Skip to main content
CybersecurityPrivacy & Surveillance

DecryptAds Exposes Adtech Ecosystem's Hidden Trackers

City office building with digital billboards in background and person in foreground.

“A search in DecryptAds for the hugely popular sports network espn.com reveals 143 ad partners and 19 registered data broker domains,” the new service reports — a single search that, on its face, maps an ad supply chain far deeper than most readers expect.

What DecryptAds collects and why it matters

DecryptAds is a free service that continuously scrapes the public ad-technology declaration files that websites and apps publish. The site pulls ads.txt and app-ads.txt records — the lists sites and apps publish to declare which adtech firms may run ads or collect data — as well as buyers.json and sellers.json files that show entities buying, selling or reselling ad inventory. The service also offers a Legal Dossier lookup, a quiet removals feed that records sellers.json deletions, and an API for automated queries.

espn.com as a case study: partners, brokers, and data types

DecryptAds’ espn.com profile shows the scale and detail these files can expose: 143 ad partners plus 19 registered data broker domains. The dataset is already becoming richer because four states — California, Oregon, Texas and Vermont — now require data brokers to register when they buy or sell consumers’ data from residents of those states, enabling DecryptAds to identify specific broker domains and their declared collection behaviors. According to DecryptAds, almost half of the listed brokers collect geolocation data from espn.com visitors who do not block ads; three disclose that they collect device fingerprints and sensitive personal information.

Between Digital, geo-risk flags, and financial links

DecryptAds applies a “Geo Risk” warning to partners based on declared bases of operation. The service flagged four advertising entities connected to espn.com as being based in Russia, China or the United Arab Emirates (UAE). One firm, Between Digital, lists a New York address but is flagged as a Russian firm in DecryptAds’ dossier — noting that its publisher offers are processed through Alfa Bank. The dossier also shows Between Digital is permitted to serve ads on multiple U.S. military news sites and is declared across roughly 55,000 partner websites in DecryptAds’ dataset. DecryptAds’ analysis of Between Digital’s app-ads.txt entries further shows the firm frequently appears as both publisher and reseller in its own portfolio, a setup that can create conflicts of interest by routing spending toward owned or affiliated inventory.

Quiet removals, sellers.json, and the missing supply-chain object

DecryptAds’ quiet removals feed catalogs instances where a seller disappears from sellers.json files on exchanges — a deletion that ad exchanges commonly perform when they suspect fraud or malicious activity but do not publicize. Zach Edwards, chief research officer for DecryptAds and a threat researcher at Infoblox, described the problem: “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone.” Edwards and DecryptAds argue that another piece of structured data — the supply chain object (SCO) attached to bid requests — is crucial for tracing exactly which intermediary or buyer delivered a malicious ad. Without SCO, DecryptAds contends, investigators can see a malicious zero-click redirection but not the full chain of sellers and resellers that led to it; exposing SCO server-side, Edwards says, would make it easier to identify culprits.

Malvertising, AI slop sites, H96 devices, and the Fengwo Group

The article ties DecryptAds’ findings to a broader malvertising problem centered on newly created “AI slop” content farms. These machine-generated sites, the article says, typically don’t pay for ad-protection tools and instead sign up low-quality partners, creating “a greased rail” for malicious ads. Research from Bitsight — cited in the piece — found H96 streaming sticks that rent out users’ internet connections and spoof themselves as mobile phones to click ads on AI slop sites. Bitsight linked the malicious apps common to H96 devices to the Fengwo Group and found that the same entity also ran the network of AI slop landing pages those devices clicked. DecryptAds’ Legal Dossier on one such domain showed shared seller IDs across low-quality gaming sites and Yandex-based properties, illustrating how seller identifiers can reveal broad, cross-site advertising networks.

What this means for end users, security teams, and publishers

  • End users: The article’s practical advice is blunt — “The only sane reaction … is to block all online ads outright.” Recommended options include uBlock Origin Lite (desktop and Android-compatible browsers), Adblock Plus for iPhone and iPad, and NoScript for users willing to manage script approvals. For network-level protection, the piece recommends a Raspberry Pi running Pi-hole to sinkhole ad domains for every device on a local network.
  • Security teams and researchers: DecryptAds’ API, Legal Dossier, quiet removals feed and SCO advocacy provide tools and data points to trace malvertising and low-quality supply chains. Edwards stresses that exposing the supply chain object in bid requests would materially improve attribution for malicious ads.
  • Publishers and app operators: The findings underline the importance of monitoring the declared ad partners in ads.txt and app-ads.txt and watching for unexpected resellers or cross-listed seller IDs. The article notes that apps frequently collect more precise data than websites and that publishers pushing app installs should be aware of the privacy and tracking implications.

DecryptAds does not eliminate complexity, but by scraping, correlating and surfacing ad-technology declarations it makes supply-chain signals visible that were previously scattered and opaque. For readers and defenders trying to block malvertising or limit tracking, the piece closes with a concrete posture: inspect the declarations, block ads aggressively, and press for the supply-chain visibility that Edwards says is still too rare.

https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/