Opening — The Question Behind the Question
Here’s something that gets lost in the shouting: worry about whether votes are counted correctly doesn’t belong to one party.
In 2016, many Democrats worried about foreign interference and whether election systems were secure. After 2020, many Republicans raised concerns about voting machines and whether votes were counted correctly.
The politics changed. The underlying question didn’t:
That’s a fair concern. It deserves a real answer — not “stop asking questions,” and not “everything is broken.”
We put money in an ATM and expect the machine to get the numbers right. But when millions of votes help decide who controls the government, how do we know the machines counting those votes got the numbers right?
Here’s the uncomfortable starting point:
Voting machines are technology. Technology can fail. Technology can also be attacked.
But that doesn’t mean someone can simply hack a machine and secretly change an American election.
Because the important question isn’t:
It’s:
Election security does not depend on blindly trusting voting machines. Modern election systems use layers of safeguards — paper records, testing, audits, reconciliation, canvassing, and sometimes recounts — to verify that reported results match the votes voters actually cast. The strongest systems are designed so the results can be independently checked.
Part 1 — What Do Voting Machines Actually Do?
Before talking about hacking, we need the right mental picture. Most people imagine every voter feeding their choice into one giant computer that sends a national result somewhere. That’s not how it works.
Three things readers call a “voting machine”:
Ballot-marking device (BMD)
Helps a voter make selections and prints a paper ballot or record for the voter to review.
Optical scanner
Reads and counts marks on paper ballots.
Direct-recording electronic machine (DRE)
Records votes electronically. Some DRE systems produce a voter-verifiable paper record, while older paperless systems do not. Paperless systems are now rare — more on that in Part 3.
Casting a vote and counting a vote are not always done by the same machine. In a common setup, the voter marks a paper ballot by hand or uses a ballot-marking device, and a separate scanner tabulates it.
And there isn’t one national machine collecting America’s votes. Elections are administered through thousands of state and local jurisdictions using different equipment, procedures, and systems.
hand-marked or BMD-printed
American elections are highly decentralized. States and local jurisdictions administer elections using different equipment and procedures rather than sending every vote through one national computer system.
That decentralization doesn’t make election systems impossible to attack. But it does mean there isn’t one central machine or database where someone can simply change the nation’s vote total.
Part 2 — So… Can Voting Machines Be Hacked?
Let’s answer it directly: Yes, voting technology can have vulnerabilities.
Security researchers have demonstrated weaknesses in election equipment under controlled conditions. Like other computer systems, election technology can contain software bugs, configuration errors, and security flaws.
But here’s the distinction this whole article turns on:
| Claim | What It Actually Establishes |
|---|---|
| Researchers hacked a voting machine in a lab | The equipment had a vulnerability |
| Election officials found a software error | Something malfunctioned and must be investigated |
| Election equipment was connected to the internet | The connection raises a security question that should be investigated |
| An audit found a discrepancy | Officials need to determine what caused the mismatch |
| An audit confirmed the paper ballots matched | Strong evidence the reported result reflects the ballots |
None of this means vulnerabilities should be ignored. If researchers find a security weakness, election officials and manufacturers should take it seriously, fix it when possible, and determine whether equipment in actual elections could be affected. The point is not that vulnerabilities don’t matter. The point is that discovering a vulnerability and proving that it was exploited in an election are two different steps.
A vulnerability tells us what could potentially happen. Evidence tells us what did happen. One does not prove the other.
Part 3 — The Most Important Safeguard: Paper
The most important safeguard against a machine counting votes incorrectly is surprisingly simple: paper.
Software can be questioned. Paper can be counted again.
Here’s the current state of play, from sources you can check yourself:
That means that for nearly all votes, election officials had a physical record that could be checked against the electronic count if questions arose.
The Election Assistance Commission found something similar when it looked at election jurisdictions: more than 98% used voting equipment that involved a paper ballot or produced an auditable paper record. Only 80 jurisdictions in three states reported using systems without a verified paper trail.
