Manav.id
Platforms ยท 19 min read

You are paying for attention that nobody paid

Published estimates of what advertisers lost to invalid traffic in 2025 range from about $25 billion to about $165 billion. Those numbers cannot all be describing the same thing, and understanding why they differ tells you more about the problem than any of them do individually. The fix is not a better detector. It is proof attached to the events that actually carry money.

Picture a demand generation lead at a B2B software company on a Tuesday morning. Last quarter she spent a little over three million dollars across paid search, paid social, and a handful of programmatic partners. The dashboards are green. Cost per lead came in eleven percent under target. Her quarterly review slide practically writes itself.

Then the sales development team sends over their notes. Of the roughly four thousand leads marketing handed them, a large share went nowhere in a specific and uncomfortable way. Not "we called and they were not interested," which is normal. The phone numbers did not connect. The company names did not resolve to companies. The email addresses accepted mail and never opened it. The form fills happened at three in the morning local time, in bursts, from residential IP addresses in the right country.

She goes to her invalid traffic vendor and asks the obvious question: how many of the conversions I paid for last quarter were people? The answer that comes back is a percentage. It is a good percentage. It is also, when she reads the methodology, an estimate produced by a model that scores traffic patterns. It is not a list. Nobody can hand her four thousand rows and mark which ones were human, because nobody in the chain ever established that in the first place.

This is the shape of the whole problem, and it has almost nothing to do with how clever the bots are. The advertising industry built enormous, genuinely sophisticated infrastructure for measuring traffic, and almost none for attributing an event to a human. When the question is "was a person here," measurement can only ever answer "probably," and the confidence interval is set by an adversary who gets a vote.

Short answer. Published estimates of advertiser losses to invalid traffic in 2025 range from roughly $25 billion to roughly $165 billion, depending on whether the source counts impressions, clicks, or conversions, and whether it measures detected fraud or extrapolates undetected fraud. Every one of those estimates is produced by a detector. A presence receipt takes a different approach: at the paid event itself, a person proves they are present, and the advertiser gets an artifact they can verify rather than a score they must trust.

How much ad spend is actually lost to bots?

Here are three serious, publicly reported figures from the same rough period. Read them together, because the disagreement is the lesson.

Anura, an ad fraud vendor, published an executive brief in June 2026 estimating that advertisers lost roughly $165 billion to invalid traffic in 2025, with invalid traffic rates running between 25 and 28 percent through that year and climbing sharply into 2026 (Anura, reported via eMarketer, June 2026).

Spider AF, another vendor in the same category, analysed just over four billion paid ad clicks and reported a global ad fraud rate of about 5.58 percent in the first half of 2026, attributing roughly $25.3 billion in losses (Spider AF 2026 report, reported via Yahoo Finance).

Broader industry estimates, including work from research firms tracking the category over several years, have put annual global losses somewhere in the $80 billion to $100 billion band.

Separately, Imperva's 2026 Bad Bot Report put automated traffic at about 53 percent of all web traffic in 2025, with a meaningful share of requests classified as outright malicious, and reported a large year over year increase in bot activity attributed to AI tooling (Imperva, part of Thales, April 2026).

So: is it 25 billion, 80 billion, 100 billion, or 165 billion? The honest answer is that these numbers are not competing estimates of one quantity. They are estimates of different quantities that share a name.

Why the estimates cannot all be right

There are four independent reasons two credible ad fraud figures can differ by a factor of six, and none of them require anyone to be dishonest.

The first is the denominator. A percentage of global digital ad spend and a percentage of measured paid clicks are different fractions of different pools. Global digital ad spend crossed into the high hundreds of billions of dollars annually. A single vendor's measured click sample, however large, is a slice of the market that vendor's customers bought. Multiply a small percentage by a very large denominator and you get a big number. Multiply a larger percentage by a smaller denominator and you can get a smaller one. Both are arithmetic done correctly.

