Security Vulnerabilities of U.S. Voting Machines
Over the past decade, cybersecurity experts have repeatedly demonstrated and warned that many U.S. electronic voting machines have significant security weaknesses. Researchers have shown how attackers could infiltrate voting systems, alter software, and even change vote tallies under certain conditions. Election officials and lawmakers have acknowledged these risks, leading to investigations, public disclosures, and urgent calls for reforms to safeguard election integrity. This report compiles factual findings from experts (like J. Alex Halderman), documented hacking demonstrations, official investigations of threats (foreign and domestic), and legislative efforts to bolster voting machine security from 2014 to 2024.
Security experts have uncovered vulnerabilities in a range of voting systems — from older touchscreen machines (Diebold/Premier and Sequoia models) to newer systems by Dominion and ES&S. University of Michigan professor J. Alex Halderman has been a leading figure in exposing these flaws. In Senate testimony in 2017, Halderman flatly stated: “I know America’s voting machines are vulnerable, because my colleagues and I have hacked them – repeatedly – as part of a decade of research”.
He explained that his team created attacks spreading “from machine to machine like a computer virus” and found ways to “sabotage machines and steal votes” in every single case tested. These hacks occurred in controlled laboratory settings, not during real elections, but they proved the machines’ susceptibilities were “within reach for America’s enemies”.
Diebold/Premier & Sequoia (Older Systems): Many legacy direct-recording electronic (DRE) machines, such as the Diebold AccuVote TS/TSX and Sequoia AVC Edge, lacked modern security protections. Researchers demonstrated that malware could be installed to alter votes or that the software could be completely replaced by an attacker. In one dramatic 2010 example, Halderman and colleagues reprogrammed a decommissioned Sequoia touch-screen voting machine to run the classic Pac-Man video game – doing so without breaking the machine’s tamper-evident seals.
This “Pac-Man hack” illustrated how an attacker with brief physical access could swap out the voting software entirely. Similarly, at DEF CON 2017’s Voting Machine Hacking Village, hackers breached all five models of paperless DRE voting machines brought to the event. One machine (the AVS WINVote, used in Virginia elections through 2014) was hacked in under two hours and even reprogrammed to play a music video (“Never Gonna Give You Up”). These demonstrations underscored longstanding vulnerabilities: weak or hardcoded passwords (one WINVote device had the password “admin” or trivial defaults), decades-old unpatched software, and lack of encryption. In fact, the WINVote was so insecure that Virginia officials called it “America’s worst voting machine” and banned it in 2015 after an investigation found glaring.
Dominion ImageCast & Newer Systems: Newer voting machines are not immune to flaws. In 2021, Prof. Halderman and Dr. Drew Springall conducted a court-approved security test on Georgia’s Dominion ImageCast X (ICX) ballot-marking devices – touchscreen machines that print a paper ballot record. They discovered “vulnerabilities in nearly every part of the system” exposed to attackers. The most severe flaw allowed malicious code on a county’s central election management system to spread to every ICX machine in that jurisdiction, without needing physical access to each device. In other words, malware could propagate at scale and potentially corrupt ballot outputs across numerous machines. Their 96-page report explains how these bugs could be exploited to alter votes and even bypass the state’s protective measures. Although there is no evidence any attacker has used these vulnerabilities in a real election, Halderman warned they pose a “serious risk” unless fixed.
The findings were significant enough that in June 2022 the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a public advisory confirming nine security vulnerabilities in Dominion’s ImageCast X software. CISA noted that exploiting these particular flaws would require insider access or physical access to equipment and that mitigations (like software updates, restricted access, and rigorous pre-election testing) can reduce the risk. Dominion Voting Systems responded that the issues do not affect tabulators and insisted its machines remain accurate when proper procedures (including use of voter-verifiable paper ballots and audits) are followed. Georgia state officials, for their part, indicated procedural safeguards make real-world exploitation unlikely – though controversially, Georgia opted to delay installing Dominion’s security patch until after the 2024 election, leaving the known vulnerabilities unaddressed for an additional election cycle.
