ELECTION SECURITY CAN VOTING MACHINES BE HACKED?

Can Voting Machines Be Hacked? How America Checks Whether Election Results Are Accurate

Opening — The Question Behind the Question

Here’s something that gets lost in the shouting: worry about whether votes are counted correctly doesn’t belong to one party.

In 2016, many Democrats worried about foreign interference and whether election systems were secure. After 2020, many Republicans raised concerns about voting machines and whether votes were counted correctly.

The politics changed. The underlying question didn’t:

How do I know my vote was counted correctly?

That’s a fair concern. It deserves a real answer — not “stop asking questions,” and not “everything is broken.”

We put money in an ATM and expect the machine to get the numbers right. But when millions of votes help decide who controls the government, how do we know the machines counting those votes got the numbers right?

Here’s the uncomfortable starting point:

Voting machines are technology. Technology can fail. Technology can also be attacked.

But that doesn’t mean someone can simply hack a machine and secretly change an American election.

Because the important question isn’t:

Can a voting machine ever be hacked?

It’s:

Could someone change election results without the safeguards around the machines catching it?
🔑 Key Takeaway

Election security does not depend on blindly trusting voting machines. Modern election systems use layers of safeguards — paper records, testing, audits, reconciliation, canvassing, and sometimes recounts — to verify that reported results match the votes voters actually cast. The strongest systems are designed so the results can be independently checked.

Part 1 — What Do Voting Machines Actually Do?

Before talking about hacking, we need the right mental picture. Most people imagine every voter feeding their choice into one giant computer that sends a national result somewhere. That’s not how it works.

Three things readers call a “voting machine”:

Ballot-marking device (BMD)

Helps a voter make selections and prints a paper ballot or record for the voter to review.

Optical scanner

Reads and counts marks on paper ballots.

Direct-recording electronic machine (DRE)

Records votes electronically. Some DRE systems produce a voter-verifiable paper record, while older paperless systems do not. Paperless systems are now rare — more on that in Part 3.

Casting a vote and counting a vote are not always done by the same machine. In a common setup, the voter marks a paper ballot by hand or uses a ballot-marking device, and a separate scanner tabulates it.

And there isn’t one national machine collecting America’s votes. Elections are administered through thousands of state and local jurisdictions using different equipment, procedures, and systems.

Voter
Paper ballot
hand-marked or BMD-printed
Scanner
Preliminary count
Verification, audit & certification
💡 Good to Know: There Is No National Voting Machine

American elections are highly decentralized. States and local jurisdictions administer elections using different equipment and procedures rather than sending every vote through one national computer system.

That decentralization doesn’t make election systems impossible to attack. But it does mean there isn’t one central machine or database where someone can simply change the nation’s vote total.

Part 2 — So… Can Voting Machines Be Hacked?

Let’s answer it directly: Yes, voting technology can have vulnerabilities.

Security researchers have demonstrated weaknesses in election equipment under controlled conditions. Like other computer systems, election technology can contain software bugs, configuration errors, and security flaws.

But here’s the distinction this whole article turns on:

“A machine has a vulnerability” ≠ “an election was hacked.”
Claim What It Actually Establishes
Researchers hacked a voting machine in a lab The equipment had a vulnerability
Election officials found a software error Something malfunctioned and must be investigated
Election equipment was connected to the internet The connection raises a security question that should be investigated
An audit found a discrepancy Officials need to determine what caused the mismatch
An audit confirmed the paper ballots matched Strong evidence the reported result reflects the ballots

None of this means vulnerabilities should be ignored. If researchers find a security weakness, election officials and manufacturers should take it seriously, fix it when possible, and determine whether equipment in actual elections could be affected. The point is not that vulnerabilities don’t matter. The point is that discovering a vulnerability and proving that it was exploited in an election are two different steps.

🔑 Key Message

A vulnerability tells us what could potentially happen. Evidence tells us what did happen. One does not prove the other.

Part 3 — The Most Important Safeguard: Paper

The most important safeguard against a machine counting votes incorrectly is surprisingly simple: paper.

Software can be questioned. Paper can be counted again.

Here’s the current state of play, from sources you can check yourself:

~98%
of votes cast in the 2024 election had a paper record

That means that for nearly all votes, election officials had a physical record that could be checked against the electronic count if questions arose.

The Election Assistance Commission found something similar when it looked at election jurisdictions: more than 98% used voting equipment that involved a paper ballot or produced an auditable paper record. Only 80 jurisdictions in three states reported using systems without a verified paper trail.

