizing the "who," it did little to address the "what" or "why" regarding data collection.
  • 2023–2025: Regulatory pressure began to mount as states like California, Oregon, Texas, and Vermont passed laws requiring data brokers to register if they handle consumer information. This forced a greater degree of disclosure, yet the data remained scattered across thousands of disparate locations.
  • 2026 (August): The official launch of DecryptAds marks the first time this disparate, semi-public data has been correlated into a searchable, analytical interface. By pulling in registration data from state-mandated broker lists and linking them to existing adtech files, the service provides an unprecedented view of the data-brokerage landscape.

Supporting Data: The Case of ESPN and Military News Sites

To demonstrate the depth of the data, a search for the sports giant espn.com reveals the staggering reality of modern adtech. The site lists 143 ad partners and 19 registered data brokers within its ads.txt and app-ads.txt files.

Crucially, DecryptAds’ analysis indicates that nearly 50% of these brokers are harvesting geolocation data from visitors who have not enabled ad-blocking software. Even more concerning, three of these entities explicitly state that they collect device fingerprints and sensitive personal information.

The implications become more severe when looking at "geo-risk" profiles. DecryptAds flags adtech partners based in jurisdictions that present potential security concerns, such as Russia, China, or countries with close ties to those nations, like the UAE or Cyprus.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

When searching for major U.S. military news outlets—including ArmyTimes, AirForceTimes, and DefenseNews—DecryptAds reveals a troubling presence. All these sites allow entities like Between Digital to serve ads and track users. While Between Digital lists a New York address, DecryptAds’ dossier reveals the firm is Russian-linked, with publisher offers processed through Alfa Bank, a major Russian financial institution sanctioned by the U.S. government following the 2022 invasion of Ukraine.

Official Responses and Industry Silence

The investigative nature of DecryptAds has already begun to highlight the "quiet removals" phenomenon. When an ad network detects that a partner is engaged in fraud or malware distribution, they often remove that entity from their sellers.json file silently.

"The ban is just removing them from the sellers.json file, but they told nobody," Edwards notes. "One day it was there, the next it was gone. If you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."

When queried about these findings, many of the adtech companies involved, including Between Digital, have remained silent. This lack of transparency is exactly what DecryptAds seeks to disrupt. By creating a permanent record of these "quiet removals," the platform forces accountability onto an industry that has historically relied on the cover of darkness to prune its own bad actors.

Security Implications: Malvertising and AI-Generated Slop

The intersection of adtech and security has reached a critical juncture. Malvertising—the injection of malicious code into ads—is no longer confined to top-tier websites. Instead, it is migrating to the fast-growing ecosystem of "AI-generated slop" websites.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

These sites, often created to farm clicks using machine-generated content, are frequently poorly defended. Because they lack the budget or the technical oversight of major networks, they often sign up with low-quality ad partners. This creates a "greased rail" for attackers to push zero-click payloads directly to unsuspecting users.

The danger is amplified by the lack of the "Supply Chain Object" (SCO). This structured data, which would identify the entire chain of custody for an ad impression—from the original publisher to the final buyer—is currently only accessible server-side. Without it, researchers cannot easily trace the source of a malicious payload. Edwards argues that for the industry to be secure, these major ad networks must be compelled to share the SCO, providing a transparent audit trail for every digital advertisement served.

Strategic Recommendations for the Individual

For the privacy-conscious individual, the findings from DecryptAds serve as a stark warning: the current model of the ad-supported web is fundamentally adversarial to the user.

1. Universal Ad Blocking

The most effective defense remains the widespread use of ad-blocking tools. For desktop users, uBlock Origin Lite remains the gold standard. For those willing to venture into hardware-based solutions, a Raspberry Pi running Pi-hole offers a network-wide defense that intercepts ad requests at the DNS level before they ever reach your devices.

2. App Skepticism

The "app-first" push by major publishers is not about user experience; it is about data harvesting. Apps allow for significantly more granular tracking—including GPS, device sensors, and cross-platform activity—than web browsers. Where possible, users should favor web versions of services over their dedicated app counterparts.

Who’s Tracking You? Use This New Service to Find Out – Krebs on Security

3. Vigilance Toward Smart Devices

The risks are not limited to phones and laptops. Smart TVs and streaming sticks have become prime targets for adtech firms looking to exploit the user’s connection. As seen with the H96 streaming stick incident, these devices can be hijacked to act as "bots" that click on ads, generating revenue for bad actors while compromising the user’s home network security.

4. Leveraging Transparency Tools

Users and professionals alike should utilize platforms like DecryptAds to perform due diligence. Whether you are an organization worried about where your employees are browsing or an individual concerned about your own data footprint, searching a site or app on DecryptAds can reveal exactly who is permitted to track you.

Conclusion: The Path Forward

The launch of DecryptAds is more than just a new tool; it is a declaration that the era of "black box" advertising is no longer sustainable. By democratizing access to the complex web of adtech declarations, the platform provides the necessary leverage for a more transparent, secure, and privacy-respecting digital environment.

As the industry faces increased scrutiny from regulators and the public, the ability to trace the flow of data and money becomes a fundamental security requirement. For those who believe that privacy is a right rather than a privilege, the data provided by DecryptAds is the first step toward reclaiming control over the digital landscape. The supply chain of our attention is finally being mapped, and for the first time, we have the map in our hands.

Leave a Reply

Your email address will not be published. Required fields are marked *