ES&S and Other Systems: The nation’s largest voting machine vendor, Election Systems & Software (ES&S), has also faced scrutiny. A 2018 investigative report revealed that ES&S had installed remote-access software (pcAnywhere) on some election-management systems sold to counties in the 2000s, creating a potential backdoor
. By the late 2010s, aging ES&S touchscreen models (like the iVotronic) were found to have insecure default passwords and no paper trail, leading states to replace them. At DEF CON and other security reviews, experts showed they could pick locks on ES&S optical scanners, upload malicious firmware, or intercept the wireless transmissions used by some models to send unofficial results. While ES&S has since pledged to disable remote-access software and improve security in newer products, independent testers continue to occasionally find weaknesses. For instance, DEF CON 2019 participants discovered vulnerabilities in every piece of equipment tested (from multiple vendors), reinforcing that modern voting machines still suffer many of the same security flaws as their predecessors.
Cybersecurity professionals stress that these technical vulnerabilities, in aggregate, pose a risk to election integrity if left unmitigated. The consensus of experts like Halderman, Princeton’s Andrew Appel, and others is that determined attackers (including nation-states) could exploit these weaknesses to alter votes – especially if machines don’t have voter-verified paper backups or if election officials don’t perform rigorous audits.
This is why academics have strongly recommended adopting voter-marked paper ballots and routine post-election audits as essential defenses, a point echoed by the National Academies of Science in a landmark 2018 report. In Halderman’s words, “our findings suggest [voting equipment] today is no more secure than equipment produced in decades past”, highlighting a need for much stronger software engineering, testing, and certification processes in the industry.
Public Disclosures by Officials and Agencies
Repeated alarms raised by security experts have compelled election officials and government agencies to investigate and publicly acknowledge voting system vulnerabilities. In some cases, officials acted decisively to decertify machines shown to be insecure. One notable example occurred in Virginia. In 2015, after reports exposed the abysmal security of the WINVote DRE machines (including that easy-to-guess “admin” password), the Virginia State Board of Elections immediately banned all WINVote machines statewide.
Then in 2017 – following DEF CON revelations that hackers could infiltrate several common voting machines within minutes – Virginia took the extraordinary step of **decertifying every remaining paperless touchscreen machine in the state. In September 2017, Virginia’s Elections Commissioner Edgardo Cortés recommended scrapping all DREs due to the “material risks” identified – including models from Diebold, Sequoia, Hart, and ES&S. The state’s IT agency had found that “each device analyzed exhibited significant vulnerabilities” and none produced a voter-verifiable paper recordscworld.com. The Board of Elections voted 3-0 to decertify them, forcing 22 counties to obtain more secure voting equipment (optical scanners with paper ballots) on very short notice. Virginia’s moves were a stark public admission that many existing machines were not up to basic security standards. Similarly, Pennsylvania, Georgia, New Jersey, and other states around 2018–2019 announced plans to replace outdated electronic machines with systems that provide paper backups, citing security concerns and voters’ declining confidence in purely electronic vote records.
Federal officials also began sounding alarms. After the 2016 elections, the Department of Homeland Security (DHS) for the first time designated election infrastructure as critical infrastructure, bringing more federal attention and resources to the issue. In June 2017, DHS publicly revealed that Russian hackers had tried to penetrate election-related systems in at least 21 states in 2016. Subsequent federal reports and hearings provided more detail: in July 2018, Deputy Attorney General Rod Rosenstein announced that Russian military intelligence (GRU) operatives “targeted state and local election boards”, hacked a U.S. voting software supplier in Florida, and accessed a state election website to steal data on 500,000 voters. These disclosures were part of Special Counsel Mueller’s investigation, which indicted 12 Russian officers for those activities. The revelations “added to years of warnings about the technologies that underpin American democracy”, as one Senate report put it. The U.S. Senate Select Committee on Intelligence, in a bipartisan 2019 study of Russian interference, concluded that cybersecurity for state and local election systems was “sorely lacking” in 2016 and that some vulnerabilities persisted even after remedial efforts. Importantly, the Senate Intelligence Committee urged that “any machine purchased going forward should have a voter-verified paper trail” as a safeguard. It also recommended allocating more funding to replace “remaining insecure voting machines and systems” across the country.