That doesn’t mean every jurisdiction uses the same equipment or procedures. It means paper-backed voting has become the overwhelming norm.

Ideally, that paper record is also voter-verifiable — meaning the voter has an opportunity to review the printed ballot or record and confirm that it reflects their selections before the vote is finalized.

Why does this matter so much? Because every downstream safeguard depends on it:

Voter makes selections
Paper ballot exists
Scanner counts votes
Officials compare totals to physical ballots
Any discrepancy can be investigated

For years, cybersecurity experts have pushed states to retire paperless voting systems and replace them with systems that create voter-verifiable paper records — and states have increasingly acted.

Mississippi and Tennessee, for example, passed laws requiring voter-verifiable paper records beginning in 2024.

📌 Federalism in Action

Election security doesn’t depend only on Congress or the federal government. States can strengthen their own election systems through state law, including requirements for paper records, audits, equipment, and election procedures. That means states can sometimes act while national standards are still being debated.

📌 Honest Caveat

Paper alone isn’t magic. Chain of custody, secure storage, and transparent handling procedures matter too. A paper trail only protects an election if the paper itself is protected.

Part 4 — What Happens Before Election Day?

Readers may assume officials simply plug machines in Tuesday morning. They don’t.

Certification

Election officials can’t simply buy any machine and put it in a polling place. Voting systems go through testing and must meet the certification requirements that apply in the state where they will be used. Many states incorporate federal testing or certification standards into that process.

Logic and Accuracy Testing

Before each election, officials feed machines known test ballots. If the test stack contains Candidate A × 50, Candidate B × 40, Candidate C × 10, the machine’s report better read 50 / 40 / 10. If it doesn’t, something is wrong — and the machine has to be fixed, replaced, or re-tested before it can be used.

Physical Security

Hacking isn’t only about someone sitting behind a computer. Who can physically reach the equipment matters too. Depending on the jurisdiction, safeguards can include tamper-evident seals, restricted access, secure storage, activity logs, and procedures requiring more than one person to be present for sensitive tasks.

🔑 Think of it like checking the scale before you weigh something important.

The scale gets tested before the weighing, not after someone doubts the result.

Are election officials just testing the machines privately and telling us they worked?

In many jurisdictions, logic-and-accuracy testing is open to public observation or conducted with representatives from political parties or campaigns present. The exact rules vary by state.

Part 5 — What Happens on Election Night?

Another common misconception to bust: Election-night results are not the final results.

Polls close
Votes are tabulated
Unofficial results reported
Outstanding ballots processed
Officials reconcile records
Canvass
Certification

Why doesn’t everything get counted at once?

Because not every ballot follows the same path. Some voters cast ballots in person. Others vote by mail. Some ballots are provisional and require officials to confirm the voter’s eligibility before they can be counted. And states have different rules for when mail ballots can be processed.

That means one county may report most of its results quickly while another still has thousands of legitimate ballots left to process.

That doesn’t mean officials suddenly “found more votes.” It means counting continued after election night.

This isn’t a small part of the election. In 2024, roughly three in ten ballots were cast by mail. And states don’t all allow election officials to begin processing those ballots at the same time.

So when millions of Americans vote before Election Day, it doesn’t necessarily mean millions of ballots can be completely processed and reported before the polls close.

💡 Good to Know: CNN, Fox, AP, and NBC Don’t Decide Who Won

News organizations may project a winner when their analysts determine that the remaining votes are extremely unlikely to change the outcome.

But a media projection is not the official election result.

Election officials certify elections. News organizations call races. Those are two different things.

🔑 Think of election night as a progress report, not the final report card.

The election doesn’t end because America went to bed. The counting, checking, and verification continue until the official results are certified.

Part 6 — The Audit: Checking the Machines Against the Ballots

This is where the paper from Part 3 becomes so important.

After an election, officials don’t necessarily have to take the scanner’s word for it. They can go back to the actual paper ballots and check whether the machine counted them correctly.

That’s the basic idea behind a post-election audit.

In a post-election audit, officials physically examine a sample of paper ballots and compare those ballots with the reported results.

If the paper and the electronic count agree, that’s strong evidence the machines counted correctly. If they don’t, officials investigate why.

A Smarter Kind of Audit: The Risk-Limiting Audit

A risk-limiting audit (RLA) uses statistics to determine how many paper ballots officials need to check to gain strong evidence that the reported winner actually won.

Here’s the clever part:

The closer the election, the more ballots officials may need to check.