That doesn’t mean every jurisdiction uses the same equipment or procedures. It means paper-backed voting has become the overwhelming norm.
Ideally, that paper record is also voter-verifiable — meaning the voter has an opportunity to review the printed ballot or record and confirm that it reflects their selections before the vote is finalized.
Why does this matter so much? Because every downstream safeguard depends on it:
For years, cybersecurity experts have pushed states to retire paperless voting systems and replace them with systems that create voter-verifiable paper records — and states have increasingly acted.
Mississippi and Tennessee, for example, passed laws requiring voter-verifiable paper records beginning in 2024.
Election security doesn’t depend only on Congress or the federal government. States can strengthen their own election systems through state law, including requirements for paper records, audits, equipment, and election procedures. That means states can sometimes act while national standards are still being debated.
Paper alone isn’t magic. Chain of custody, secure storage, and transparent handling procedures matter too. A paper trail only protects an election if the paper itself is protected.
Part 4 — What Happens Before Election Day?
Readers may assume officials simply plug machines in Tuesday morning. They don’t.
Certification
Election officials can’t simply buy any machine and put it in a polling place. Voting systems go through testing and must meet the certification requirements that apply in the state where they will be used. Many states incorporate federal testing or certification standards into that process.
Logic and Accuracy Testing
Before each election, officials feed machines known test ballots. If the test stack contains Candidate A × 50, Candidate B × 40, Candidate C × 10, the machine’s report better read 50 / 40 / 10. If it doesn’t, something is wrong — and the machine has to be fixed, replaced, or re-tested before it can be used.
Physical Security
Hacking isn’t only about someone sitting behind a computer. Who can physically reach the equipment matters too. Depending on the jurisdiction, safeguards can include tamper-evident seals, restricted access, secure storage, activity logs, and procedures requiring more than one person to be present for sensitive tasks.
The scale gets tested before the weighing, not after someone doubts the result.
Are election officials just testing the machines privately and telling us they worked?
In many jurisdictions, logic-and-accuracy testing is open to public observation or conducted with representatives from political parties or campaigns present. The exact rules vary by state.
Part 5 — What Happens on Election Night?
Another common misconception to bust: Election-night results are not the final results.
Why doesn’t everything get counted at once?
Because not every ballot follows the same path. Some voters cast ballots in person. Others vote by mail. Some ballots are provisional and require officials to confirm the voter’s eligibility before they can be counted. And states have different rules for when mail ballots can be processed.
That means one county may report most of its results quickly while another still has thousands of legitimate ballots left to process.
That doesn’t mean officials suddenly “found more votes.” It means counting continued after election night.
This isn’t a small part of the election. In 2024, roughly three in ten ballots were cast by mail. And states don’t all allow election officials to begin processing those ballots at the same time.
So when millions of Americans vote before Election Day, it doesn’t necessarily mean millions of ballots can be completely processed and reported before the polls close.
News organizations may project a winner when their analysts determine that the remaining votes are extremely unlikely to change the outcome.
But a media projection is not the official election result.
Election officials certify elections. News organizations call races. Those are two different things.
The election doesn’t end because America went to bed. The counting, checking, and verification continue until the official results are certified.
Part 6 — The Audit: Checking the Machines Against the Ballots
This is where the paper from Part 3 becomes so important.
After an election, officials don’t necessarily have to take the scanner’s word for it. They can go back to the actual paper ballots and check whether the machine counted them correctly.
That’s the basic idea behind a post-election audit.
In a post-election audit, officials physically examine a sample of paper ballots and compare those ballots with the reported results.
If the paper and the electronic count agree, that’s strong evidence the machines counted correctly. If they don’t, officials investigate why.
A Smarter Kind of Audit: The Risk-Limiting Audit
A risk-limiting audit (RLA) uses statistics to determine how many paper ballots officials need to check to gain strong evidence that the reported winner actually won.
Here’s the clever part:
If one candidate wins by a landslide, a relatively small sample may provide strong evidence that the outcome is correct. If the race is extremely close, officials may need to examine many more ballots.
