DecryptAds Tool Reveals Hidden Ad Trackers on Websites

A new free tool called DecryptAds reveals the hidden network of ad trackers and data brokers behind websites.

By Central
DecryptAds cross-references ads.txt and sellers.json files to uncover hidden adtech relationships.
Highlights
  • DecryptAds scrapes public ads.txt and sellers.json files to map the hidden ad supply chain.
  • The tool reveals broken cross-references and cloned declaration sets across unrelated domains.
  • Zach Edwards designed DecryptAds for privacy and security use cases that were previously underserved.

The digital advertising ecosystem has long operated as a murky, multi-layered machine where countless intermediaries buy, sell, and resell the right to place an ad in front of you. For the average internet user, determining exactly which companies are tracking your browsing habits, harvesting your location data, or serving the ads that appear on a given website has been nearly impossible. That information, while technically public, has remained locked inside fragmented files and proprietary databases controlled by the largest advertising platforms. A new, free service called DecryptAds is changing that by scraping and cross-referencing the adtech declaration files that websites and apps are required to make public, revealing the hidden network of trackers, data brokers, and ad partners operating behind the scenes. The tool offers an unprecedented window into the supply chain of online advertising, and its implications for privacy, security, and corporate accountability are profound.

What Is DecryptAds and How Does It Uncover Hidden Trackers?

DecryptAds is a free, publicly accessible service that continuously scrapes the files websites and mobile applications publish to disclose which companies are authorized to run ads or collect user data. These files — ads.txt, app-ads.txt, and sellers.json / buyers.json — have been mandated by industry bodies and, in some cases, by emerging state privacy regulations, but they have historically been difficult for non-specialists to parse and analyze in any meaningful way.

The ads.txt file lists all the adtech companies and data brokers that may run ads or harvest data from a given website. The app-ads.txt file does the same for mobile and smart TV applications. The sellers.json and buyers.json files document the entities buying, selling, or reselling advertising inventory for a given site or app. On their own, each file provides a narrow, incomplete snapshot. The power of DecryptAds lies in its ability to correlate these declarations, building a comprehensive picture of the advertising ecosystem for any website or app in its database.

Zach Edwards, chief research officer for DecryptAds and a threat researcher at the security company Infoblox, explained that the service was created because adtech data locked inside these files is only truly useful when it can be cross-referenced to reveal the full supply chain. “It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”

Why Cross-Referencing Adtech Files Matters for Security

The core insight behind DecryptAds is that supply-chain integrity issues in advertising rarely live inside a single file. As the service explains on its website, these problems “show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.”

Edwards outlined several critical use cases for the tool. Security researchers can use it to trace the source of malicious ads that attempt to deliver malware to targeted users. Investigators can identify ad networks operating out of adversarial nations. And analysts can detect the rapidly growing number of AI-generated slop websites and apps that are flooding the internet with low-quality, machine-produced content designed solely to generate ad revenue. These threats are virtually impossible to detect by examining a single ads.txt or app-ads.txt file in isolation.

The ESPN Example: 143 Ad Partners and 19 Data Brokers

A search for espn.com on DecryptAds illustrates the scale of the tracking ecosystem. The sports network’s ads.txt and app-ads.txt files list 143 ad partners and 19 registered data broker domains. This data broker information is becoming increasingly available because four states — California, Oregon, Texas, and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states.

DecryptAds reports that nearly half of those 19 data brokers are collecting geolocation data from espn.com visitors who are not blocking ads, while another three brokers disclose that they collect device fingerprints and sensitive personal information. The visual representation of the ad supply chain for ESPN, generated by DecryptAds, reveals a dense, interconnected web of intermediaries that most visitors to the site would never suspect.

High-Risk Ad Partners: Geo-Risk Warnings and Sanctioned Connections

One of the most striking features of DecryptAds is its ability to flag advertising partners based on geographic risk. The service displays conspicuous warnings when an adtech partner of a website or app is based in what it classifies as “geo-risk” areas — specifically China, Russia, and countries with strong financial and political ties to both, such as Cyprus and the United Arab Emirates (UAE).

According to DecryptAds, espn.com works with four different advertising entities that are based in Russia, China, or the UAE. Among them is the adtech firm Between Digital, which lists a New York address but is flagged by DecryptAds as a Russian firm. The dossier on Between Digital reveals that its publisher offers are processed through Alfa Bank, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 following Russia’s invasion of Ukraine.

The implications extend far beyond sports media. A search for several top U.S. military news websites — including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com, and federaltimes.com — shows that all of them allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Pivoting on Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards noted that Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of its portfolio. “It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” he said. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”

The Opera Browser Case: Chinese Ownership and a Web of Trackers

The Opera web browser remains quite popular, and many users may be unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech, even though its operational headquarters remain in Oslo, Norway. Opera.com’s profile at DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia, and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent only seven percent of the total adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.