Election agencies have tried to reassure the public while not dismissing legitimate concerns. In the wake of the 2020 election – amid swirling rumors – a coalition of federal and state election officials (including CISA and the Election Assistance Commission) released a joint statement affirming “the November 3rd [2020] election was the most secure in American history.” They emphasized that all critical swing states used paper ballots that could be audited and that “there is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised” in 2020.
This strong statement, meant to bolster public confidence, nevertheless implicitly recognized the possibility of cyber tampering by highlighting the preventive measures (paper records, audits, testing) that ensured the vote count’s accuracy. Throughout 2021–2023, CISA and the FBI continued to issue security advisories to election officials, urging steps like rigorous pre-election testing, post-election audits, network segmentation, and prompt software updates to address newly discovered vulnerabilities. The FBI has also investigated and alerted states to specific threat incidents – for instance, in 2021 the FBI warned that an unknown actor was attempting to sell stolen election system passwords from a county office online, and in 2022 it helped probe insider breaches in Colorado (described below).
Cybersecurity professionals in the private sector have joined in public disclosures. Each year, organizers of DEF CON’s “Voting Village” publish reports detailing the hacking results and common security failures of voting machines tested. These reports (2017–2021) consistently found that “many machines still use outdated software or default passwords and are vulnerable to local or remote attacks”. In testimony to Congress and state legislatures, experts like Halderman, Appel, and Matt Blaze have bluntly stated that no current electronic voting system is completely secure – and that without paper audit trails and robust oversight, undetected fraud is possible. Such frank assessments from experts, election officials, and federal agencies over the past decade have firmly established that voting machine security is a real, non-partisan concern. The conversation has shifted from “could machines be hacked?” to “how do we mitigate the known risks?”.
Hacking Incidents and Threats to Election Infrastructure
While there is no confirmed case to date of hackers maliciously changing vote totals in a U.S. election, there have been several notable incidents and breaches highlighting the threat. These include both “test hacks” by researchers and real-world security failures or attacks against election infrastructure:
As mentioned, Russian government hackers in 2016 targeted U.S. election systems in a campaign of espionage and disruption. They breached the Illinois state voter registration database, stealing personal information on hundreds of thousands of voters.
They also infiltrated a Florida-based election software vendor (VR Systems), then sent phishing emails to county election officials impersonating that vendor. Two Florida counties had their networks accessed in this scheme (though the breach was not discovered until later, and no damage to election results was found). DHS confirmed that hackers scanned systems in all 50 states, and at least one state’s election website was successfully penetrated. These incidents prompted urgent warnings in late 2016, though many state officials were initially skeptical. Ultimately, the Mueller investigation and Senate reports documented the “extensive activity” directed at election infrastructure and concluded it was a wake-up call: election networks were much more vulnerable than previously believed.
In the 2020 election, U.S. intelligence agencies reported attempts by Iran (and to a lesser extent Russia) to influence or interfere with election systems, though on a smaller scale than 2016. In one case, Iranian operatives obtained public voter data and sent threatening spoofed emails to voters in Florida and Alaska in an attempt to sow chaos. The FBI and CISA held a press conference in October 2020 to disclose this and to announce that a misconfigured county election system had been briefly accessed by the Iranian attackers. Again, no votes were altered; the goal appeared to be undermining voter confidence via intimidation and misinformation. Separately, criminal hackers in 2020 did deploy ransomware against a few local government networks (for example, Hall County, Georgia’s election office had a ransomware incident that affected some internal systems). Such attacks risk disrupting election operations even if they don’t touch voting machines directly. The consensus from DOJ, DHS, and the intelligence community after 2020 was that no foreign government succeeded in compromising vote counting, but they certainly tried to probe for weaknesses.