And if the audit doesn’t provide enough evidence that the reported outcome is correct? Officials keep checking more ballots.
Think of it like checking someone’s math.
If you check several calculations and everything matches, your confidence grows. If you find something that doesn’t match, you don’t shrug and walk away — you check more.
States have increasingly experimented with stronger audits. Colorado pioneered statewide risk-limiting audits beginning in 2017, and Rhode Island followed with statewide use in 2020. Per the MIT Election Lab, more than three-quarters of states now require post-election tabulation audits. Thirty-four require traditional audits, while five require risk-limiting audits. Several other states have different or optional audit arrangements, and six have no post-election audit requirement.
This is an important weakness to understand: having a paper trail gives officials the ability to check the machine, but states don’t all require the same kind of post-election check.
What Does This Look Like in Real Life?
After Pennsylvania’s 2024 general election, officials conducted a statewide risk-limiting audit using the state treasurer race.
And here’s my favorite part: they rolled dice.
During a livestream, Department of State employees rolled 10-sided dice to generate a random 20-digit number. That number was entered into open-source audit software, which randomly selected 55 batches of ballots in 32 counties for officials to examine by hand.
The audit confirmed the reported outcome.
A 2025 analysis from Free Speech for People argued that post-election audits conducted in seven key 2024 swing states did not meet all the standards the organization considers necessary for a true risk-limiting audit.
Importantly, the report did not claim that the 2024 election result was wrong. Its argument was about the strength of the verification process.
That’s an important distinction.
You can believe an election result is accurate and still argue that the system used to verify it should be stronger.
An audit isn’t asking, “Do we trust the machine?”
It’s asking, “Does the paper agree with the machine?”
That’s a much better question.
Part 7 — Audit, Recount, Canvass, Certification: What’s the Difference?
These words often get thrown together after an election, but they describe different things.
Here’s the easiest way to keep them straight:
| Term | Plain-English Meaning |
|---|---|
| Audit | Checks whether the reported results are supported by the underlying ballots |
| Recount | Counts votes again under state law |
| Canvass | Makes sure the election records add up and every valid ballot is included |
| Certification | Makes the election results official |
The canvass is basically election bookkeeping. Officials reconcile ballots, voter records, and vote totals to make sure everything that should be counted is accounted for before the results become official.
A recount and an audit can sometimes look similar because both may involve examining paper ballots. But they’re asking different questions.
Do we have enough evidence that the original result is correct?
Let’s count the votes again.
Certification is the finish line.
Election-night numbers are unofficial. After the required counting, reconciliation, canvassing, any required audits, and other state-specific procedures are completed, election officials certify the results as official.
Certification is what turns an unofficial result into an official one.
Part 8 — What If Something Doesn’t Match?
What happens if an audit, recount, or canvass finds that something doesn’t match?
A discrepancy can have many causes: human error, a configuration mistake, a damaged ballot, an unclear voter mark, a scanner problem, or a reporting mistake.
The important question isn’t simply “Was there an error?”
It’s “What caused it, and did it affect the result?”
Finding an error is not evidence that election safeguards failed. Sometimes finding the error is the safeguard working.
Remember Pennsylvania’s 2024 audit from Part 6? The audit found a handful of small discrepancies. The largest changed the tally by only two votes.
Pennsylvania officials said discrepancies like these can result from human error when ballots are manually tallied during the audit or from stray or unclear marks that require officials to interpret voter intent.
The discrepancies were found because officials checked. The audit still confirmed the reported outcome.
Of course, not every discrepancy is harmless. A larger or unexplained mismatch deserves more investigation — and, depending on the audit rules and what officials find, more ballots may need to be examined.
The size, cause, and effect of the discrepancy matter.
Part 9 — What About the Internet?
One of the most common questions about voting machines is simple:
The answer depends on what equipment we’re talking about.
An election office uses several kinds of technology, and they don’t all do the same job. Saying “the election system was connected to the internet” without identifying the system can create more confusion than clarity.
