Security Vulnerability in a Voting System

Refract AI Intelligence Digest

BLUF

AI tools have successfully exploited a known voting scanner flaw to de-anonymize voters using public records.

NEWS

Security researcher Bruce Schneier demonstrated the ability to recover ballot order in Georgia's May 2026 primary using an AI agent and public early-voting lists. The vulnerability impacts scanners used in 21 states and requires no access to non-public systems or source code.

Why I Care

This breach of ballot secrecy threatens voter privacy across a significant portion of the US, enabling potential coercion or retaliation based on voting choices. It demonstrates how AI automation lowers the technical barrier for exploiting critical infrastructure vulnerabilities.

Next Steps

Election officials in affected states must immediately audit scanner configurations and prioritize hardware replacement before the next general election. Voters should verify if their jurisdiction uses affected scanners and advocate for mandatory paper trails to ensure ballot integrity.

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but not the voters’ names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable...
Back to Blog Listing

Source: Schneier on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.