One of the most powerful features of DecryptAds is its Legal Dossier lookup. Each search takes several minutes, but the results provide a wealth of information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.

The value of this feature was demonstrated in a recent investigation by Bitsight researchers. They found that an extremely popular line of TV streaming sticks called H96 quietly rent out each user’s internet connection to strangers. When these devices are not being used to stream pirated video content, they are spoofing themselves as mobile phones and clicking ads on AI-generated slop websites. Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the Fengwo Group — also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices.

A DecryptAds legal dossier on the now-dormant Fengwo Group domain name medicalbeautyhub.com shows that it shares a seller ID (1674071) with a gaming website, giacoloredstones.com, which features yet another seller ID (103488000). Pivoting on that latter ID reveals hundreds of active websites within Russia’s Yandex ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads. This trail of cross-referenced seller IDs provides a concrete investigative pathway that would have been impossible to follow using traditional tools.

Quiet Removals: When Ad Networks Silently Drop Suspicious Partners

Edwards explained that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without publicly disclosing their suspicions. This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others.

To address this visibility gap, DecryptAds features a quiet removals feed that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name. “The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”

The quiet removals feed effectively exposes these hidden decisions, giving researchers and the public a real-time view into which entities are being silently de-platformed by the ad exchanges.

Malvertising and the AI Slop Epidemic

Malvertising — the practice of inserting malicious ads that deliver malware or redirect visitors to phishing pages — remains a persistent threat in the adtech industry. But Edwards noted that these malicious ads are far more common on newly generated AI slop websites than on high-traffic destinations, which typically employ a variety of technologies and third-party tools to quickly flag bad ads.

“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather some lower quality content farm and someone just went there because it came up in a search.”

These AI slop websites are populated with machine-generated blog posts and images, covering themes from home improvement and decorating to food recipes, hunting, cars, and consumer technology. Organizations that get hit with malicious ads are often at a loss for next steps, unaware that in most cases the answer lies within the website’s own ads.txt or app-ads.txt file. “A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” Edwards said.

The Supply Chain Object: The Missing Piece for Malware Attribution

Edwards maintains that truly addressing the malvertising and AI slop problems will require more data sharing by the major ad networks. Specifically, he says those platforms do not broadly share what is known as the supply chain object (SCO) — structured data attached to each advertising bid request that lets buyers see every seller, reseller, and intermediary involved in passing an ad impression from the publisher to the final buyer.

“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained. “You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”

DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms, making it possible to incorporate these supply-chain checks into broader security workflows.

What Can You Do to Protect Yourself?

The examples detailed above make one thing clear: the only sane response is to block online ads entirely. This approach is broadly endorsed by security experts because it makes it significantly harder for adtech firms and data brokers to build detailed profiles on you and track your movements across the web and in the real world.

For those primarily browsing via a desktop or laptop browser, uBlock Origin Lite is an excellent, free, and well-maintained open-source option. It also works with mobile browsers like Firefox, but only on Android-based devices. Adblock Plus is a decent option for iPhone and iPad users. Both Adblock and uBlock Origin support custom blocking rules from easylist.to, which publishes a frequently updated list that removes most advertisements from webpages.

The well-established browser extension NoScript blocks all non-approved JavaScript code and generally does a fine job preventing most ads from loading. However, script blockers like NoScript may not be suitable for average users who do not enjoy constantly refereeing which scripts should be allowed to load for each site to display properly.

For more technically inclined readers, a hardware approach at the local network level is the cheapest, most secure, and most scalable solution. A tiny, low-cost computer known as a Raspberry Pi can be turned into a powerful ad blocker for all devices on a local network when fitted with a microSD memory card and a free program called Pi-hole. Once configured properly and the router’s network settings are changed to use the Pi-hole’s DNS sinkhole and DHCP servers, it prevents ads from displaying on any device connected to that network.

It is important to note that ad blockers often do little to block ads or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly to access the site’s services and content more fully. The reality is that these companies push their apps because they make it easier to keep you on their platforms longer and to collect — and in many cases resell — far more precise data about who, what, and where you are. Companies pushing hardest for app installs also tend to liberally opt everyone in to having their data used to train large language models. Be cautious about the apps you install on your mobile devices, including any smart TVs, and use DecryptAds to investigate their privacy practices and relationships with adtech firms.

The launch of DecryptAds marks a significant step toward transparency in an industry that has long thrived on opacity. By making the adtech supply chain visible and searchable, the tool empowers researchers, journalists, and ordinary users to hold websites and advertising networks accountable for who they do business with. The data has always been public. Now, for the first time, it is also accessible, correlated, and actionable. The question that remains is whether the industry will embrace this transparency or find new ways to obscure its operations. The answer will determine not just the future of online advertising, but the future of privacy and security on the open web.

Share This Article