Some security breaches came from inside. In May 2021, an election official in Mesa County, Colorado (a clerk sympathetic to election conspiracy theories) made unauthorized copies of the Dominion voting system software and hard drives during a trusted build update. Those copies were later leaked online. This breach of security protocols forced Colorado to decertify and replace Mesa County’s voting machines, since the chain of custody was broken. A similar unauthorized intrusion happened in Coffee County, Georgia after the 2020 election – outsiders were allowed to access the county’s Dominion voting machines and copied sensitive files. These incidents did not alter any election results (they occurred after votes were cast), but they exposed software and passwords that could aid hackers in the future. They also illustrated the risk of rogue insiders: election system security is only as strong as the humans entrusted with it. Both cases led to criminal investigations. The Mesa County clerk was indicted for tampering, and Georgia officials tightened physical access controls to prevent repeats.
Though not hacks, real-world machine failures have on occasion raised alarms. In the November 2018 midterms, some counties in Texas and Georgia experienced touchscreen calibration errors that flipped votes on DRE machines (e.g. touching one candidate’s name selected the other). In Antrim County, Michigan in 2020, an incorrect election management system configuration led to an initial mis-reporting of vote totals, which was quickly caught and corrected via a manual review. Although it was human error – not a hack – this incident was seized upon by conspiracy theorists to claim Dominion machines were “rigged.” Extensive audits and a hand recount in Antrim County confirmed the final results were accurate and the error did not indicate any systematic hack. Still, the Antrim case underscored how even routine glitches can be exploited to spread disinformation about voting machines. Election officials now emphasize transparency and rapid audits to counteract false claims following any anomalies.
Ongoing Security Research: Hackers at conferences continue to uncover troubling issues in voting equipment. At DEF CON 2019 and 2021, for instance, participants showed how an ES&S ballot scanner could be hacked to alter its reported tallies by swapping a memory card with malicious code – a tactic reminiscent of earlier academic studies. In 2022, independent researchers found that some Dominion ICP scanners had wireless modems configured to transmit unofficial results, theoretically opening a vector for remote exploitation (though mitigated by the fact that these modems use cellular networks and are not internet-addressable). Each new finding highlights the necessity of a “defense in depth” approach: assuming machines can be compromised and layering security through voter-verified paper ballots, robust chain-of-custody, and postelection audits to detect and correct any manipulation.
Demonstrated vulnerabilities and incidents above show that the threat is not hypothetical, “a hack that would disrupt the election is unlikely, but any vulnerabilities provide fodder for those wishing to question the results.”In today’s hyper-partisan climate, the mere existence of security flaws – even if not exploited – can erode public trust. Election officials now must worry not just about actual hacks, but also perception hacks: false or exaggerated claims of hacking that, if believed, can be just as damaging to democracy as a real cyberattack. This dual threat is why so much effort since 2016 has gone into both securing voting systems and countering misinformation about them.
Strengthening Election Security: Reforms and Legislation
Facing mounting evidence of vulnerabilities, policymakers over the past decade have pushed a series of reforms to improve voting machine security. A key focus has been transitioning away from paperless electronic voting toward systems that produce a voter-verifiable paper record, which can be audited or recounted by hand. In 2014, several states still used paperless DRE machines statewide (including Georgia, Delaware, Louisiana, South Carolina, New Jersey, Pennsylvania, and Virginia). By 2024, almost all U.S. voters cast ballots on paper (either marking a paper ballot by hand or using a ballot-marking device that prints their choices) – a monumental shift driven largely by security concerns.
Help America Vote Act (HAVA) Grants (2018 & 2020): In response to the revelations of Russian meddling, Congress appropriated $380 million in early 2018 to help states upgrade election equipment and improve cybersecurity. Many states used these HAVA grants to replace aging machines before the 2020 election. A Senate Intelligence Committee review urged Congress to evaluate the effectiveness of this funding and consider additional appropriations to “address remaining insecure voting machines and systems”.
An additional $425 million was appropriated in late 2019 for further upgrades ahead of 2020. This influx of funds accelerated the retirement of paperless systems. For example, Georgia used federal and state funds to replace its 16-year-old Diebold DRE machines with the Dominion ICX ballot-marking device system in 2019 (though, as noted, that choice came with its own debates). Pennsylvania and New Jersey also phased out their DREs by 2019, moving to paper ballots statewide.