The second is the definition. "Invalid traffic" and "fraud" are not synonyms, and the gap between them is enormous. Invalid traffic, in the Media Rating Council's framing, includes general invalid traffic, which covers things like known data centre traffic, declared crawlers, and internal testing, alongside sophisticated invalid traffic, which is the adversarial category most people mean when they say fraud. A large share of invalid traffic is not somebody stealing from you. It is a search engine crawler. If one report counts all invalid traffic and another counts only sophisticated invalid traffic, they will differ by a lot before anyone measures anything.

The third is the unit. Impressions, clicks, and conversions have wildly different prices and wildly different fraud economics. A fraudulent impression costs the advertiser a fraction of a cent. A fraudulent lead in a category where a real lead is worth two hundred dollars costs approximately two hundred dollars. A report that measures impression fraud and a report that measures conversion fraud can produce opposite conclusions about severity from the same underlying activity, because the money is not distributed evenly across the funnel.

The fourth is detected versus estimated. This is the most important one and it is the one buried deepest in methodology sections. A vendor can report what it caught, which is a floor and is verifiable in principle. Or it can model what it thinks it missed, which is a much larger number and is not verifiable by construction, because if you could verify it you would have caught it. Both are legitimate exercises. They are not the same exercise, and headline numbers rarely say which one they are.

How to read an ad fraud statistic

When you see a figure, ask five questions in order. What is the denominator, spend or events? Is this invalid traffic or fraud specifically? Which unit, impressions, clicks, or conversions? Is this detected or modelled? And whose sample is it?

That last one deserves its own note, because it applies to every vendor number in this article including the ones cited above. A fraud vendor's telemetry comes from customers who bought a fraud vendor. Companies that suspect they have a fraud problem are more likely to buy fraud detection than companies that do not. This is textbook selection bias and it pushes measured rates up relative to the true population rate. That does not make the numbers useless. It makes them a measurement of a particular, non random slice of the market, and you should mentally attach that caveat to every percentage in this space, including any that Manav ever publishes.

None of this is a reason to dismiss the problem. Every serious source, using every methodology, finds that a meaningful double digit share of paid digital activity has no human behind it. The range of estimates tells you the industry cannot measure this precisely. It does not tell you the problem is small.

Why does detection keep losing ground?

The entire defensive apparatus of the advertising industry is a measurement apparatus. Invalid traffic vendors score traffic. Verification vendors score placements. Accreditation bodies audit the scorers. It is a large, competent, well funded system, and it is structurally incapable of producing the artifact the demand generation lead actually needs.

The detector reads signals the adversary controls

Every traffic based detection method works by examining properties of a request: the IP address and its reputation, the user agent string, the TLS fingerprint, the timing and pattern of mouse movement, the presence and consistency of browser APIs, the shape of the session. The adversary supplies all of these. Every single one.

Think of it as trying to identify a forger by examining the paper. For a long time this worked, because good paper was expensive and forgers used cheap paper. The method was never actually about paper quality. It was about the cost asymmetry. When paper got cheap, the method stopped working, and no amount of improving your paper analysis brings it back.

The equivalent cost asymmetries in ad fraud have collapsed one by one. Residential proxy networks made trustworthy looking IP addresses cheap. Headless browser frameworks made a complete, consistent browser environment cheap. And browser driving agents, which arrived as consumer products through 2025 and 2026, made human like interaction patterns cheap, because they are not simulating a human using a browser, they are a program using a browser the way a human would, which is a different and much harder thing to distinguish.

It is worth noting that this is not a controversial claim among the vendors themselves. hCaptcha, a bot defence company, states on its own site that traditional fingerprints are becoming useless, because browser makers are working to break them and attackers can emulate them easily. When a detection vendor writes the obituary for detection signals on its own homepage, the argument is over.

The incentive problem nobody names

There is a second reason detection plateaus, and it is structural rather than conspiratorial, so it deserves to be stated carefully and without accusation.

