Vulnerabilities Negative 6

6-Week Vote Machine Audit Found Weaknesses, Zero Fraud

A six-week federal review of a Liberty Vote machine found extensive vulnerabilities but no evidence of exploitation. That honest finding cost Mojave Research its government contract and triggered a disinformation campaign. The case exposes the political risks of independent security testing.

· 5 min read · Verified by 3 sources ·

Cybersecurity briefing

Key takeaways

6 impact
Negativesentiment
3sources
5min read
  1. A six-week federal review of a Liberty Vote machine found extensive vulnerabilities but no evidence of exploitation.
  2. That honest finding cost Mojave Research its government contract and triggered a disinformation campaign.
  3. The case exposes the political risks of independent security testing.
Drawn from
  • us.cnn.com
  • news8000.com
  • kten.com

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Mojave Research had no prior experience testing election systems when ODNI contacted it in spring 2025.
  2. 2The firm analyzed a specific Liberty Vote (formerly Dominion Voting Systems) machine acquired by ODNI from Puerto Rico.
  3. 3Mojave completed the technical review in six weeks in CEO Jason Wareham's basement in Reston, Virginia.
  4. 4CTO Manbir Gulati reported 'extensive and largely unacceptable weaknesses' but no evidence of active exploitation or altered votes.
  5. 5Mojave submitted its report to ODNI in July 2025, and it has not been made public as of August 2026.
  6. 6The Trump administration declined to renew Mojave's contract after the firm did not endorse false voter-fraud claims, and allies spread false George Soros funding claims.

We found extensive and largely unacceptable weaknesses, but we did not find evidence that those weaknesses were actively exploited or that votes were altered.

Manbir Gulati Chief Technology Officer, Mojave Research

At DEF CON's Voting Village symposium

Analysis

For election security researchers, the Mojave Research case is a stark warning about what happens when technical truth collides with political expectation. A small firm with no election-testing background was thrust into a federal review, found serious weaknesses but no fraud, and saw its contract vanish. The implications for vulnerability disclosure, procurement integrity, and researcher independence are profound.

The central development is that Mojave Research, a cybersecurity firm with no prior election-systems testing experience, was hired by the Office of the Director of National Intelligence in the spring of 2025 to examine a Liberty Vote voting machine—formerly Dominion Voting Systems—that the agency had acquired from Puerto Rico. According to the firm's executives, speaking publicly for the first time at the DEF CON cybersecurity conference in Las Vegas in August 2026, the six-week basement review found extensive and largely unacceptable weaknesses, but no evidence that those weaknesses were actively exploited or that votes were altered. That finding, rather than reassuring the Trump administration, appears to have triggered a political backlash: the contract was abruptly not renewed after the firm declined to endorse false claims of voter fraud, and allies of President Donald Trump spread baseless claims that Mojave was funded by liberal billionaire George Soros.

Mojave Research's CEO, Jason Wareham, acknowledged that the work was done in his basement in Reston, Virginia, over six weeks—an unusual setting for a review of critical election infrastructure.

This episode sits at the intersection of election security, cybersecurity research integrity, and partisan pressure. The broader context is the long-running effort by President Trump and his allies to relitigate the 2020 election through claims of unreliable voting machines. The Office of the Director of National Intelligence, rather than establishing an independent technical review process with experienced election-security specialists, reached out to a small firm with no relevant domain expertise. Mojave Research's CEO, Jason Wareham, acknowledged that the work was done in his basement in Reston, Virginia, over six weeks—an unusual setting for a review of critical election infrastructure. The specific machine under examination came from Puerto Rico and was made by Liberty Vote, previously known as Dominion Voting Systems, a company that has long been a target of election-fraud conspiracy theories.

The technical findings themselves are nuanced and significant. Mojave's chief technology officer, Manbir Gulati, described the result at DEF CON's Voting Village symposium: "We found extensive and largely unacceptable weaknesses, but we did not find evidence that those weaknesses were actively exploited or that votes were altered." That distinction matters enormously in election security. The presence of serious vulnerabilities in voting equipment is itself a legitimate and serious public-safety concern, regardless of whether it was exploited. But the absence of evidence of active exploitation directly contradicts the Trump administration's preferred narrative that the 2020 election was stolen. This placed Mojave in a politically untenable position: its technical honesty undermined a politically convenient falsehood, and the consequence was professional retaliation.

The retaliation took multiple forms, according to the executives and documents they provided to CNN. Government work was derailed, the contract was not renewed, and false claims spread through Trump-aligned circles that Mojave Research was funded by George Soros—a familiar antisemitic trope used to discredit perceived political opponents. Wareham stated that a group of "White House-adjacent" Trump allies was dissatisfied that he was unwilling to "name and shame" and declare that the election had been a landslide for Trump. This pressure campaign illustrates how independent security findings can be weaponized or suppressed when they conflict with a powerful client's worldview. For the broader cybersecurity community, the message is chilling: honest technical assessment can cost contracts, reputation, and political viability.

What to Watch

There are also operational and market implications for government cybersecurity contracting. Federal agencies increasingly rely on outside firms for election-security testing, vulnerability research, and incident response. The Mojave episode raises questions about procurement standards, experience requirements, and the insulation of technical findings from political review. If small firms perceive that delivering unfavorable findings will result in non-renewal or public smears, it may discourage candid reporting or skew the marketplace toward contractors willing to produce favorable conclusions. Election technology vendors such as Liberty Vote also face reputational risk: the machine in question had extensive vulnerabilities, yet no evidence of exploitation. That dual finding could still pressure vendors to remediate vulnerabilities urgently while avoiding liability for past security failures.

The forward-looking picture is uncertain. Mojave submitted its report to ODNI in July 2025, but it remains unpublished more than a year later. Public release of the full technical findings would allow independent security experts to assess the severity of the weaknesses, verify whether the testing methodology was adequate, and determine whether the voting machine in question has been or should be remediated. Without publication, the report remains a political football rather than a useful piece of election-security intelligence. The episode also underscores the need for structural safeguards around election-security testing, including independent peer review, public disclosure protocols, and protection against political retaliation. If those safeguards are not built, the next firm may hesitate to tell the truth.

Timeline

Timeline

  1. Puerto Rico general election

  2. ODNI contacts Mojave Research

  3. Mojave submits report to ODNI

  4. Mojave executives speak at DEF CON

Source cluster

Primary reporting

3articles

Cite This Page

"6-Week Vote Machine Audit Found Weaknesses, Zero Fraud." Cyber Intelligence Brief, August 13, 2026. https://getcyberbrief.com/story/mojave-research-vote-machine-audit-weaknesses-no-fraud

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.