State Laws Requiring Paper Ballots: Several states enacted laws or regulations mandating paper-based voting systems. In 2017, Virginia and Pennsylvania ordered that no paperless machines be used by the 2020 elections. New York and California had long banned paperless voting, and others like Colorado and Rhode Island adopted requirements for voter-verified paper ballots and rigorous post-election audits. By 2022, Louisiana remained one of the last states planning to replace its legacy DRE machines; legislation there set in motion a replacement with paper-based systems (though procurement issues delayed full implementation). Even in jurisdictions that still allow DREs, many have added voter-verifiable paper audit trail (VVPAT) printers to the machines so a physical record is created.
Risk-Limiting Audits (RLAs): A growing number of states have instituted RLAs – statistical hand-count audits of randomly sampled ballots – after each election to ensure machine counts are accurate. Colorado pioneered RLAs statewide in 2017, and by 2024 over 10 states had either required or piloted RLAs (including Nevada, Virginia, Michigan, Pennsylvania, and Rhode Island). RLAs can catch outcome-altering hacks or errors with high confidence and thus are seen as a critical backstop in the event of a cyberattack. The federal Cybersecurity & Infrastructure Security Agency has been actively promoting RLAs and providing technical guidance to states on how to conduct them.
Various election security bills have been introduced in Congress, though none have become law as of 2024. The bipartisan Secure Elections Act (proposed in 2018) would have mandated paper ballots and post-election audits nationwide, but it stalled in the Senate. The Election Security Act of 2019 (House) similarly aimed to require paper records and authorize more funding. While these specific bills didn’t pass, their core ideas often found support in must-pass appropriation bills that released funding with guidance for security improvements. Lawmakers from both parties (such as Senators James Lankford, Amy Klobuchar, Susan Collins, and Mark Warner) have, at times, publicly urged action to replace insecure machines and harden systems against foreign hackers.
The U.S. Election Assistance Commission updated its testing guidelines for voting equipment. The latest standards (Voluntary Voting System Guidelines 2.0 adopted in 2021) include enhanced security requirements – for instance, prohibiting wireless networking capabilities in voting machines and requiring auditability. While these standards are voluntary, states tend to require that any system used in their elections pass EAC certification. The hope is that new machines designed under VVSG 2.0 will be more resistant to cyber threats. Additionally, some states (like California) have imposed their own security testing on systems as a condition of use, catching problems that federal certification might miss.
Despite progress, experts note that challenges remain. Many election offices lack IT staff and rely on vendors for maintenance, which can be problematic if vulnerabilities need rapid patching. Funding is often cited as an issue – once federal grant money is spent, election administrators caution that machines have a lifespan and will need regular replacement (typically every 10-15 years).
A 2018 ProPublica analysis found two-thirds of counties used machines over a decade old, underscoring an ongoing need for investment. Moreover, even the best technology fails if procedures aren’t followed: recent insider breaches have prompted calls for better background checks and security training for election personnel.
The past decade saw a concerted effort to migrate the U.S. to auditable paper-based voting systems and to shore up both the cyber and physical security of election infrastructure. By 2024, these efforts significantly reduced the risk of undetectable software hacks changing votes, since most ballots can now be cross-checked outside the machine. Yet, as the next section shows, public debate about voting machine security remains heated – often fueled by political rhetoric that can distort the factual record.
Elon Musk’s Statements on Voting Machine Security
Tech billionaire Elon Musk has in recent years joined the fray of voices discussing election security – though his public statements about voting machines have been controversial. In 2023–2024, Musk used his platform (as owner of X, formerly Twitter) and public appearances to question the integrity of electronic voting systems, echoing some claims made by election skeptics. In an October 2024 town hall event in Pennsylvania, Musk argued that U.S. elections should “return to paper ballots” counted by hand, because he believes electronic machines are “just too easy to hack.”
Musk, who has a background in software, told the audience, “I know a lot about computers, and the last thing I would do is trust a computer program [for voting]”, suggesting even a single line of malicious code could undermine the results. These remarks were made during a campaign stop supporting former President Trump, and Musk implied that certain jurisdictions using Dominion machines (like Philadelphia and Maricopa County, AZ) coincidentally favored Democrats – insinuating the machines might be biased or manipulated.
