VASTlint
Back to blog

Confiant vs GeoEdge lines up 1 in 133 impressions and 80% redirects

An annual combined rate, a platform spread, a single-actor count, a vector share, and two regional or in-app rates sit together here and do not share a scale.

FirmFigureUnitPopulationSurfaceDate
Confiant1 in 133 impressions dangerous or highly disruptiveCombined security and quality rateNormalized sample of 1 trillion+ impressions, 2025Premium web and app programmaticJuly 2, 2026
ConfiantHighest SSP security rate 300 times the lowestPlatform spread13 SSPs, majority of global programmatic volumeProgrammatic supplyJuly 2, 2026
Confiant59 million malicious impressions, 95.4% in the USSingle-actor countD-Shortiez campaigns tracked in 2025Forced redirectsFebruary 24, 2026
GeoEdgeAuto-redirects at 80% of malicious activityVector shareMalicious incidents GeoEdge observed, Q3 2025Web and in-app programmaticQ3 2025 report, December 2025
GeoEdge1 in 120 ads malicious in non-gaming apps, 1 in 77 in gamesServed-ad rateAds GeoEdge saw served in apps, Q3 2025In-appQ3 2025 report, December 2025
GeoEdge1 in 40 programmatic impressions maliciousRegional impression rateNorth America, 2025ProgrammaticNovember 18, 2025
Three cards. Confiant reports 1 in 133 impressions dangerous or highly disruptive across more than 1 trillion impressions in 2025. GeoEdge reports auto-redirects at 80 percent of malicious incidents in Q3 2025 and 1 in 40 North American impressions malicious. vastlint checks VPAID, SIMID, MediaFile, URL, and wrapper structure and does not run creatives.
An annual share of all impressions and a quarterly share of malicious incidents both describe bad ads, and they count different things over different months. Diagram by vastlint.org. An independent open-source project. The diagram restates figures already cited in this post.

Alex Sekowski · October 2, 2026 · 14 min read

Confiant vs GeoEdge is the shortlist a publisher, SSP, or app developer writes when bad ads have started costing users and revenue. Both firms sell real-time creative scanning and blocking to publishers and ad platforms, and both publish research. The research does not use the same unit. Confiant's 2026 Malvertising, Ad Quality and Risk Index, released July 2, 2026 under the title Risky Business, says one in every 133 impressions in 2025 was dangerous or highly disruptive to the end user, on a normalized sample of more than one trillion impressions from tens of thousands of premium websites and apps. GeoEdge's Q3 2025 Ad Quality Report says auto-redirects made up 80 percent of all malicious activity it saw that quarter, the highest share on record, and GeoEdge said on November 18, 2025 that 1 in every 40 programmatic impressions in North America in 2025 carried malicious intent. vastlint does not rank Confiant against GeoEdge. It checks VAST 2.0–4.4 structure, including the places where executable creative code enters a video tag, and it does not judge whether a creative is malicious.

One in 133 is a share of all impressions, combining security problems with quality problems such as heavy ads and auto-playing video. Eighty percent is a share of malicious incidents by attack type, which says nothing on its own about how many impressions were malicious. One in 40 is a share of impressions in one region under GeoEdge's definition of malicious intent. A shortlist that reads 1 in 40 against 1 in 133 and decides that one firm sees three times more danger has compared a region with the world and one definition with another.

Neither firm's public numbers settle the contract. Both are listed as privately held, both published research under their own names in 2026, and both put forced or auto-redirects among the main attacks they block. With the names removed, an annual combined rate, a quarterly vector share, and a regional impression rate still do not order one another.

What the Confiant figures measure

The 2026 MAQ Index draws on Confiant's real-time creative verification product, which the report says captures live impressions rather than sandbox scans, across devices and channels, on a normalized sample of more than one trillion impressions monitored from January 1 to December 31, 2025. Confiant says 2025 produced the highest security rate it has observed, that every quarter came in above what used to count as a bad year, and that risk increased every quarter. By country, Japan's security rate multiplied several times over from 2024, France tripled, and Spain and Great Britain doubled; in 2024 no market in the dataset had a security rate above 0.50 percent, and in 2025 three did.