1. Voting equipment
These are the scanners and other equipment used to record or tabulate votes. Voting systems use security controls intended to protect them from unauthorized access, and election officials use procedures to securely move results from voting systems into other reporting systems.
2. Election management systems
These are back-office systems election officials use to prepare elections, configure equipment, create ballot definitions, and manage election data.
3. Election-night reporting systems
These are the systems that publish unofficial results to websites that voters and news organizations watch on election night. These systems can be internet-connected.
If a county’s election-results website crashes, is defaced, or is attacked, that’s a cybersecurity incident and officials should take it seriously.
But it does not automatically mean the votes themselves were changed.
Election-night reporting websites display unofficial results. The underlying ballots and official tabulation process are separate things that can be checked through the procedures we’ve already discussed.
Think of an election-results website like a scoreboard.
If someone hacks the scoreboard, you have a serious security problem. But changing what the scoreboard displays doesn’t automatically change what happened on the field.
None of this means internet connections should be shrugged off. If voting equipment or another sensitive election system is unexpectedly connected to an outside network, that’s a legitimate security concern that should be investigated.
But evidence of a connection is not automatically evidence that someone gained access, changed votes, or changed an election outcome.
Which system?
A public website, a voter-registration database, an election management system, and a voting machine are not the same thing.
Part 10 — How to Evaluate a Claim That an Election Was Hacked
AI. Satellites. Foreign hackers. Secret internet connections. A video racing across social media.
Election claims can get complicated — and dramatic — very quickly.
You don’t need to be a cybersecurity expert to evaluate every claim. You need to know what questions to ask.
What system was allegedly compromised?
A voting machine? Election-management software? A voter-registration database? A public results website?
What evidence shows someone actually gained access?
Remember Part 2: a vulnerability is not the same thing as evidence that someone exploited it.
Is there evidence that votes were changed?
Getting into a system and changing an election result are two different claims.
Is there a paper record?
If so, the electronic count can potentially be checked against physical ballots.
Was there an audit or recount?
And if there was, did the physical ballots agree with the reported outcome?
What did the investigation find?
What did election officials, courts, cybersecurity investigators, auditors, or other relevant evidence conclude?
The strongest evidence is something that can be independently checked — especially physical ballots, audit results, recounts, court records, technical findings, and documented election records.
The same standard should apply no matter who is making the claim.
“The election was hacked” requires evidence.
So does “there’s nothing to worry about.”
Ask what happened. Ask for the evidence. Then ask how it was checked.
What About AI?
AI makes it easier to create convincing fake audio, images, documents, screenshots, and videos. But AI doesn’t change the standard of proof.
If a viral video claims voting machines were hacked, the questions remain the same: Which system? What evidence shows access? Did votes change? Is there a paper record? What did the audit find?
New technology can make the claim look more convincing. It doesn’t make the evidence stronger.
Don’t start with Who said it?
Start with: What is the evidence, and how can it be checked?
Part 11 — Putting the Test to Work: What Happened in 2020?
After the 2020 election, claims spread that voting machines had secretly changed votes or altered the outcome.
Rather than starting with “true” or “false,” let’s apply the same test from Part 10.
Were the claims tested in court?
Yes. Numerous lawsuits challenged the 2020 election results or election procedures.
But there’s an important nuance: not every case was decided after a full trial on the evidence. Some were withdrawn or dismissed for procedural reasons. Others were considered on their merits, and courts rejected claims because the evidence or legal arguments did not support the requested relief.
That’s more accurate than the shorthand you sometimes hear that “60 courts examined all the evidence and found nothing.”
Were the machine totals checked against paper?
In Georgia, yes.
Because the presidential race was close, the state’s 2020 risk-limiting audit expanded into a full manual tally of every ballot cast in the presidential contest.
In other words: humans counted the paper ballots and compared the result with the machine count.
The hand count confirmed the same winner.
Georgia didn’t stop there.