Most parties in the programmatic chain are compensated on volume. Publishers are paid for inventory sold. Exchanges take a percentage of spend. Agencies have historically been compensated in ways connected to media budgets. Verification vendors are paid by the parties whose traffic they grade, which is a genuinely awkward position even when everyone in it is acting in good faith.

The result is not fraud. The result is that the system's collective appetite for finding fraud is uneven, and the equilibrium settles at a tolerable rate rather than at zero. A tolerable rate is a business decision. It is a reasonable business decision. But an advertiser should understand that the number they are quoted is the output of a system that is optimising for tolerability, not elimination, and should price accordingly.

The Association of National Advertisers described invalid traffic in June 2026 as programmatic's hidden tax, which is the right frame. A tax is something you budget for. It is not something you expect the tax collector to help you avoid.

What would proof look like instead of detection?

Here is the shift. Stop trying to grade traffic, which is a population you do not control and cannot interrogate. Start proving the specific events that carry money.

This works because of an asymmetry that the industry has not exploited. At an impression, there is no human interaction, no consent moment, and a per event value measured in fractions of a cent. There is nowhere to put a proof and no budget to pay for one. But at a conversion, a person is already present, already acting, already submitting something. The human is right there. All that is missing is an artifact establishing it.

Which events can carry a proof, and which cannot

Be rigorous about this, because the failure mode of every technology in advertising is claiming to cover the whole funnel. It cannot. Here is the honest map.

Funnel stageTypical volumeCan a presence proof attach?Why
ImpressionBillionsNoNo interaction and no consent moment; per event value is a fraction of a cent
Viewable impressionBillionsNoViewability is a rendering property, not a human act
ClickMillionsRarelyThe click is the navigation; inserting a step before value is delivered damages the funnel
Landing page viewMillionsSometimesOnly where the page already asks for an action
Lead form submitThousandsYesHuman present and already acting; the form is the proof moment
Trial start or signupThousandsYesHigh value per event, existing friction budget
App install with first meaningful actionThousandsYesThe first action step is the attachment point, not the install
PurchaseThousandsYesHighest value per event, established checkout friction

Read the right hand column of that table and you can see the whole strategy. Proof attaches where value concentrates and where a human is already doing something. That is roughly the bottom third of the funnel, and it is also where roughly all of the recoverable money is, because a fraudulent lead costs you two hundred dollars and a fraudulent impression costs you a twentieth of a cent.

This is a smaller claim than "we solve ad fraud." It is also a claim that survives contact with an adversary, which the larger one does not.

What does a presence receipt actually contain?

At the conversion step, the visitor completes a brief interaction on their own device. The device produces a signature. The advertiser receives a receipt. Here is what is in it.

{
  "typ": "manav.presence.v1",
  "event": "conversion",
  "event_id": "lead_9f2c1a4b",
  "rp": "advertiser.example",
  "campaign": "q3-enterprise-demo",
  "human_key": "hk_5d7f81c0a2...",
  "assurance": "device-bound",
  "iat": "2026-09-12T14:31:07Z",
  "exp": "2026-09-12T14:36:07Z"
}

Walk the fields, because each one is doing specific work and the omissions matter as much as the contents.

event_id ties the receipt to one conversion in the advertiser's own system, so a receipt cannot be reused against a different event. rp names the relying party, which scopes the whole artifact: a receipt issued for one advertiser does not verify for another.

human_key is the interesting one. It is a one way key derived on the device, scoped to this relying party. It is stable for the same person at the same advertiser, which is what gives you uniqueness, so you can tell that four hundred leads came from four hundred people rather than from four people submitting a hundred forms each. It is not reversible to a person, it is not portable to another advertiser, and it is not an identity. The advertiser learns "these are distinct humans" and learns nothing about who they are.

assurance records how the presence was established. iat and exp keep the window tight, so a captured receipt has minutes of value rather than months.