The headline ratio moved in the opposite direction from the security rate, and the methodology note explains why. For this edition, Confiant says Quality Rate now reflects only confirmed interventions, and security incidents include additional threat categories it previously tracked internally without reporting. Security violation rates remain directly comparable with earlier editions, while quality rates now use a stricter definition. For reference, Confiant's 2024 edition reported one in every 90 impressions as dangerous or highly disruptive, with a 0.21 percent security violation rate, and its mid-year 2025 report, built on 550 billion impressions from January to June 2025, said 1 in 78 ads put users at risk, with security violations at 0.32 percent and quality violations at 0.92 percent. The move from 1 in 78 to 1 in 133 is consistent with that stricter quality definition, since Confiant says the security half of the ratio rose.

The platform section is a spread rather than a rate. Confiant compares 13 supply-side platforms that it says account for the majority of global programmatic volume, and reports that in 2025 the highest SSP security rate was 300 times the lowest. It adds that platforms strong on security also tended to be strong on quality. The mid-year 2025 report showed the same shape on a shorter clock: some SSPs spiked as high as 7.39 percent, about 1 in 14 ads, in what the report calls daily spikes. Confiant's quality glossary includes heavy ads by file weight, video arbitrage (video players stuffed into a display slot, formerly called in-banner video), undesired video that auto-plays on load, undesired audio, expandables, and pop-ups; its security glossary includes cloaking, forced redirects, tech support scams, deepfake ads, phishing, and malware-as-a-service.

Confiant's actor reports carry a third kind of number. A February 24, 2026 post says Confiant tracked the D-Shortiez operation serving 59 million malicious ad impressions in 2025, 95.4 percent of them targeting the United States, with iOS at 26,154,969 impressions and Windows at 22,977,804. D-Shortiez used forced redirection code inside ads, legitimate-looking creatives copied from brands such as Adobe, and a traffic distribution system that sent Windows users to tech support scams and mobile users to reward scams. The MAQ appendix says ScamClub, another forced-redirect actor, injects malicious JavaScript into conventional VPAID. A July 23, 2026 post describes SourTrade, which has impersonated TradingView, Solana, and Luno across 12 countries and 25 languages and assembles its executable inside the victim's browser. An actor count describes one operation, not a market rate.

What the GeoEdge figures measure

GeoEdge publishes quarterly Ad Quality Reports. Each says GeoEdge monitored billions of impressions across premium websites, apps, and SSPs using its real-time ad security product on live impressions. The Q3 2025 report, posted to GeoEdge's site in December 2025, says malvertising reached its highest level of the year, driven by malvertising-as-a-service payloads aimed at high-CPM markets, with the United States and Canada reporting record activity. Auto-redirects made up 80 percent of all malicious activity, the highest share on record and a 33 percent lift over the first-half average. That figure is a share of malicious incidents by vector. It tells you what kind of attack dominated, not how many impressions were attacked.

The Q2 2025 report gives the rate-style figures. Malicious ad rates doubled in the top five markets, the United States and United Kingdom hit a 12-month peak in June, 1 in every 40 impressions in the UK was malicious, and Canada reached 1 in 35. Auto-redirects rose from 48 percent of malicious activity in Q1 to 66 percent in Q2, and tech support scams became the second most common threat at 18 percent. GeoEdge names Google but codes the other SSPs: one, labeled SSP18, spiked to more than 7 percent of its impressions, mostly redirect attacks targeting Japan in April and May. The Q1 2025 report put Google at 0.23 percent, SSP06 at 0.03 percent, and SSP18 at 0.89 percent.

GeoEdge's in-app and user-experience cuts use their own denominators. In Q3 2025, 1 in 120 served ads in non-gaming apps was malicious and 1 in 77 in games; 1 in 120 non-gaming app ads and 1 in 53 game ads were gambling-related. Floating ads and heavy ads both doubled from Q2 to Q3. Among ads GeoEdge blocked by content category, 78 percent in Europe were gambling, 32 percent in APAC were gambling, and 11 percent in North America fell into health. On November 18, 2025, GeoEdge launched User Safety Now, an initiative calling for a universal ad safety standard, and said that in 2025, 1 in every 40 programmatic impressions in North America carried malicious intent designed to defraud users.

