Vulnerability in Voting Scanners Allows Ballot Order Recovery Using AI

Researcher demonstrates exploit in Georgia primary using only public data and a coding agent

edit
By LineZotpaper
Published
Read Time2 min
A security vulnerability in voting scanners used by 21 U.S. states allows recovery of the order in which ballots were cast, a problem a researcher has now exploited with AI tools to analyze voter behavior in Georgia’s May 2026 primary — without ever touching a voting machine or accessing non-public information.

A vulnerability disclosed nearly four years ago in certain voting scanners continues to pose a risk to ballot secrecy, according to new research. The flaw allows anyone with access to two public data sources — the early-voting list for each county and the cast-vote record (CVR) file — to reconstruct the order in which ballots were cast, potentially linking individual voters to their choices.

In a recent demonstration, a researcher used a coding agent to exploit the vulnerability after feeding it the original vulnerability paper and the two data sources. The CVR file, which contains every ballot and its selections but not voter names, is available upon request as part of the public-record transparency that allows independent verification of election results.

“Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public,” the researcher wrote. They were able to analyze voter behavior in Georgia, one of the states using the affected scanners.

The demonstration highlights that the vulnerability remains exploitable years after its initial disclosure, now made easier with AI tools that can automate the reconstruction process. The researcher emphasized that no hacking or tampering was required — the exploit relies entirely on publicly available information.

§

Analysis

Why This Matters

  • The vulnerability undermines the secret ballot, which is a cornerstone of democratic elections. If ballot ordering can be reconstructed, coercion or vote-selling becomes easier to verify.
  • Because the exploit requires no physical access to machines or non-public data, it can be carried out by anyone with basic programming skills and access to public records.
  • The ease of exploitation using AI tools means the threat is more immediate than when the vulnerability was first disclosed, yet the same scanners remain in use across 21 states.

Background

The vulnerability was first disclosed around 2022 in certain optical-scan voting scanners used predominantly in the United States. It stems from a design flaw in how the scanners record ballot images and metadata. The current U.S. election system relies on a patchwork of state and local procedures, with many jurisdictions using these machines without software updates that would close the loophole. Georgia’s May 2026 primary was the test case for the new research.

Key Perspectives

[Researcher / Security Expert]: Demonstrates that a known flaw remains exploitable with public data and AI, raising alarms about election integrity and voter privacy. The fix should be straightforward — either randomizing ballot order in the CVR file or obscuring it before release. [Election Officials]: May argue that the vulnerability has been known for years and that no evidence suggests it has been used maliciously. They might also point out that the CVR files are intended for verification, not privacy, and that linking ballots to voters still requires knowing the exact voting order. However, the demonstration shows that order can be reconstructed. [Civil Liberties Groups]: Concerned that the vulnerability erodes trust in the electoral process. They will likely call for immediate replacement or software updates for affected machines, as well as changes to how CVR files are released.

What to Watch

  • Whether Georgia or other affected states will update scanner software or alter CVR file release procedures before the midterm or general elections.
  • Potential legal actions or federal guidance from the Election Assistance Commission regarding the vulnerability.
  • Further research using AI to exploit similar vulnerabilities in other voting systems, raising the broader question of whether transparency and privacy can coexist in digital elections.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.