Musk’s claims resonated with a segment of the public concerned about election fraud, but they are not well-supported by evidence. Election officials and security experts quickly pushed back. Dominion Voting Systems released a statement correcting Musk: Dominion’s devices were not even used in Philadelphia and in places they are used (like Arizona), the machines produce paper ballots and have been verified by audits as accurate. Dominion highlighted that audits and hand recounts repeatedly confirm their tabulations, and noted the irony that Musk was advocating paper ballots when Dominion’s system already incorporates paper records. Musk’s broad assertion that machines “rigged” the 2020 races in those areas is unfounded, as numerous audits and a $787 million defamation settlement from a media outlet attested (Musk’s comments came after Fox News had to concede in court that claims of Dominion fraud were false).
In fact, experts worry that Musk’s high-profile repetition of debunked theories could distract from real security issues. University of Michigan’s Halderman noted that exaggerated conspiracy claims about wholesale machine hacking have led some officials to initially dismiss legitimate warnings of smaller-scale vulnerabilitiesalumni.umich.edu. In other words, false allegations can create a “boy who cried wolf” effect, making it harder to address authentic risks.
At the same time, Musk’s core recommendation of hand-marked paper ballots aligns with what many security experts prefer. Virtually all experts agree that paper ballots, counted either by machine with audits or by hand, are more trustworthy than black-box electronic results.
Where Musk’s stance veers into controversy is his belief that voting machine manufacturers or election officials are complicit in fraud. No credible evidence has emerged of such an inside job, and federal agencies (like CISA and the DOJ) have affirmed that the 2020 election saw no machine-based fraud. Musk’s comments, therefore, need to be viewed in context: they underscore a popular distrust in election technology, even as actual election administrators emphasize that multiple layers of security and verification protect the vote.
Elon Musk’s foray into election integrity debates in 2024 highlights the tension between public perception and expert analysis. His soundbite that computers are “easy to hack” is partially validated by the findings of cybersecurity researchers – as this report has detailed, many voting machines have been shown to be technically hackable in test settings. However, equating hackable in theory with “rigged in practice” is a leap not supported by forensic investigations of past elections. The silver lining is that Musk’s interest brings attention to the need for secure elections. His advocacy for paper ballots and voter ID (another point he mentioned may spur constructive discussion, so long as the conversation remains rooted in facts: yes, we should fortify voting systems (and we have made progress doing so), but public confidence must be maintained through transparency and truthful information about what did or did not happen in our elections.
From 2014 to 2024, a clearer picture has emerged of the security of America’s voting machines. Cyber experts have exposed serious technical vulnerabilities in many voting systems – vulnerabilities that in a lab or with insider access could be exploited to change votes. Election officials and lawmakers have publicly acknowledged these weaknesses, leading to the widespread adoption of paper-backed voting systems and audits to mitigate the risks. Investigations by the FBI, DHS/CISA, and bipartisan panels have confirmed attempts by hostile actors to breach election networks (especially in 2016) and underscored the urgent need to harden our defenses. Crucially, they have also affirmed that there is no evidence any cyberattack has ever altered official vote counts in the United States. The documented hacks and breaches – whether by researchers at DEF CON or Russian operatives – serve as warnings, not tales of lost votes. In response, legislation and funding at federal and state levels have moved the country toward more resilient voting infrastructure (paper ballots, better audits, updated machines).
Public trust in voting technology is fragile. Maintaining that trust will require continued vigilance in addressing real security flaws while swiftly debunking false claims. Election security is a continual process, not an end state. The past decade’s lessons have prompted significant improvements, but also a recognition that attackers adapt and new vulnerabilities can emerge. Going forward, the challenge for election officials is twofold: keep strengthening the technical security of voting systems and strengthen transparency so that voters understand the issues vat hand.
Sources.
alumni.umich.edublog.citp.princeton.edu
blog.citp.princeton.edublog.citp.princeton.edu
intelligence.senate.go
alumni.umich.edualumni.umich.edu
All assertions are backed by documented evidence and expert testimony from 2014–2024, as cited above.