A cybersecurity firm hired to examine the security of American voting machines says its federal contract was abruptly terminated after it reported serious software vulnerabilities but found no evidence that any votes were altered, raising new questions about how election security work is being handled ahead of the 2026 midterms.
A Contract Born From Intelligence Concerns
The firm, Mojave Research, was retained in May 2025 by the Office of the Director of National Intelligence to conduct a forensic analysis of Dominion voting equipment used in Puerto Rico’s 2024 elections. Mojave CEO Jason Wareham said the roughly ten-person team spent months reverse-engineering the machines’ software and hardware, ultimately producing a lengthy technical report that was briefed to White House officials in September 2025. Puerto Rico used Dominion equipment territory-wide in its 2024 elections, and similar Dominion machines remain in service in parts of roughly twenty states, though Mojave cautioned it had only examined the Puerto Rico deployment in depth.
A Dozen Serious Flaws, But No Evidence of Fraud
According to Wareham and Mojave chief technology officer Manbir Gulati, researchers identified at least a dozen high- or critical-severity vulnerabilities in the systems, including reused and embedded passwords, disabled firewalls, open network ports, poorly implemented cryptographic protections, and active cellular modems that created potential pathways into machines meant to be isolated from outside networks. Gulati said the team successfully executed five of the flaws during testing and described the system as “deeply insecure,” failing to meet security standards “for an average low-risk application, let alone critical infrastructure.” Despite the findings, Mojave was explicit that it uncovered no proof any of the weaknesses had actually been exploited or that vote totals had been manipulated in Puerto Rico’s 2024 election.
A Planned Expansion That Never Happened
Wareham said the government had been preparing to significantly scale up the work, growing the team from about ten people to sixty and authorizing examination of additional voting systems from other manufacturers before the 2026 midterms. Personnel had reportedly already been hired and equipment funding provided. Instead, following the federal government shutdown in November 2025, Mojave received a stop-work order and no further funding, effectively ending the expanded initiative before it began.
A Trump Adviser’s Alleged Role
Wareham said he was told that Kurt Olsen, a Trump adviser and prominent figure in efforts to challenge the 2020 election results who now works at the Justice Department, pressed the firm to broaden its work in search of evidence supporting claims of election manipulation. When the findings did not support those claims, Wareham said, Olsen advocated for ending the contract and, without evidence, suggested the firm was connected to funding from billionaire George Soros — an accusation Wareham dismissed outright. “It was reported to me it was Kurt Olsen” who pushed for termination, Wareham said, adding that a “White House-adjacent” group was dissatisfied that Mojave would not “name and shame” specific actors or declare the 2020 election stolen.
Officials Decline Comment, Warnings on 2026 Persist
The White House, the Office of the Director of National Intelligence, and Olsen did not respond to requests for comment on the account. Liberty Vote, the company that acquired Dominion’s election business, said it had not received Mojave’s roughly 100-page report. Gulati, for his part, cautioned that similar vulnerabilities likely extend well beyond the single manufacturer and jurisdiction Mojave examined, though the firm has not tested enough systems elsewhere to confirm that. He also stressed there is no evidence that any foreign adversary, including China, has successfully infiltrated U.S. election systems or manipulated vote counts. Separately, surveys of local election officials have found that roughly three-quarters say state or local governments have not replaced federal resources cut over the past year, adding to concerns that election infrastructure will enter the midterms with weaker cyber defenses than in 2024. Democratic lawmakers have cited the episode as evidence the administration is more interested in silencing unwelcome findings than shoring up election defenses, while allies of the administration have countered that Mojave’s work was always intended as a limited pilot rather than an open-ended commitment.
What Happens Next
Wareham has announced plans to launch a new nonprofit, the Machine Assurance Institute, to continue independent verification of voting infrastructure security outside of federal contracts, arguing that unresolved fraud accusations remain “national security-destabilizing” regardless of political affiliation. With the 2026 midterms approaching, election security researchers, state officials, and members of Congress are likely to face renewed pressure to explain why a federally funded effort to identify and fix voting-system vulnerabilities was halted rather than expanded, and whether any independent group will pick up the work before ballots are cast this fall.