If one candidate wins by a landslide, a relatively small sample may provide strong evidence that the outcome is correct. If the race is extremely close, officials may need to examine many more ballots.

And if the audit doesn’t provide enough evidence that the reported outcome is correct? Officials keep checking more ballots.

Think of it like checking someone’s math.

If you check several calculations and everything matches, your confidence grows. If you find something that doesn’t match, you don’t shrug and walk away — you check more.

States have increasingly experimented with stronger audits. Colorado pioneered statewide risk-limiting audits beginning in 2017, and Rhode Island followed with statewide use in 2020. Per the MIT Election Lab, more than three-quarters of states now require post-election tabulation audits. Thirty-four require traditional audits, while five require risk-limiting audits. Several other states have different or optional audit arrangements, and six have no post-election audit requirement.

This is an important weakness to understand: having a paper trail gives officials the ability to check the machine, but states don’t all require the same kind of post-election check.

Reported result
Randomly select paper ballots
Compare ballots to reported totals
Enough evidence?
Yes
Done
No
Examine more ballots

What Does This Look Like in Real Life?

After Pennsylvania’s 2024 general election, officials conducted a statewide risk-limiting audit using the state treasurer race.

And here’s my favorite part: they rolled dice.

During a livestream, Department of State employees rolled 10-sided dice to generate a random 20-digit number. That number was entered into open-source audit software, which randomly selected 55 batches of ballots in 32 counties for officials to examine by hand.

The audit confirmed the reported outcome.

34 Traditional audit requirement
5 Risk-limiting audit requirement
Several Different or optional arrangements
6 No post-election audit requirement
📌 Honest Caveat: Not All Audits Are Created Equal

A 2025 analysis from Free Speech for People argued that post-election audits conducted in seven key 2024 swing states did not meet all the standards the organization considers necessary for a true risk-limiting audit.

Importantly, the report did not claim that the 2024 election result was wrong. Its argument was about the strength of the verification process.

That’s an important distinction.

You can believe an election result is accurate and still argue that the system used to verify it should be stronger.

🔑 Key Takeaway

An audit isn’t asking, “Do we trust the machine?”

It’s asking, “Does the paper agree with the machine?”

That’s a much better question.

Part 7 — Audit, Recount, Canvass, Certification: What’s the Difference?

These words often get thrown together after an election, but they describe different things.

Here’s the easiest way to keep them straight:

Term Plain-English Meaning
Audit Checks whether the reported results are supported by the underlying ballots
Recount Counts votes again under state law
Canvass Makes sure the election records add up and every valid ballot is included
Certification Makes the election results official

The canvass is basically election bookkeeping. Officials reconcile ballots, voter records, and vote totals to make sure everything that should be counted is accounted for before the results become official.

A recount and an audit can sometimes look similar because both may involve examining paper ballots. But they’re asking different questions.

Audit

Do we have enough evidence that the original result is correct?

Recount

Let’s count the votes again.

Certification is the finish line.

Election-night numbers are unofficial. After the required counting, reconciliation, canvassing, any required audits, and other state-specific procedures are completed, election officials certify the results as official.

Certification is what turns an unofficial result into an official one.

Part 8 — What If Something Doesn’t Match?

What happens if an audit, recount, or canvass finds that something doesn’t match?

Officials investigate.

A discrepancy can have many causes: human error, a configuration mistake, a damaged ballot, an unclear voter mark, a scanner problem, or a reporting mistake.

The important question isn’t simply “Was there an error?”

It’s “What caused it, and did it affect the result?”

Something doesn’t match
Investigate why
Correct the problem
Audit or recount more ballots if needed
Document what happened
Certify the result
🔑 The Keeper Line

Finding an error is not evidence that election safeguards failed. Sometimes finding the error is the safeguard working.

Remember Pennsylvania’s 2024 audit from Part 6? The audit found a handful of small discrepancies. The largest changed the tally by only two votes.

Pennsylvania officials said discrepancies like these can result from human error when ballots are manually tallied during the audit or from stray or unclear marks that require officials to interpret voter intent.

The discrepancies were found because officials checked. The audit still confirmed the reported outcome.

Of course, not every discrepancy is harmless. A larger or unexplained mismatch deserves more investigation — and, depending on the audit rules and what officials find, more ballots may need to be examined.

The size, cause, and effect of the discrepancy matter.

Part 9 — What About the Internet?

One of the most common questions about voting machines is simple:

Are they connected to the internet?

The answer depends on what equipment we’re talking about.

An election office uses several kinds of technology, and they don’t all do the same job. Saying “the election system was connected to the internet” without identifying the system can create more confusion than clarity.