GeoEdge also sells to CTV. Its SafeStream product, which ExchangeWire reported on April 25, 2025, scans video frames, audio, on-screen text, and landing pages, and GeoEdge's CTV page lists the media checks it runs: audio loudness, video frame rate, video bit rate, aspect ratio, media length, and creative size, with inputs that include an OpenRTB bid response, VAST XML, a standalone media file, or a JavaScript tag. On December 22, 2025, GeoEdge described LANJack, a campaign using DNS rebinding through ads to probe users' local networks, routers, and IP cameras, and scheduled it as a Black Hat USA briefing on August 5, 2026. GeoEdge's homepage says it secures more than 100 billion user sessions a month. A session count is coverage, and it is not a malvertising rate.

Why the Confiant and GeoEdge headlines have no shared scale

The units differ. Confiant's 1 in 133 is a share of all monitored impressions that were dangerous or highly disruptive, which folds quality issues such as heavy ads and auto-playing video into the same ratio as malware and scams. GeoEdge's 80 percent is a share of malicious incidents by vector. GeoEdge's 1 in 40 and 1 in 120 are shares of impressions or served ads, but in one region or one app category. Confiant's 300 times is a ratio between the best and worst of 13 platforms. None of these converts into another without data neither firm publishes.

The definitions differ, and one of them changed this year. Confiant's quality half now counts only confirmed interventions, so its annual headline is not comparable with its own 2024 headline even though the security rate is. GeoEdge reports malicious ads and treats floating and heavy ads as user-experience trends beside the malvertising index, rather than folding them into one ratio. Malicious intent designed to defraud users, the phrase behind GeoEdge's 1 in 40, is narrower than dangerous or highly disruptive, the phrase behind Confiant's 1 in 133. A narrower definition with a higher number is possible when the region and sample also differ.

The populations differ. Each firm measures impressions that pass through its own customers: publishers, apps, and platforms that bought protection. Confiant describes a normalized sample from tens of thousands of premium sites and apps. GeoEdge describes billions of impressions across premium websites, apps, and SSPs. Neither publishes the overlap. GeoEdge codes every SSP except Google, and neither firm publishes a crosswalk between its platform list and the other's. Confiant's 7.39 percent daily SSP spike and GeoEdge's more-than-7-percent SSP18 quarter look alike and may or may not describe the same platform.

The clocks differ. Confiant's index is annual, covering 2025 and released in July 2026, with a mid-year edition in between. GeoEdge's reports are quarterly, with the Q3 2025 file posted in December 2025, and its regional 1 in 40 is a 2025 figure announced in November 2025, before the year closed. A quarterly vector share from the third quarter and an annual rate for the whole year can both be accurate and still describe different months of the same campaigns.

Which question each firm's number answers

Cells restate what each firm has published; Not published means the reviewed material does not answer the question.

Question a buyer asksConfiant public answerGeoEdge public answer
How often was an impression bad last year?1 in 133 in 2025, security and quality combined, on 1 trillion+ impressions1 in 40 programmatic impressions in North America in 2025; no single annual global rate published
Which attack type dominates?Forced redirects among six named threat patterns; no vector share in the headlineAuto-redirects at 80% of malicious activity in Q3 2025, up from 66% in Q2
How much do SSPs differ?Highest security rate 300 times the lowest across 13 SSPs in 2025Coded SSP rates from 0.03% to more than 7% across 2025 quarters
Are apps riskier than websites?Splits by country, browser, and bidding framework; no app-versus-web rate in the headline1 in 120 non-gaming app ads and 1 in 77 game ads malicious in Q3 2025
How big is one named operation?D-Shortiez: 59 million malicious impressions in 2025, 95.4% USLANJack: described and blocked, no impression count published
Does it cover CTV creative specs?Undesired video and video arbitrage are quality categories; no CTV rate in the headlineSafeStream checks loudness, frame rate, bit rate, aspect ratio, length, and size, and accepts VAST XML
Who owns the firm?Privately held and venture backed, per PitchBookPrivately held, per its company page

