The vast, interconnected machinery that powers online advertising has long operated behind a "walled garden" of opacity. For the average internet user, the journey from clicking a link to viewing an advertisement involves a complex, split-second auction process involving dozens of intermediaries, data brokers, and trackers. Historically, this ecosystem has been shielded from public scrutiny, buried under proprietary technology and obfuscated technical files.
However, a new, free service called DecryptAds is changing the landscape. By scraping and cross-referencing public but previously unintelligible adtech files, the service provides a window into the entities harvesting user data and the supply chains powering digital ads. This initiative is not merely a tool for marketers; it is a critical instrument for security researchers, privacy advocates, and concerned citizens attempting to navigate a digital environment increasingly saturated with tracking, malvertising, and AI-generated "slop."
The Mechanics of Transparency: How DecryptAds Works
The core of DecryptAds lies in its ability to synthesize data that is technically public but practically inaccessible. Websites and mobile applications are required by industry standards to publish specific files that disclose which entities are authorized to serve ads or collect data. These files—ads.txt, app-ads.txt, and buyers.json/sellers.json—act as a registry of a site’s advertising partners.
Until now, parsing these files manually was a task for data scientists. DecryptAds automates this by continuously crawling these disclosures and correlating the findings.
- ads.txt: Lists the adtech companies and data brokers authorized to run ads on a website.
- app-ads.txt: Performs a similar function for mobile and smart TV applications, identifying entities that harvest data or display ads within the app environment.
- buyers.json/sellers.json: Maps the complex web of entities buying, selling, or reselling ad inventory, exposing the middlemen in the digital advertising supply chain.
By aggregating this information, DecryptAds allows users to see the "big picture" of a domain’s ad ecosystem, revealing partnerships that might be hidden when looking at a single file in isolation.

Chronology: From Industry Obscurity to Public Accountability
The launch of decryptads.com represents a pivot in the way cybersecurity professionals approach digital privacy. Zach Edwards, the chief research officer for DecryptAds and a threat researcher at Infoblox, spearheaded the project alongside two other founders. The team recognized that the adtech industry had become a blind spot for security operations.
"It’s an adtech tool, but we’re trying to approach adtech from a security perspective," Edwards noted. "It’s really built for a lot of privacy and security use cases that have been dramatically underserved."
The project emerged in response to the growing threat of "supply-chain integrity issues." These issues, which involve cloned declaration sets across unrelated domains or broken cross-references between different ad files, are often the hallmarks of malicious activity. By identifying these patterns, DecryptAds provides a proactive way to detect fraud rather than reacting to it after a user has been compromised.
Supporting Data: The ESPN Case Study and Data Brokerage
To understand the scale of the surveillance apparatus, one need only look at a mainstream giant like espn.com. A search on DecryptAds reveals that the site maintains relationships with 143 ad partners and 19 registered data brokers.
Recent legislative action has forced some of this activity into the light. Laws passed in California, Oregon, Texas, and Vermont now require data brokers to register if they buy or sell consumer data. The findings on ESPN are telling: nearly 50% of its listed data brokers collect geolocation data from visitors who do not employ ad-blocking technology. Furthermore, three entities explicitly disclose that they collect device fingerprints and sensitive personal information.

This data is not just used for targeted ads; it is part of a global, multi-billion-dollar trade in personal behavioral data. The complexity of these relationships, as visualized by DecryptAds’ mapping tools, shows that for every ad a user sees, there is a sprawling, invisible network of entities working in tandem to profile them.
High-Risk Ad Partners and Geopolitical Exposure
Perhaps the most alarming feature of the DecryptAds platform is its "Geo-Risk" indicator. The tool flags adtech partners based in countries with high political or financial risk, specifically highlighting firms in Russia, China, and nations with deep ties to these powers, such as Cyprus and the United Arab Emirates.
The data reveals that espn.com, among others, works with entities based in these regions. A prime example is the adtech firm Between Digital. While the company maintains a New York address, DecryptAds flags it as a Russian-based firm. The dossier on the company shows that its publisher payments are processed through Alfa Bank, Russia’s largest private commercial bank—an institution currently under U.S. sanctions following the invasion of Ukraine.
The risks extend to U.S. military news outlets as well. Investigations into sites like armytimes.com, airforcetimes.com, and defensenews.com show that they allow entities like Between Digital to serve ads, despite the firm’s ties to adversarial infrastructure. Between Digital reportedly collects ad data on approximately 55,000 partner websites, illustrating how deeply embedded potentially hostile adtech has become in the American media landscape.
Implications: Malvertising, AI Slop, and Conflict of Interest
The implications of this opaque system are profound. When advertising networks suspect fraud—such as unauthentic clicks or the delivery of malware—they often engage in "quiet removals." They strike the offending advertiser from their sellers.json file without notifying the public or other exchanges. This allows bad actors to hop from one network to another, evading accountability.

DecryptAds addresses this through a "Quiet Removals Feed," which tracks these silent purges across the industry.
Furthermore, the rise of "AI-generated slop"—low-quality, machine-produced websites designed solely to host ads—has created a new breeding ground for malvertising. These sites lack the security budgets of major media organizations, making them "greased rails" for attackers to deploy zero-click payloads.
Edwards emphasizes that solving this requires more than just better tools; it requires industry-wide transparency, specifically regarding the "supply chain object" (SCO). The SCO provides the data necessary to see the entire journey of an ad, from the original publisher to the buyer. Currently, this data is kept server-side, hidden from the researchers and security professionals who need it to stop malicious redirects.
Official Responses and Industry Stance
While the adtech industry has traditionally maintained that self-regulation is sufficient, the findings from researchers like Zach Edwards suggest otherwise. KrebsOnSecurity has reached out to firms like Between Digital for comment on their ties to sanctioned entities and their role in the ad ecosystem. To date, such entities have largely remained silent, relying on the complexity of their corporate structures to deflect scrutiny.
The lack of standardized, public-facing supply chain accountability remains the industry’s greatest weakness. As long as ad networks prioritize volume and revenue over vetting the integrity of their partners, the burden of security remains on the user.

Empowering the User: Strategies for Defense
In light of these findings, the most effective defense remains the aggressive blocking of ads and trackers. The digital ecosystem is currently structured to prioritize data collection, and without user intervention, that collection is effectively total.
Recommended Defensive Measures:
- Desktop Browsers: uBlock Origin Lite remains the gold standard for open-source, lightweight ad and tracker blocking. It provides an immediate layer of protection against the most common data-harvesting scripts.
- Mobile Browsers: Firefox on Android is a strong choice as it supports robust extension ecosystems. For iOS users, Adblock Plus or similar tools that support custom filter lists (like
easylist.to) are essential. - Network-Level Protection: For those seeking a comprehensive, set-and-forget solution, a Raspberry Pi running Pi-hole is the most effective approach. By acting as a DNS sinkhole, it blocks ads at the network level, protecting every device connected to your home Wi-Fi.
- The "App" Trap: Be wary of websites that aggressively push you to download their mobile app. In many cases, these apps are designed to harvest more intrusive telemetry than a mobile browser, including precise location and device-specific identifiers. Where possible, stick to the browser.
A Call for Digital Hygiene
As we navigate an era where the line between a legitimate advertisement and a malicious data-harvesting operation has blurred, tools like DecryptAds serve as an essential reminder: the internet is not a neutral space. Every click, view, and page load is an opportunity for a vast, hidden industry to extract value from your personal information. By arming ourselves with the right tools and maintaining a healthy skepticism toward the "free" services we consume, we can reclaim a measure of privacy in an increasingly tracked world.