1. Voting equipment

These are the scanners and other equipment used to record or tabulate votes. Voting systems use security controls intended to protect them from unauthorized access, and election officials use procedures to securely move results from voting systems into other reporting systems.

2. Election management systems

These are back-office systems election officials use to prepare elections, configure equipment, create ballot definitions, and manage election data.

3. Election-night reporting systems

These are the systems that publish unofficial results to websites that voters and news organizations watch on election night. These systems can be internet-connected.

🚨 Election Website ≠ Voting System

If a county’s election-results website crashes, is defaced, or is attacked, that’s a cybersecurity incident and officials should take it seriously.

But it does not automatically mean the votes themselves were changed.

Election-night reporting websites display unofficial results. The underlying ballots and official tabulation process are separate things that can be checked through the procedures we’ve already discussed.

Think of an election-results website like a scoreboard.

If someone hacks the scoreboard, you have a serious security problem. But changing what the scoreboard displays doesn’t automatically change what happened on the field.

None of this means internet connections should be shrugged off. If voting equipment or another sensitive election system is unexpectedly connected to an outside network, that’s a legitimate security concern that should be investigated.

But evidence of a connection is not automatically evidence that someone gained access, changed votes, or changed an election outcome.

🔑 Before reacting to “the election system was hacked,” ask one question:

Which system?

A public website, a voter-registration database, an election management system, and a voting machine are not the same thing.

Part 10 — How to Evaluate a Claim That an Election Was Hacked

AI. Satellites. Foreign hackers. Secret internet connections. A video racing across social media.

Election claims can get complicated — and dramatic — very quickly.

You don’t need to be a cybersecurity expert to evaluate every claim. You need to know what questions to ask.

1

What system was allegedly compromised?
A voting machine? Election-management software? A voter-registration database? A public results website?

2

What evidence shows someone actually gained access?
Remember Part 2: a vulnerability is not the same thing as evidence that someone exploited it.

3

Is there evidence that votes were changed?
Getting into a system and changing an election result are two different claims.

4

Is there a paper record?
If so, the electronic count can potentially be checked against physical ballots.

5

Was there an audit or recount?
And if there was, did the physical ballots agree with the reported outcome?

6

What did the investigation find?
What did election officials, courts, cybersecurity investigators, auditors, or other relevant evidence conclude?

🔑 A dramatic claim is not evidence. And an official statement should not be the end of the inquiry.

The strongest evidence is something that can be independently checked — especially physical ballots, audit results, recounts, court records, technical findings, and documented election records.

The same standard should apply no matter who is making the claim.

“The election was hacked” requires evidence.

So does “there’s nothing to worry about.”

Ask what happened. Ask for the evidence. Then ask how it was checked.

Think of it like a smoke alarm.

A security vulnerability tells you where a fire could start. Evidence tells you whether there was actually a fire.

If the alarm goes off, investigate. But don’t declare the building burned down before anyone checks.

What About AI?

AI makes it easier to create convincing fake audio, images, documents, screenshots, and videos. But AI doesn’t change the standard of proof.

If a viral video claims voting machines were hacked, the questions remain the same: Which system? What evidence shows access? Did votes change? Is there a paper record? What did the audit find?

New technology can make the claim look more convincing. It doesn’t make the evidence stronger.

🔑 The Rule

Don’t start with Who said it?

Start with: What is the evidence, and how can it be checked?

Part 11 — Putting the Test to Work: What Happened in 2020?

After the 2020 election, claims spread that voting machines had secretly changed votes or altered the outcome.

Rather than starting with “true” or “false,” let’s apply the same test from Part 10.

What was the evidence, and how was it checked?

Were the claims tested in court?

Yes. Numerous lawsuits challenged the 2020 election results or election procedures.

But there’s an important nuance: not every case was decided after a full trial on the evidence. Some were withdrawn or dismissed for procedural reasons. Others were considered on their merits, and courts rejected claims because the evidence or legal arguments did not support the requested relief.

That’s more accurate than the shorthand you sometimes hear that “60 courts examined all the evidence and found nothing.”

Were the machine totals checked against paper?

In Georgia, yes.

Because the presidential race was close, the state’s 2020 risk-limiting audit expanded into a full manual tally of every ballot cast in the presidential contest.

In other words: humans counted the paper ballots and compared the result with the machine count.

The hand count confirmed the same winner.

Georgia didn’t stop there.

