Shedding Light on the Shadows: DecryptAds and the Fight for Adtech Transparency
The digital advertising ecosystem—a sprawling, multi-billion-dollar labyrinth of data brokers, ad exchanges, and tracking pixels—has long operated behind a veil of technical complexity. For the average internet user, the mechanism behind why a specific ad appears on a mobile app or website has remained a "black box." However, a newly launched, free service named DecryptAds is changing the game by scraping, correlating, and simplifying the semi-public data that governs our digital footprint.
By aggregating files like ads.txt, app-ads.txt, and sellers.json, DecryptAds provides a clear, searchable, and often alarming map of the entities harvesting user data. For researchers, privacy advocates, and security professionals, this tool represents a pivotal shift from passive observation to active, data-driven investigation of the adtech supply chain.
The Mechanics of Transparency
At the core of the digital advertising industry are standardized files that websites and apps publish to declare who is authorized to buy their ad inventory. These files are designed to prevent fraud, but they are rarely read by human eyes. DecryptAds automates the retrieval and analysis of these declarations:
- ads.txt: A public record of all adtech companies and data brokers authorized to run ads or harvest data on a specific website.
- app-ads.txt: The equivalent for mobile and smart TV applications, identifying entities that track users across portable devices.
- buyers.json/sellers.json: Detailed files that disclose the chain of custody for ad inventory, revealing the middlemen—buying, selling, and reselling—that facilitate the modern ad economy.
Zach Edwards, the Chief Research Officer for DecryptAds and a veteran threat researcher at Infoblox, notes that this information was never intended to be siloed. "It’s an adtech tool, but we’re trying to approach it from a security perspective," Edwards explains. "It’s built for privacy and security use cases that have been dramatically underserved."

Chronology of the Adtech "Wild West"
The necessity for a tool like DecryptAds stems from years of unchecked growth in the adtech sector. Historically, the industry has relied on "self-policing," a strategy that has proven ineffective against the rising tides of malvertising and AI-generated "slop" content.
In recent years, the landscape shifted as data privacy laws in jurisdictions like California, Oregon, Texas, and Vermont began forcing data brokers to disclose their activities. This legal pressure created a trickle of transparency that DecryptAds now collects into a floodlight. The service’s emergence follows a period of heightened scrutiny surrounding how streaming hardware—such as the H96 TV sticks—and various mobile applications were found to be covertly participating in click-fraud rings and data harvesting, often disguised as legitimate advertising traffic.
Supporting Data: The Case of ESPN and Global Risk
To illustrate the depth of the data, a quick search for a high-traffic site like espn.com yields 143 ad partners and 19 registered data brokers. Of these, nearly half are actively collecting geolocation data from non-blocking visitors, with others harvesting device fingerprints and sensitive personal information.
The most concerning findings, however, relate to "geo-risk." DecryptAds highlights adtech partners based in jurisdictions that are either adversarial to the U.S. or maintain deep financial ties to such nations, including Russia, China, and the United Arab Emirates (UAE).

For example, DecryptAds flags Between Digital, an entity with a New York presence that is actually a Russian firm. Their financial dealings are processed through Alfa Bank, one of Russia’s largest private institutions and a target of U.S. sanctions. Despite these ties, Between Digital is found on the approved ad-partner lists of numerous U.S. military news outlets, including Army Times and Defense News. Currently, Between Digital is collecting data across approximately 55,000 websites, highlighting the massive, systemic security risks inherent in the current ad supply chain.
Official Responses and Industry Accountability
The adtech industry is notoriously opaque when it comes to "quiet removals." When an ad network identifies a partner as a bad actor—perhaps due to involvement in fraud or malware distribution—they often remove that entity from their sellers.json files without a public announcement.
This creates a dangerous information gap. Security researchers, unaware of why an entity was blacklisted, struggle to track the evolution of threat actors. DecryptAds addresses this through its "Quiet Removals Feed," which tracks when and where specific domains are purged from the digital ecosystem.
"The problem we have right now is that for years we’ve had almost no one policing these files," Edwards says. "One day a bad actor is there, the next they are gone. By correlating these removals across different exchanges, we can finally begin to hold these networks accountable for who they allow into their ecosystem."

Implications for Security and Privacy
The implications of this visibility are profound, particularly regarding "malvertising"—the injection of malicious code into legitimate ad networks. Malvertising is increasingly moving away from high-traffic, well-protected sites like ESPN and toward "AI slop" farms. These are low-quality websites generated by machines to maximize ad impressions with minimal overhead. Because these sites lack the resources or motivation to employ sophisticated security filters, they become "greased rails" for zero-click malware payloads.
The solution, according to Edwards, lies in the "Supply Chain Object" (SCO). If major ad networks were to publicly share the SCO—which details the full path of an ad impression from publisher to buyer—security teams could pinpoint the exact moment a malicious payload was injected. Currently, this data is kept private, protecting the networks but leaving the public vulnerable.
What Can Users Do?
For the individual, the findings presented by DecryptAds underscore the importance of taking control of the browser environment.
- Block Ads at the Source: Using browser extensions like uBlock Origin Lite is the baseline for protection. For those seeking more robust security, a hardware-based solution—such as a Raspberry Pi running Pi-hole—is the gold standard. By acting as a DNS sinkhole, a Pi-hole blocks ads and trackers for every device on a local network, including smart TVs and IoT devices that cannot host traditional browser extensions.
- Reject the App Trap: Whenever possible, avoid downloading standalone mobile apps for services that can be accessed via a web browser. Apps are frequently used as "data vacuums," collecting far more granular information than a browser session would allow.
- Audit Your Environment: The rise of "AI slop" and the proliferation of geo-risk ad partners mean that the apps and sites you visit are likely part of a much larger, global surveillance network. Using the DecryptAds search tool allows users to perform their own due diligence before installing an app or trusting a website with their personal data.
As the digital world continues to be flooded with AI-generated content and increasingly complex ad-tracking schemes, the work performed by platforms like DecryptAds is no longer just a technical luxury—it is a fundamental necessity for a secure and private internet. By turning the lights on in the adtech basement, researchers are finally giving users the tools to see who is watching them, where their data is going, and how to stop the cycle.
