DecryptAds Launches to Expose the Opaque Ecosystem of Global AdTech and Digital Tracking

Determining precisely who is responsible for the advertisements displayed on a website or which entities are harvesting data from a daily-use mobile application has long been a daunting task for security researchers and privacy advocates. While the technical files governing these relationships—such as ads.txt and app-ads.txt—are theoretically public, they have remained effectively walled off from public scrutiny, buried under layers of complex, non-standardized data. A newly launched service, DecryptAds, aims to dismantle this information asymmetry by scraping, correlating, and simplifying this data, offering a transparent look into the entities that track digital footprints across the web and mobile ecosystems.
The Mechanism of AdTech Transparency
The infrastructure of modern online advertising relies on a series of files that websites and apps publish to disclose authorized sellers. These include ads.txt, which identifies authorized adtech vendors; app-ads.txt, which serves the same function for mobile and smart TV applications; and the buyers.json and sellers.json files, which detail the entities involved in the buying and reselling of ad inventory.
DecryptAds, spearheaded by Chief Research Officer Zach Edwards—a seasoned threat researcher at Infoblox—was developed to move beyond the limitations of examining these files in isolation. Edwards and his co-founders recognized that the true danger of the adtech supply chain often lies in the inconsistencies found when cross-referencing these files. By aggregating this data, the platform allows users to view the broader picture of an advertising ecosystem, exposing patterns that would otherwise remain hidden from a cursory glance.

A Security-First Approach to Advertising
While the tools are technical in nature, the mission of DecryptAds is rooted in cybersecurity. "It’s an adtech tool, but we’re trying to approach it from a security perspective," Edwards stated during the launch. The platform addresses several critical gaps in current security practices: the identification of malicious "malvertising" campaigns, the detection of ad networks based in adversarial nations, and the flagging of the burgeoning industry of AI-generated "slop" websites and applications designed solely for ad fraud.
The supply chain of digital advertising is notoriously porous. Security issues rarely manifest in a single file; instead, they emerge as broken cross-references between various disclosure documents, cloned declaration sets across unrelated domains, and supply paths in bid logs that appear nowhere on an authorized seller list. DecryptAds seeks to provide the visibility necessary to audit these digital supply chains effectively.
Case Study: The Complexity of ESPN.com
A search for a high-traffic destination like espn.com reveals the depth of the current tracking apparatus. The site’s ads.txt and app-ads.txt files disclose 143 distinct ad partners and 19 registered data brokers. With recent privacy legislation in states like California, Oregon, Texas, and Vermont mandating that data brokers register their activities, more information is becoming public. According to DecryptAds, nearly 50% of the data brokers associated with ESPN are actively collecting geolocation data from users who have not opted out of tracking, while others collect granular device fingerprinting and sensitive personal information.
This data highlights a growing trend: the commodification of user behavior by entities that operate in the shadows of the primary platform. For a site like ESPN, the ad supply chain is not merely a method of revenue generation; it is a complex web of intermediaries, some of which may pose significant privacy or security risks to the end user.

High-Risk Partnerships and Geopolitical Implications
One of the most notable features of DecryptAds is its "geo-risk" indicator. The platform highlights when adtech partners are based in jurisdictions known for limited regulatory oversight or geopolitical tension, such as Russia, China, or countries with close financial ties to these regions, including Cyprus and the United Arab Emirates.
An analysis of Between Digital, a prominent adtech firm with a reported New York presence, illustrates the importance of this transparency. DecryptAds identifies the firm as having significant Russian ties, noting that its publisher payments are processed through Alfa Bank, a Russian financial institution under U.S. sanctions following the 2022 invasion of Ukraine. Despite these red flags, the company is permitted to serve ads and track users on numerous high-profile U.S. military news websites, including Army Times and Defense News.
The broader implications are clear: the adtech industry often facilitates the movement of capital and data across borders without sufficient vetting. When a company is permitted to act as both a buyer and a seller of ad inventory, it creates inherent conflicts of interest and facilitates the proliferation of low-quality or malicious content.
Combatting the Rise of AI-Generated Slop
The emergence of AI-generated content farms—often referred to as "slop"—has created a new frontier for malicious actors. These sites, which are populated by low-quality, machine-generated articles and images, are rarely subjected to the rigorous security standards applied to mainstream media outlets. Because these sites prioritize quick revenue, they often partner with low-tier ad networks that are less concerned with verifying the safety of the advertisements being served.

This environment has become a "greased rail" for malvertising, where users are redirected to phishing pages or exposed to drive-by downloads. Edwards emphasizes that the solution to this systemic issue is the industry-wide adoption of the "supply chain object" (SCO). By including this structured data in every bid request, ad networks could provide buyers with a clear, immutable record of every intermediary involved in an ad impression. Currently, this data is kept private at the server level, preventing researchers and security professionals from identifying the final culprit behind a malicious ad.
The Role of Regulatory and Voluntary Disclosure
The landscape of data broker transparency is shifting. As more U.S. states pass laws requiring the registration of data brokers, the public’s ability to map these relationships is improving. However, the onus remains on the individual to protect their digital footprint.
DecryptAds provides an API that allows for the automation of these lookups, enabling researchers to integrate adtech data into larger security models. This is a significant development for organizations trying to defend against zero-click payloads or state-sponsored tracking. The platform’s "quiet removals" feed is also a vital tool; it tracks when ad exchanges quietly drop an advertiser without public notification. By correlating these removals, researchers can spot patterns of fraud that the adtech industry often hides behind non-disclosure agreements or internal policy changes.
Practical Steps for User Protection
For the average internet user, the technical complexity of the adtech ecosystem is overwhelming. However, experts continue to advocate for a multi-layered approach to digital hygiene.

- Browser-Level Blocking: Utilizing tools such as uBlock Origin Lite or Adblock Plus is the most immediate defense against trackers and malicious ads. These extensions, when configured with updated lists from sources like easylist.to, can significantly reduce the attack surface.
- Network-Level Protection: For households looking for a more robust solution, a Raspberry Pi running a "sinkhole" software like Pi-hole provides network-wide ad blocking. By filtering traffic at the DNS level, users can ensure that no device on their network, including smart TVs and IoT gadgets, communicates with known ad-tracking domains.
- App Skepticism: The shift toward mobile apps is often driven by the desire for better data collection rather than improved user experience. Users should be cautious when installing apps that request excessive permissions and should prioritize accessing services through a hardened web browser whenever possible.
Future Implications for Digital Privacy
The launch of DecryptAds marks a turning point in the struggle for transparency in the digital economy. By transforming raw, obfuscated technical data into actionable intelligence, the service provides the necessary tools for journalists, security researchers, and the public to hold the adtech industry accountable. As long as the supply chain remains opaque, users remain vulnerable to surveillance and malvertising. The transition toward a "security-first" view of advertising is no longer a luxury but a necessity in an era where the integrity of the digital supply chain is a fundamental component of national and personal security.
Whether the adtech industry will respond by adopting more transparent standards—such as the widespread use of supply chain objects—remains to be seen. In the meantime, the availability of granular data on ad partnerships will undoubtedly lead to a greater public understanding of how the modern internet is funded, tracked, and potentially weaponized against its users.






