Thanks, Burl Smith, for providing us with this great summary of the info provided last week regarding the election system vulnerabilities.

The 2026 election will not use one national electronic voting system. Equipment selection is decentralized and often occurs at the county, municipality, or township level. Consequently, a state may simultaneously operate ES&S, Dominion/Liberty Vote, Hart InterCivic, Clear Ballot, Unisyn, VotingWorks, MicroVote, and locally developed systems.
The principal national concern is not that one vendor has been proved to be manipulating votes. It is that much of the equipment expected in 2026:
- was certified under the 2005 VVSG 1.0 standard, rather than VVSG 2.0;
- relies on centrally programmed election-management systems;
- transfers election definitions and results through removable media;
- may contain operating systems and third-party components that cannot be patched at normal enterprise speed;
- is operated on county networks whose segmentation, identity controls, logging, and monitoring vary substantially;
- sometimes uses ballot-marking devices that encode votes in barcodes or QR codes voters cannot directly verify;
- is not always subjected to a statistically valid risk-limiting audit.
The EAC lists only a small number of systems certified to VVSG 2.0 by mid-2026. Hart Verity Vanguard 1.0 and 1.1 and Smartmatic VSR1 2.1 had achieved VVSG 2.0 certification, while ES&S EVS 7.0, VotingWorks VxSuite 4.0, Liberty Vote Frontier 1.0, and Unisyn Optio 1.0 remained under testing. Most systems fielded in November 2026 will therefore remain VVSG 1.0-era systems.
Verified Voting’s November 2026 inventory estimates that approximately:
- 67.9% of registered voters live in jurisdictions using hand-marked paper ballots supplemented by accessible ballot-marking devices;
- 22.7% live in jurisdictions using ballot-marking devices for all voters; this applies to SC for in-person voting
- 3.9% use hybrid ballot-marking/tabulating devices for all voters;
- approximately 3.9% remain in jurisdictions relying primarily on direct-recording electronic equipment with or without voter-verifiable paper.
Risk Scale
Higher: Paperless DRE use, all-voter barcode BMDs, hybrid BMD/scanners, weak paper-audit coverage, legacy equipment, or fragmented local administration.
Elevated: Paper exists, but substantial reliance on machine-generated selections, centralized election-management systems, removable media, or limited post-election auditing.
Moderate: Predominantly hand-marked paper ballots with optical scanners, meaningful audits, reconciliation, and offline tabulation—but still subject to EMS, media, insider, and local-network risks.
Lower relative risk: Hand-marked paper, strong ballot accounting, risk-limiting audits, secure custody, independent audit software, and minimal network dependence. “Lower” does not mean risk-free.
South Carolina Risk Assessment
Equipment names below identify the principal or commonly deployed families expected in 2026, not a guarantee that every county will use the same version. Final certification and deployment should be validated against each state’s pre-election equipment list and county logic-and-accuracy records.
Relative Risk of South Carolina Election System

According to the analysis, SC has the highest risk assessment level and is joined by the following states: Arkansas, Delaware, Georgia, Illinois, Indiana, Louisiana, Mississippi, Missouri, Nevada, New Jersey, Pennsylvania, Tennessee, Texas, and West Virginia—NOTE THAT SC NOW USES THE DS300 Tabulators, but the issues still apply.
Vendor and architecture vulnerabilities applicable across states with ES&S
ES&S EVS, ElectionWare, DS scanners and ExpressVote
Potential weaknesses include:
- election definitions created centrally in ElectionWare and distributed through removable media;
- USB or media compromise crossing an otherwise isolated boundary;
- inability of voters to verify barcode-encoded selections independently;
- configuration or ballot-definition errors affecting many precincts;
- Windows and third-party component patch lag;
- administrative credential and local EMS exposure;
- central scanner and election-night-reporting file integrity;
- hybrid ExpressVote XL devices combining marking and tabulation within one device.
This applies particularly to Arkansas, Delaware, Maryland, Nebraska, South Carolina, West Virginia, and numerous counties elsewhere.
The South Carolina Library material identifies patching, unsupported-component, media, barcode and EMS concerns, although its conclusions should be treated as advocacy analysis rather than a government finding.
States requiring the highest-priority review before November 2026
Tier 1: Independent technical and paper-audit review strongly warranted
- Arkansas
- Delaware
- Georgia
- Illinois
- Indiana
- Louisiana
- Mississippi
- Missouri
- Nevada
- New Jersey
- Pennsylvania
- South Carolina
- Tennessee
- Texas
- West Virginia
The principal reasons are paperless DRE remnants, all-voter BMD or hybrid use, barcode dependence, weak statewide uniformity, or limited auditability.
Recommended Minimum pre-election controls for every state
Before November 2026, each state should publicly document:
- Exact deployed system and version by county, including EMS, scanner, BMD, firmware, operating system, and central-count software.
- Certification-baseline comparison, showing that the installed build matches the certified trusted build.
- Software bill of materials and status of known exploited vulnerabilities.
- Unsupported operating-system report, including compensating controls.
- Independent penetration testing of election-management networks—not just laboratory testing of voting devices.
- Removal or physical disabling of unnecessary wireless and cellular hardware.
- Phishing-resistant MFA for every election-system administrator and vendor technician.
- No routine vendor remote access during the election period.
- Cryptographic signing and hash verification of election definitions, firmware and result files.
- Serialized removable media under two-person custody.
- Clean, publicly observed logic-and-accuracy testing using adversarial test decks covering every candidate and ballot position.
- Pollbook-to-ballot reconciliation before certification.
- Risk-limiting audits based on voter-verifiable paper.
- Human-readable paper as the controlling record, rather than a barcode.
- Preservation of ballots, cast-vote records, original ballot images, logs, media and forensic system images.
- Public reporting of discrepancies, including unexplained differences among pollbook, scanner, canvass and audit totals.
Bottom line: Not one, but many potential vote alteration & inflection points still exist
The greatest 2026 election-system risk is not a single identified vendor backdoor. It is the combined effect of old certification baselines, slow patching, proprietary software, removable media, county network weaknesses, machine-generated barcode ballots, incomplete auditing and decentralized operational control.
Most voters will have a paper record in 2026, which is a major improvement over 2018 and 2020. However, not every paper record is equally trustworthy. A voter-marked paper ballot that is independently audited provides materially stronger assurance than a machine-generated ballot whose controlling QR or barcode cannot be read by the voter.
The most urgent federal and state requirement should be:
Every federal contest must be independently reproducible from voter-verifiable paper after reconciling the number of accepted ballots to the number of eligible voters credited with voting.
NOTE: This analysis identifies architecture-level risks. A definitive forensic readiness report would require the exact 2026 county deployment lists, software versions, certification records, audit statutes, modem configurations, operating systems and CISA mitigation status for approximately 8,000 local election jurisdictions
