For the average internet user, the digital experience often feels like a series of disjointed interactions: a sports update on ESPN, a scroll through a news site, or a quick game on a mobile app. Beneath the surface, however, these interactions trigger a high-speed, automated auction—a global "adtech" ecosystem that harvests data, tracks behavior, and serves content with terrifying efficiency. Until now, the inner workings of this ecosystem have been largely obscured, hidden behind complex, semi-public files that only industry insiders could interpret.
The launch of DecryptAds, a powerful, free, and public-facing analytical service, is fundamentally changing that dynamic. By scraping and correlating fragmented adtech data, the service provides an unprecedented look at the entities tracking users across websites and mobile applications.
The Mechanics of Transparency: What DecryptAds Uncovers
The advertising industry relies on a set of standardized, publicly available files designed to foster transparency. These include:
- ads.txt: A list of authorized digital sellers, revealing which adtech firms and data brokers are permitted to monetize a specific website.
- app-ads.txt: The mobile and Smart TV equivalent, identifying entities harvesting data from or serving ads within applications.
- buyers.json/sellers.json: Detailed files that disclose the chain of custody for ad inventory, tracking who is buying, selling, or reselling access to your eyeballs.
While these files are technically "public," they are rarely accessible in a meaningful way. "It’s an adtech tool, but we’re trying to approach it from a security perspective," explains Zach Edwards, Chief Research Officer for DecryptAds and a threat researcher at Infoblox. Edwards, who co-founded the project with a small team, argues that the data is only useful when cross-referenced. By building a comprehensive map of the advertising ecosystem, DecryptAds exposes connections that were previously invisible.

Chronology and Evolution of the Adtech Threat
The push for adtech transparency began as an industry-led effort to combat "spoofing"—where fraudulent actors pretend to be legitimate websites to siphon off advertising dollars. However, the rise of "AI slop" (low-quality, machine-generated websites) and the increasing sophistication of malicious advertising (malvertising) have turned this into a critical security issue.
In recent months, the landscape has shifted rapidly. New state-level legislation in California, Oregon, Texas, and Vermont has forced data brokers to register if they handle consumer data, creating a paper trail that DecryptAds now aggregates.
As recently as July 2026, investigations by companies like Bitsight highlighted how hardware devices—such as the H96 streaming sticks—were being used to spoof mobile traffic to "slop" websites. This wasn’t just a nuisance; it was a complex supply-chain attack. DecryptAds provides the connective tissue to these incidents, allowing researchers to trace a single, shady seller ID across hundreds of domains, exposing the infrastructure behind botnets and AI-generated content farms.
Supporting Data: The ESPN and "Geo-Risk" Case Studies
To understand the scale of the tracking, one only needs to look at the profile of a mainstream giant like espn.com. DecryptAds reveals that the site hosts 143 ad partners and 19 registered data brokers. Nearly half of these brokers are collecting geolocation data from users who haven’t enabled ad-blocking, while others are harvesting device fingerprints and sensitive personal information.

The "Geo-Risk" Warning System
Perhaps the most alarming feature of DecryptAds is its "Geo-Risk" indicator. The platform flags advertising partners based in high-risk regions—specifically Russia, China, and nations with deep financial ties to those states, such as the UAE or Cyprus.
For example, DecryptAds identifies that espn.com interacts with several adtech entities based in Russia or the UAE. One notable firm, Between Digital, lists a New York address but is identified by DecryptAds as a Russian entity. Their financial backend, according to public dossiers, is processed through Alfa Bank—a Russian financial institution under U.S. sanctions.
This pattern is not limited to sports entertainment. An analysis of U.S. military-related news sites—including armytimes.com and defensenews.com—shows these outlets also allow Between Digital to serve ads. This raises significant national security questions: why are entities connected to sanctioned nations allowed to track the browsing habits of military personnel and defense industry observers?
Official Responses and Industry Accountability
The adtech industry is notoriously opaque. When ad exchanges identify fraudulent behavior, they often remove the offending party from their sellers.json file silently, without notifying the public or other partners.

"One day it was there, the next it was gone," Edwards notes. "If you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once."
To combat this, DecryptAds maintains a "Quiet Removals Feed." By tracking these deletions across exchanges, the service highlights the "bad actors" that the industry is trying to scrub from its records without transparency.
Despite the growing utility of these tools, the major ad networks remain reluctant to share the "Supply Chain Object" (SCO). The SCO is structured data that would allow buyers to see every intermediary in the bidding process. Currently, this data is kept server-side, preventing researchers from identifying who exactly served a malicious payload in a "zero-click" attack. Edwards believes that until the industry is forced to expose the SCO, identifying the culprits behind sophisticated malvertising campaigns will remain an uphill battle.
Implications: The Surveillance Future and User Defense
The implications of these findings are profound. We are no longer just talking about intrusive ads; we are talking about a global surveillance infrastructure that spans from our Smart TVs to our browsers, often funded by unsuspecting advertisers and managed by entities in adversarial nations.

The Strategic Necessity of Blocking
Given the current state of the industry, security experts are increasingly advocating for a "block-first" approach.
- Desktop/Laptop: Tools like uBlock Origin Lite remain the gold standard.
- Mobile: While browser-based blocking is effective, mobile apps present a unique challenge. Many apps are designed specifically to bypass browser-based privacy protections.
- Network Level: For those with technical aptitude, a Raspberry Pi running Pi-hole offers a robust, network-wide solution that filters traffic at the DNS level before it even reaches the device.
The "App Trap"
The most vital takeaway for the average user is the danger of the "mobile app push." Many services aggressively nudge users to download an app, claiming a "better user experience." In reality, these apps often serve as a "greased rail" for data collection and ad tracking. They grant developers deeper access to device identifiers, geolocation, and usage patterns that are significantly harder to block or audit than standard web traffic.
As the lines between consumer technology, AI-generated content, and foreign data harvesting continue to blur, the tools provided by platforms like DecryptAds are no longer just for developers or security researchers. They are essential navigational charts for anyone attempting to retain a modicum of privacy in an era of total digital visibility.
"If we’re not breaking down this ad data," Edwards concludes, "we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis." By shining a light on the hidden conduits of the internet, DecryptAds has provided the public with the first real opportunity to see exactly who is watching them—and why.