After the hand audit, the Trump campaign requested a machine recount. That recount also confirmed the outcome. The state also had a federally accredited testing laboratory examine equipment in six counties; according to the Georgia Secretary of State, the examination found no evidence that the machines had been tampered with.

So the evidence wasn’t simply:

“Trust the original machine count.”

It included a paper-ballot hand count, a recount, and additional equipment examination.

What happened to some of the machine claims afterward?

Some allegations involving Dominion Voting Systems later became the subject of defamation litigation.

In 2023, Fox agreed to pay $787.5 million to settle Dominion’s defamation lawsuit on the day the trial was scheduled to begin. Because the case settled, there was no jury verdict at trial.

The larger lesson for this article isn’t about Fox or Dominion.

A claim can be repeated millions of times and still has to survive the evidence.

Run the checklist

Was a vulnerability alleged? Yes.

Was there evidence that machines changed enough votes to alter the outcome? No such evidence was established in the court decisions and post-election examinations discussed here.

Was there paper to check? In key contested jurisdictions such as Georgia, yes.

Were ballots audited or recounted? Yes.

Did those checks change the reported winner? No. Georgia’s statewide hand audit and subsequent recount confirmed the same outcome.

Similar claims and rumors continued to circulate during later elections, including 2024. But the standard doesn’t change with the election year, candidate, or political party:

ClaimEvidenceVerificationFinding

Not who shouted loudest.

What did the records show?

Part 12 — No Election System Is Perfect

The wrong conclusion would be “voting machines cannot be hacked.” That’s too absolute, and you shouldn’t trust anyone who tells you so.

Voting machines are not perfect.

They’re technology. Technology can fail. Software can have bugs. Equipment can malfunction. People can make mistakes. And attackers can try to exploit weaknesses.

Election security isn’t built on pretending those risks don’t exist.

It’s built on planning for them.

🔐 Defense in Depth

Cybersecurity experts call this defense in depth.

In plain English: don’t bet the whole election on one lock.

If one safeguard fails, another should be there to catch the problem.

No single layer is perfect. That’s why there are multiple layers designed to catch each other’s misses.

Certification
Recounts
Audits
Reconciliation
Paper records
Pre-election testing
Physical + cyber access controls
Think of a house.

You might have locks on the doors, an alarm system, cameras, and smoke detectors.

Having an alarm doesn’t mean the locks failed. Having locks doesn’t mean you don’t need an alarm.

Each layer protects against something different.

Election security works the same way.

This is why the paper-record number from Part 3 matters so much. A voter-verifiable paper ballot gives officials something the software cannot rewrite after the fact:

a physical record of the vote.

It’s the ground truth that audits and recounts can go back and check.

The goal isn’t to build a system where nothing can ever go wrong.

The goal is to make it much harder for something to go wrong without being detected — and to leave evidence that can be checked when questions arise.

🔑 Key Takeaway

Election security isn’t one machine, one test, or one official saying, “Trust us.”

It’s layers of checks that can check each other.

Final Thoughts — Don’t Trust the Machine. Verify It.

The reassuring argument shouldn’t be:

“Trust voting machines.”

It should be:

We shouldn’t have to.

That’s why the paper matters. That’s why the audits matter. That’s why we check.

In the 2024 election, roughly 98% of votes cast had a paper record. That gives election officials something physical to compare against the electronic count when questions arise.

We started this article with a question:

Can voting machines be hacked?

The answer is that voting technology can have vulnerabilities, just like other technology.

But that was never the most useful question.

The better question is:

Can we check the machine’s work?

In the overwhelming majority of American elections, paper records make that possible. How thoroughly those records are checked still varies by state — which is why strong audit laws matter.

Ask questions. Demand evidence. And when someone tells you an election was hacked, don’t stop at the claim.

Ask how they know. Then ask how it was checked.

Discussion Questions

  1. Should every voting system in the United States be required to produce a voter-verifiable paper record?
  2. Should post-election audits — including risk-limiting audits — be mandatory nationwide?
  3. How much evidence should be required before officials investigate claims that voting machines changed election results?
  4. Does learning how audits and certification work make you more confident in election results — or raise new questions?
  5. Who should be responsible for explaining election-security safeguards to the public before misinformation spreads?

Sources & Further Reading

Related Articles: Voting in AmericaWho Runs Elections in the United States?

Discussion(0)

💬

No discussions yet

Be the first to join the discussion and share your thoughts with the community.

Join the Discussion

Please log in to share your thoughts with the community.

Log In

Popular Articles

Stay in the Loop

Get new explainers and insights—no noise, no overload.