Where a bad creative enters a VAST tag, and what a validator can and cannot see

A linear MediaFile of type video/mp4 is a file the player decodes, not a program. Executable code enters a VAST document through a small number of doors: a MediaFile with apiFramework set to VPAID, which VAST 4.1 deprecated in favor of SIMID for interactivity and OMID for measurement; an InteractiveCreativeFile with apiFramework set to SIMID, which loads an HTML page in an iframe layered over the video; HTMLResource and IFrameResource in companions and nonlinear ads; and the JavaScriptResource inside a Verification element. Confiant's appendix says ScamClub injects malicious JavaScript into conventional VPAID, and GeoEdge has said it introduced a player-level defense after finding auto-redirects in video ads in early 2024. Those doors are where a forced redirect in a video placement has to come from, because a plain MP4 cannot navigate the page.

The tag also makes claims the creative may not honor. A MediaFile declares type, delivery, width, and height, and it can declare bitrate, or from VAST 3.0 a minBitrate and maxBitrate pair; the Linear declares a Duration. GeoEdge's SafeStream measures the actual loudness, frame rate, bit rate, aspect ratio, length, and file size, which is how a heavy or off-spec creative gets caught even when the XML says otherwise. Wrappers add a second gap. Each VASTAdTagURI hop is another ad server that decides at serve time what InLine to return, so the same chain can hand a clean creative to a scanner and a different one to a user, which is the cloaking both firms describe. VAST 4.1 also lets a wrapper declare BlockedAdCategories with an authority, a request about content rather than proof of what was served.

A structural validator works on the document, not the behavior. vastlint flags apiFramework set to VPAID as deprecated on VAST 4.1 and later, flags a VPAID MediaFile sitting beside a SIMID InteractiveCreativeFile, checks that a SIMID file declares type text/html and that a linear SIMID ad still carries a playable media file, flags media and tracking URLs served over plain HTTP, missing MediaFile dimensions, conflicting bitrate attributes, wrapper chains deeper than the configured limit, and BlockedAdCategories without an authority. It does not execute the creative, follow the redirect, decode the video, or judge intent. A malicious VPAID creative can be structurally perfect, and a validator that passes it has said only that the XML is well formed.

What to do with the shortlist

Ask each firm for your own rate with your inventory as the denominator, split the way you will act on it: by SSP or demand partner, by attack vector, by market, and by app versus web. Industry averages from either firm describe their customer base, and Confiant's 300 times SSP spread is the reason a publisher's own mix matters more than any headline. Ask whether definitions changed between periods, since Confiant changed its quality definition for the 2026 edition, and ask whether coded SSP names can be disclosed under contract.

Ask how each firm handles video. For web and app video, that means whether blocking runs in the page, in the player, or at the SSP, and what happens to a VPAID or SIMID creative that tries to navigate the page. For CTV, it means whether the product is live-impression blocking or creative review before trafficking, which is where GeoEdge positions SafeStream, and whether it reads VAST XML directly. Ask for the denominator on any CTV number, because neither firm's headline separates CTV.

Then check the document both firms receive. vastlint is independent of Confiant and of GeoEdge. It checks VAST 2.0–4.4 structure, including deprecated VPAID, SIMID wiring, HTTPS on media and tracking URLs, MediaFile attributes, wrapper depth, and the AdVerifications node. It does not detect malvertising, scan creatives, score ad quality, or know whether a vendor's host is responding.

What to separate before using this comparison

  • Confiant's 1 in 133 combines security and quality across all monitored impressions in 2025, under a quality definition tightened for the 2026 edition.
  • Confiant's 1 in 78 for the first half of 2025 and 1 in 90 for 2024 were computed under the earlier quality definition and should not be read as a trend into 1 in 133.
  • GeoEdge's 80 percent is a share of malicious incidents by vector in Q3 2025, not a share of impressions.
  • GeoEdge's 1 in 40 is North American programmatic impressions in 2025, announced in November 2025, and it is not a global rate.
  • Coded SSP rates from GeoEdge and the 13-platform spread from Confiant cannot be matched to each other without names neither firm publishes.
  • An actor count such as D-Shortiez's 59 million impressions describes one operation, not the market.
  • A VAST tag that validates cleanly can still carry a malicious VPAID or SIMID creative, because structure and intent are different checks.