Note what is absent: no name, no email, no device fingerprint, no IP address, no behavioural profile, no cross site identifier. There is nothing in this object that helps anyone track a person across the web, which is not an accident and not a compromise. It is the point.

Verification runs against a published key, with no callback to us:

// Fetch the published key set once, cache it, verify offline thereafter.
const keys = await fetchOnce('https://manav.id/.well-known/manav-keys')

function verifyConversion(receipt, expected) {
  if (!verifyEd25519(receipt, keys)) return { ok: false, why: 'bad signature' }
  if (receipt.rp !== expected.rp) return { ok: false, why: 'wrong relying party' }
  if (receipt.event_id !== expected.event_id) return { ok: false, why: 'event mismatch' }
  if (now() > Date.parse(receipt.exp)) return { ok: false, why: 'expired' }
  return { ok: true, humanKey: receipt.human_key }
}

Four checks. No vendor call at verification time, which means your reporting does not break when someone else's service does, and no third party learns which advertisers a person converted with. Collect the human_key values across a campaign, count the distinct ones, and you have something no detection vendor can produce: a count of humans, evidenced, rather than a score.

The number this produces

The output that matters to a CFO is a single ratio per campaign: of the conversions we were billed for, what share carry a verifiable human presence receipt? Call it the human verified rate. It is not an estimate and it is not a model output. Every point in it corresponds to an artifact you can re verify a year later during an audit.

A campaign at ninety four percent and a campaign at thirty one percent are telling you something concrete about two partners, and the conversation with the thirty one percent partner is a different conversation than the one you can have today, because today it ends in duelling methodologies and a negotiated make good.

Does this work without tracking?

It works better without tracking, and this is worth spelling out because the reflexive assumption in advertising is that more certainty requires more surveillance.

The current detection stack is built on exactly the signals that privacy regulation and browser vendors have spent a decade dismantling: third party cookies, device fingerprints, cross site identifiers, behavioural profiles. Every one of those is under pressure, and the pressure is not going to reverse.

A presence receipt runs the other direction. It needs no cross site identifier because it is scoped to one relying party. It needs no behavioural profile because it does not infer humanity from behaviour, it establishes it from a signature. It needs no persistent tracking because the proof happens at the moment of the event and expires minutes later. Under GDPR framing, the data minimisation argument is straightforward: a one way, relying party scoped key is dramatically less personal data than the fingerprinting stack it replaces.

The face, where a face is used at all, is matched on the device and never uploaded. What leaves the device is a key that cannot be reversed into a person. We are not in the business of watching anyone. We are in the business of letting a person prove something, once, at a moment they choose.

If you want the mechanics of that in more depth, how do I prove I am human in 2026 covers the primitive itself, and age verification without the ID upload works through the same idea applied to a different attribute.

What about AI agents that convert legitimately?

This is the question that makes the whole area more interesting than it was two years ago, and it is going to matter more every quarter.

If a person instructs their assistant to research vendors and request demos, and the assistant fills in your form, is that a fraudulent lead? Obviously not. A real person wants the demo. But it is also not a human presence event, and treating it as one by accident is exactly how you end up with numbers you cannot defend.

The correct answer is a third category rather than a binary. An agent acting under an explicit, scoped delegation from a human is a legitimate, attributable conversion, and it should carry a delegation receipt naming the human who authorised it rather than a presence receipt asserting a human was at the keyboard. An agent acting with no human behind it is neither. The distinction is exactly the one the authority graph and delegation chain pieces develop in an enterprise context, and it lands in advertising sooner than most marketers expect.

Practically: decide your policy now, before the volume arrives. Most advertisers will want to accept delegated agent conversions and count them separately, because a lead generated by a buyer's research assistant is a real lead with a real buyer attached.

What this cannot do

The limits here are real and an advertiser should hear them before a pilot, not after.

