/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

An independent audit of mobile voting app Voatz, which has been used in elections in four US states, details many critical vulnerabilities and recommends fixes

Voatz allows voters to cast their ballots from any geographic location on supported mobile devices.

Trail of Bits Blog Dan Guido

Context & Ripple Effects

Voatz's mobile voting platform entered US elections through West Virginia's 2018 midterm rollout for overseas troops and spread to four more states, but the security story has been deteriorating all year: February researcher findings already flagged elementary flaws that could let an attacker intercept and alter votes.

This Trail of Bits audit is the independent confirmation of those claims, and it lands between two escalations — the researchers' disclosure and Voatz's subsequent expulsion from HackerOne over hostile treatment of security researchers — leaving election officials with a vendor whose product and security posture are both under documented challenge.

First-order effects

  • Jurisdictions in the four states using Voatz now have an independent audit recommending fixes for critical vulnerabilities, forcing each to decide whether to keep running elections on the app, pause it, or demand remediation before the next cycle.
  • Voatz must implement the audit's recommended fixes while its researcher relationships are broken — it no longer has a bug-bounty channel after the HackerOne removal, so vulnerability reports have fewer legitimate paths in.

Second-order effects

  • Scrutiny spreads to adjacent vendors: OmniBallot, used nationally for ballot delivery and marking, was independently flagged weeks later, so buyers of mobile and web voting tools now treat third-party audits as table stakes rather than optional diligence.
  • Expansion plans like the Greater Seattle district's smartphone voting for ~1.2M voters face a higher evidentiary bar, since every new deployment now gets measured against the Voatz audit record rather than against vendor assurances.

Third-order effects

  • If the pattern holds — independent audits contradicting vendor claims, followed by platform bans and expert skepticism about trial 'successes' — procurement of internet-based voting shifts toward mandatory external verification, and vendors that resist researcher engagement get priced out of public contracts.

The trend: US mobile voting is moving from pilot enthusiasm toward audit-gated adoption, where independent security review — not vendor marketing or early state trials — determines which systems stay deployed.

Discussion

  • @sarahjamielewis Sarah Jamie Lewis on x
    That Voatz had the audacity to paint researchers as malicious when they were using hardcoded encryption keys from a stack overflow answer to “protect” ballot receipts says everything you need to know about e-voting vendors. Closed source e-voting has no future. https://twitter.co…
  • @gossithedog Kevin Beaumont on x
    US election Blockchain voting company Voatz have had another independent security audit, this time by @trailofbits. It shows an incredible array of basic security issues, with systems and code used in live US elections. https://blog.trailofbits.com/ ... https://twitter.com/...
  • @djweitzner Danny Weitzner on x
    Nice summary thread on comprehensive report - this is the model of the kind of scrutiny that voting systems should be subject to *before* used for actual voting in real elections. @voatz put real-live voters ballots at risk all around the country. https://blog.trailofbits.com/ ..…
  • @alex_gaynor Alex Gaynor on x
    https://blog.trailofbits.com/ ... This is a stunning result, Voatz's blockchain nonsense had no business being anywhere near a US election. This is a pattern I've seen repeated in the public sector: Blockchain not solving problems securely, but scamming governments out of money a…
  • @alexstamos Alex Stamos on x
    This is good work by a highly respected team. Looks like Voatz is trying to dig themselves out of the hole they created with their horrible response to MIT. https://twitter.com/...
  • @kevincollier Kevin Collier on x
    New study on Voatz from @trailofbits is by far the most comprehensive one yet made public. They discovered a *lot* of vulnerabilities, and many issues unfixed, though the fact that we're able to read this is also significant progress from Voatz. https://blog.trailofbits.com/ ...
  • @rmhrisk Ryan Hurst on x
    “The quantity of findings discovered during this assessment, the complexity of the system, and the lack of access to both a running test environment as well as certain codebases leads us to believe that other vulnerabilities are latent.” https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Remember that Voatz mobile voting app? MIT researchers who published a recent report weren't able to examine all of it, but @trailofbits has now taken a more comprehensive look and found 79 issues - 1/3 of them “high severity” https://blog.trailofbits.com/ ...
  • @profcarroll @profcarroll on x
    Vote-By-Mail is urgently needed all over the country. Also, hucksters shilling “smart” voting tech should be avoided like the coronavirus. https://twitter.com/...
  • @kimzetter Kim Zetter on x
    And here's some commentary from @SarahJamieLewis on that new Voatz report (Sarah had previously examined the Swiss internet voting system and found severe security flaws with that system, which I reported here at the time: https://t.co/...) https://twitter.com/...