Questions buyers ask about Confiant and GeoEdge

  • Was GeoEdge acquired by Confiant, or was either firm acquired by someone else? Not in the material reviewed: GeoEdge's company page lists it as privately held, PitchBook lists Confiant as privately held and venture backed, and both published research under their own names in 2026.
  • What is Confiant's malvertising rate? The 2026 MAQ Index says one in every 133 impressions in 2025 was dangerous or highly disruptive, which combines security and quality, on a normalized sample of more than one trillion impressions.
  • What does GeoEdge report about auto-redirects? GeoEdge's Q3 2025 report says auto-redirects made up 80 percent of all malicious activity, the highest share on record, after 66 percent in Q2 2025.
  • Why does GeoEdge say 1 in 40 when Confiant says 1 in 133? GeoEdge's figure covers North American programmatic impressions with malicious intent in 2025, while Confiant's is a share of all impressions in its global sample that were dangerous or highly disruptive.
  • Do Confiant and GeoEdge cover video and CTV? GeoEdge sells SafeStream for CTV creative quality and accepts VAST XML as an input; Confiant counts undesired video and video arbitrage as quality issues and documents ScamClub injecting JavaScript into VPAID.
  • Can vastlint detect malvertising? No. It checks VAST 2.0–4.4 structure and flags deprecated VPAID and malformed SIMID wiring, and it does not execute creatives or judge intent.

Validate the VAST tag before the creative runs

Paste a VAST 2.0–4.4 tag to check VPAID deprecation, SIMID wiring, MediaFile attributes, HTTPS URLs, and wrapper depth against specification-derived rules. Nothing is stored.

Paste the tag

XML opens the validator, and a live tag URL opens the tester.

Or test a live URL

Sources

1 in 133, the 1 trillion impression sample, 300 times SSP spread, country changes, methodology change, glossary, and the ScamClub VPAID note.

Summary page for the 2026 edition, based on the 2025 reporting period.

Risky Business release postConfiant on LinkedIn

July 2, 2026 release date for the 2026 MAQ Index.

550 billion impressions, 1 in 78, 0.32 percent security, 0.92 percent quality, and the 7.39 percent daily SSP spike.

1 in 90 for 2024 and a 0.21 percent security violation rate.

February 24, 2026. 59 million impressions in 2025, 95.4 percent US, operating system counts, forced redirects.

July 23, 2026. Impersonation of TradingView, Solana, and Luno across 12 countries and 25 languages.

Privately held, venture backed, founded 2013.

Auto-redirects at 80 percent, in-app rates, floating and heavy ads, blocked categories, and the coded SSP index.

UK at 1 in 40, Canada at 1 in 35, auto-redirects from 48 to 66 percent, and SSP18 above 7 percent.

Google at 0.23 percent, SSP06 at 0.03 percent, SSP18 at 0.89 percent.

November 18, 2025 release text, including 1 in every 40 North American programmatic impressions in 2025.

SafeStream media checks and inputs, including VAST XML.

April 25, 2025 report on SafeStream and GeoEdge's CTV focus.

December 22, 2025. DNS rebinding through ads against routers, IP cameras, and other devices.

LANJack: Turning Ads into IoT Recon Tools.

GeoEdge's account of auto-redirects in video ads found in early 2024 and its player-level defense.

Listed as privately held, headquartered in New York.

The 100 billion user sessions a month coverage claim.

The other script door in a VAST tag, and how wrappers and stitchers drop it.

Why a content or quality verdict is a different measurement from a fraud rate.

The same unit problem across the verification vendors buyers compare more often.

Read another comparison in this set

All posts

Check the tag these notes describe

The rates above do not say whether AdVerifications survived the wrapper.