What to do this week

  1. Pull last quarter's paid conversions and ask, for each channel, what fraction you could prove had a human behind it today. The answer is zero, and writing that zero down is the useful part.
  2. Separate invalid traffic from fraud in your own internal reporting, even if your vendors do not. They are different problems with different owners.
  3. Ask each verification vendor two specific questions: what is your estimated false negative rate on browser driving agent traffic, and is your headline number detected or modelled? Note who answers cleanly.
  4. Rank your paid events by cost per event. Take the top three. That is your entire pilot scope.
  5. Instrument one of them with a presence proof at the submit step. One event, one channel, thirty days.
  6. Report the human verified rate by channel and partner. Do not aggregate. The aggregate hides exactly the partner you need to find.
  7. Write your agent policy before the volume forces one: accept delegated agent conversions, count them in a third bucket, reject unattributed automation.
  8. Put a proof clause in your next partner renewal. Not a fraud rate guarantee, which is unenforceable, but a requirement that paid events above an agreed value carry a verifiable receipt.

If you want to see the underlying gate before you scope any of this, the humans first demo runs the flow in a browser without a signup, and the developer documentation covers the receipt format and verification.

Frequently asked questions

How much ad spend is lost to bots? Published estimates for 2025 range from roughly $25 billion, based on measured click samples, to roughly $165 billion, based on modelled invalid traffic across global spend. They differ because they use different denominators, definitions, units, and detection versus modelling. Every serious source finds a double digit percentage of paid activity has no human behind it.

Why do ad fraud estimates disagree so much? Four reasons. The denominator may be total ad spend or one vendor's measured sample. The definition may be all invalid traffic, which includes crawlers, or only adversarial fraud. The unit may be impressions, clicks, or conversions, which have very different values. And the figure may be what was detected or what a model thinks was missed.

Can advertisers verify that a real human converted? Not with today's standard stack, which produces probability scores rather than evidence. A presence receipt changes that at the conversion step: the person proves presence on their own device, and the advertiser receives a signed artifact verifiable offline against a published key, with no identity attached.

Does a presence receipt require cookies or tracking? No. The receipt is scoped to one advertiser, contains a one way key rather than an identifier, carries no name, email, IP address, or device fingerprint, and expires within minutes. It collects substantially less personal data than the fingerprinting and cross site tracking that current detection depends on.

Does this stop impression fraud? No, and it is important to be clear about that. There is no interaction at an impression to attach a proof to, and the per event value is far too low to justify one. Impression level invalid traffic remains a detection and contracting problem. Presence proofs address the events that carry meaningful money.

What happens when an AI agent completes a conversion for a real person? That should be a third category rather than a pass or fail. An agent acting under a scoped delegation from a human can carry a delegation receipt naming the human who authorised it. Most advertisers will want to accept those and count them separately from conversions where a person was directly present.

What replaces device fingerprinting for ad fraud? Proof at the paid event. Fingerprinting infers humanity from signals the adversary supplies and is degrading as browsers restrict it and agents mimic it. A signature produced on the visitor's device at the conversion establishes presence directly, and does so with far less data collection.

Sources

  1. Anura, executive brief on invalid traffic, June 2026, reported via eMarketer. anura.io
  2. Spider AF, 2026 ad fraud report on measured paid clicks. spideraf.com
  3. Imperva (Thales), 2026 Bad Bot Report, April 2026. imperva.com resource library
  4. Media Rating Council, Invalid Traffic Detection and Filtration Guidelines. mediaratingcouncil.org
  5. Association of National Advertisers, programmatic transparency work. ana.net
  6. Trustworthy Accountability Group, Certified Against Fraud programme. tagtoday.net
  7. IAB Tech Lab, ads.txt and sellers.json specifications. iabtechlab.com
  8. hCaptcha, public statements on the declining reliability of browser fingerprints. hcaptcha.com
Detection tells you a percentage you have to trust. Proof gives you a list you can audit.