After the hand audit, the Trump campaign requested a machine recount. That recount also confirmed the outcome. The state also had a federally accredited testing laboratory examine equipment in six counties; according to the Georgia Secretary of State, the examination found no evidence that the machines had been tampered with.
So the evidence wasn’t simply:
It included a paper-ballot hand count, a recount, and additional equipment examination.
What happened to some of the machine claims afterward?
Some allegations involving Dominion Voting Systems later became the subject of defamation litigation.
In 2023, Fox agreed to pay $787.5 million to settle Dominion’s defamation lawsuit on the day the trial was scheduled to begin. Because the case settled, there was no jury verdict at trial.
The larger lesson for this article isn’t about Fox or Dominion.
Run the checklist
Was a vulnerability alleged? Yes.
Was there evidence that machines changed enough votes to alter the outcome? No such evidence was established in the court decisions and post-election examinations discussed here.
Was there paper to check? In key contested jurisdictions such as Georgia, yes.
Were ballots audited or recounted? Yes.
Did those checks change the reported winner? No. Georgia’s statewide hand audit and subsequent recount confirmed the same outcome.
Similar claims and rumors continued to circulate during later elections, including 2024. But the standard doesn’t change with the election year, candidate, or political party:
Not who shouted loudest.
Part 12 — No Election System Is Perfect
The wrong conclusion would be “voting machines cannot be hacked.” That’s too absolute, and you shouldn’t trust anyone who tells you so.
Voting machines are not perfect.
They’re technology. Technology can fail. Software can have bugs. Equipment can malfunction. People can make mistakes. And attackers can try to exploit weaknesses.
Election security isn’t built on pretending those risks don’t exist.
🔐 Defense in Depth
Cybersecurity experts call this defense in depth.
In plain English: don’t bet the whole election on one lock.
If one safeguard fails, another should be there to catch the problem.
No single layer is perfect. That’s why there are multiple layers designed to catch each other’s misses.
This is why the paper-record number from Part 3 matters so much. A voter-verifiable paper ballot gives officials something the software cannot rewrite after the fact:
It’s the ground truth that audits and recounts can go back and check.
The goal isn’t to build a system where nothing can ever go wrong.
The goal is to make it much harder for something to go wrong without being detected — and to leave evidence that can be checked when questions arise.
Election security isn’t one machine, one test, or one official saying, “Trust us.”
It’s layers of checks that can check each other.
Final Thoughts — Don’t Trust the Machine. Verify It.
The reassuring argument shouldn’t be:
It should be:
That’s why the paper matters. That’s why the audits matter. That’s why we check.
In the 2024 election, roughly 98% of votes cast had a paper record. That gives election officials something physical to compare against the electronic count when questions arise.
We started this article with a question:
The answer is that voting technology can have vulnerabilities, just like other technology.
But that was never the most useful question.
The better question is:
In the overwhelming majority of American elections, paper records make that possible. How thoroughly those records are checked still varies by state — which is why strong audit laws matter.
Ask questions. Demand evidence. And when someone tells you an election was hacked, don’t stop at the claim.
Ask how they know. Then ask how it was checked.
Discussion Questions
- Should every voting system in the United States be required to produce a voter-verifiable paper record?
- Should post-election audits — including risk-limiting audits — be mandatory nationwide?
- How much evidence should be required before officials investigate claims that voting machines changed election results?
- Does learning how audits and certification work make you more confident in election results — or raise new questions?
- Who should be responsible for explaining election-security safeguards to the public before misinformation spreads?
Sources & Further Reading
- EAC, 2024 Election Administration and Voting Survey
- Brennan Center, “Accuracy of Election Results”
- Brennan Center & Verified Voting, “Costs for Replacing Voting Equipment in 2024”
- MIT Election Lab, “Post-Election Audits”
- Verified Voting, “Risk-Limiting Audits”
- Pennsylvania Dept. of State, 2024 General RLA Report
- Free Speech For People, swing-state audit assessment
Related Articles: Voting in America, Who Runs Elections in the United States?



No discussions yet
Be the first to join the discussion and share your thoughts with the community.