/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers: Voatz, the voting app used in W. Virginia and four other states, has elementary security flaws that could let an attacker intercept and alter votes

A mobile voting app being used in West Virginia and other states has elementary security flaws that would allow someone …

VICE Kim Zetter

Context & Ripple Effects

West Virginia brought Voatz's blockchain-based mobile voting to the 2018 midterms as a pilot for overseas troops, and four more states followed. This report is the first public claim that the app's flaws are elementary enough to let an attacker intercept and alter ballots in production use.

The finding lands in a crowded arc: researchers had already flagged a severe undetectable-tampering flaw in Switzerland's online voting system, and within weeks of this story an independent Trail of Bits audit catalogued critical vulnerabilities in Voatz itself. The vendor's response to scrutiny became its own story when HackerOne cut ties over hostile interactions with researchers.

First-order effects

  • Voters casting ballots through Voatz in West Virginia and the four other states are directly exposed: the reported flaws mean ballots could be intercepted or altered rather than merely observed.
  • Election officials in those five states must decide whether their deployed Voatz programs can continue running on an app whose basic protections researchers say fail.

Second-order effects

  • Independent auditors move from outside critics to de facto gatekeepers — the Trail of Bits audit and the Swiss-system disclosure set a template where no mobile voting vendor survives deployment without third-party verification.
  • Voatz's adversarial posture toward researchers culminates in its removal from HackerOne's bug-bounty program, cutting off the coordinated-disclosure channel that might have caught these flaws before publication.

Third-order effects

  • The recurring pattern — weak hard-coded credentials in Virginia's e-voting systems, the Swiss tampering flaw, now Voatz — points toward internet voting being structurally unable to clear the bar of verifiable, auditable elections without a breakthrough in end-to-end verifiability.
  • If the pattern holds, procurement rules for election technology shift toward mandatory independent security audits and researcher-access policies, making vendor transparency a condition of state contracts rather than a courtesy.

The trend: Mobile voting is colliding with independent security research, and adversarial findings are consistently outpacing the vendors' ability to deploy safely.

Discussion

  • @konklone Eric Mill on x
    Today, the NYT covered research by @mspecter, @jimmykoppel, and @djweitzner into the security of Voatz, a mobile app that's been used for online voting in US elections: https://www.nytimes.com/... This found serious issues, but they're just some of the many problems with @Voatz. …
  • @kimzetter Kim Zetter on x
    Researchers find that Voatz mobile voting app used in several states has flaws that would let attackers intercept and alter votes and doesn't use blockchain as claimed. Here's my story with technical details about the findings: https://www.vice.com/...
  • @matthew_d_green Matthew Green on x
    This is the public response to the Voatz analysis published by MIT today. It seems to avoid actually refuting any of the findings, and concentrated on vaguely attacking the research methods. https://blog.voatz.com/?p=1209
  • @mit_csail Mit Csail on x
    BREAKING: MIT team identifies security vulnerabilities in voting app Voatz that could allow hackers to change or eliminate votes. Voatz has already been used in multiple state elections in WV, CO, OR & UT. Full story: http://news.mit.edu/... Paper: https://internetpolicy.mit.edu/…
  • @emanuelmaiberg Emanuel Eggberg on x
    someone probably said something like ‘put democracy on the blockchain’ and people actually went for it I want to die and deserve to https://www.vice.com/...
  • @dsilverman Dwight Silverman on x
    This @vice story about another poorly done voting app is like an XKCD comic come to life - right down to the blockchain nonsense. https://www.vice.com/... https://twitter.com/...
  • @davidgerard David Gerard on x
    NYT article on the MIT article on how dumbass insecure Voatz is, in broad outlines for a general audience https://www.nytimes.com/...
  • @random_walker Arvind Narayanan on x
    It's not that venture capitalists are bad people per se. It's that they have their heads in the sand. https://www.nytimes.com/... https://twitter.com/...
  • @onekade @onekade on x
    step one: name your stupid voting app company VOATZ step two: build a shitty, insecure app step three: sell it to stupid people step four: profit step five: bash security researches as fame whores when they point out your app is shitty and insecure https://www.vice.com/...
  • @k8em0 Katie Moussouris on x
    A voting mobile app that can't even spell... security. https://twitter.com/...
  • @caitlin__kelly Caitlin Kelly on x
    “People shouldn't have to reverse engineer an app to answer these questions. Democracy requires a lot more transparency.” https://www.wired.com/...
  • @kevincollier Kevin Collier on x
    Worth noting that in addition to today's MIT research warning of significant vulns in Voatz, we also have a DHS report that found no evidence of malicious activity but plenty of recs for improved security. Voatz hadn't previously made any reports public. https://www.nbcnews.com/.…
  • @dl0x0 Doug on x
    @Voatz has a lot of nerve with their response to @MIT_CSAIL. Going so far as to say the MIT researchers made bad faith recommendations, and state “...their priority being to find media attention, that the researchers' true aim is to deliberately disrupt the election process...” h…
  • @yoda Drew Olanoff on x
    People out there making cars that drive themselves and yet... https://twitter.com/...
  • @ericgeller Eric Geller on x
    Unsurprisingly, Voatz is dismissing these findings (http://blog.voatz.com/?p=1209). But CISA is investigating. I'm curious to hear from election officials who tout the app. Will they trust their vendor or independent experts? https://twitter.com/...
  • @ideagov Alan W. Silberberg on x
    #HandMarkedPaperBallots only. NO APPS. NO. NO. NO. https://twitter.com/...
  • @thevowel Eric Neustadter on x
    PAPER. BALLOTS. https://twitter.com/...
  • @joeuchill Joe Uchill on x
    Boy howdy, it won't take until daybreak to hear from Voatz. Says Voatz: The version of the app tested by MIT was “27 versions old” and the assumptions about the backend server were “false.” https://blog.voatz.com/?p=1209 https://twitter.com/...
  • @voatz @voatz on x
    Voatz is the first app for mobile voting, as identified by the New York Times. As technology leaders we also get to defend against detractors, however unfounded. Here is our response: https://blog.voatz.com/?p=1209
  • @mmasnick Mike Masnick on x
    And speaking of bad tech PR, when well respected researchers prove that your blockchain-based mobile voting system has serious security flaws (https://t.co/...) this is NOT HOW YOU RESPOND: https://blog.voatz.com/?p=1209
  • @gossithedog Kevin Beaumont on x
    Not sure if anybody remembers that thread I had about blockchain election company Voatz a few years ago (they faked their list of pentesters and such), but somebody external actually looked at their security. https://twitter.com/...