VOATZ

Organization dossier SCOTUS amicus 19-783 Status: still operating

The blockchain voting app that collected real ballots in real U.S. elections — then, when someone poked at it, had the intrusion reported to the FBI. Reporting later linked the poking to a University of Michigan election-security course. When MIT and Trail of Bits found the app riddled with holes, Voatz's answer was a Supreme Court brief arguing that uninvited security research should stay a crime.

the researchers were analyzing an Android version of the Voatz mobile voting app that was at least 27 versions old at the time of their disclosure and not used in an election … they were unable to register, unable to pass the layers of identity checks to impersonate a legitimate voter, unable to receive a legitimate ballot and unable to submit any legitimate votes or change any voter data.

Voatz, "Voatz Response to Researchers' Flawed Report," voatz.com, Feb 13, 2020

necessary research and testing can be performed by authorized parties. These include private consulting firms and participants in organized "bug bounty" programs.

Voatz, amicus brief in Van Buren v. United States, filed with the U.S. Supreme Court, Sep 3, 2020

ENTITY
Voatz, Inc., Boston, Massachusetts — mobile "blockchain" voting platform, secured (per the company) by biometric identity checks FACT
PRINCIPAL
Nimit Sawhney, co-founder & CEO — the company's public voice; the record below is the company's conduct, not a personal indictment FACT
DEPLOYMENT
Live U.S. elections — West Virginia's 2018 absentee/overseas and military ballots, plus pilots in other jurisdictions FACT
THE DRAMA
An intrusion reported to the FBI that reporting tied to a student researcher; an MIT teardown; a commissioned Trail of Bits audit that confirmed it; a HackerOne expulsion; and a Supreme Court brief against uninvited research
RECORD
No fraud adjudication, and no charges against any researcher, appear in this record. The vulnerability findings are MIT's and Trail of Bits's, attributed. Voatz's rebuttals are Voatz's, quoted. FACT
STATUS
STILL OPERATINGvoatz.com is live; the app persists; the archive keeps the tape running

This one is a company, not a person — and a company of this species speaks through a single mouth, so the CEO appears throughout. Keep the two distinct; this file does. What follows is the sequence in order: the deployment, the referral, the teardown, the audit, and the brief.

It is a strange arc to keep straight: a vendor sold "secure by design," a stranger tested that claim, and the vendor's first instinct was law enforcement, its last instinct the Supreme Court. That is why the archive exists. Every beat below carries its receipt. Both sides get the microphone. You decide who wins.

the drama timeline

ACT I — THE DEPLOYMENT (2018)

A startup persuades a state to let citizens vote from their phones. The pitch is a word the field distrusts on sight: blockchain. Watch what the field does with it.

  1. 2018

    Real ballots, real election

    West Virginia deploys Voatz to collect absentee ballots from overseas and military voters in the 2018 midterms — the first U.S. jurisdiction to run mobile voting in a federal election. Per state officials and the developer, the app grants ballot access only to voters who clear "multiple layers of biometric identification, including facial-recognition and fingerprint scanning." Pilots in other jurisdictions follow.

ACT II — THE REFERRAL (OCT 2019)

Somebody prods the gate. The gate reports the prodding to the federal government. Months later the government is still deciding whether the prodder was a criminal or a sophomore.

  1. OCT 2019

    The FBI investigation, revealed

    U.S. Attorney Mike Stuart reveals an FBI investigation into an "attempted intrusion by an outside party" against the Voatz app during the 2018 cycle. West Virginia Secretary of State Mac Warner's office had detected activity from IP addresses associated with the University of Michigan; CNN reports the FBI is investigating a person or people who tried to access the app as part of a University of Michigan election-security course. Voatz's account, from CEO Nimit Sawhney: "The attempt was detected, thwarted at the gate and reported to the authorities." No charges are filed.

    Michigan is one of a handful of universities with a curriculum built around election security. The gate held; the question was only who was standing outside it.

ACT III — THE TEARDOWN (FEB 2020)

This time the testers do not stop at the gate. They publish. And they do it under three names, at a venue that peer-reviews.

  1. FEB 13, 2020

    MIT: "The Ballot is Busted Before the Blockchain"

    MIT researchers Michael Specter, James Koppel, and Daniel Weitzner publish a security analysis finding that an attacker could alter, block, or observe a user's vote, and that a compromised server could change votes without detection. Their conclusion: the app should not be used in high-stakes elections. The work later appears at USENIX Security 2020 as "The Ballot is Busted Before the Blockchain." West Virginia and a Washington county drop Voatz for their 2020 primaries.

  2. FEB 13, 2020

    Voatz answers, same day

    Voatz publishes "Voatz Response to Researchers' Flawed Report" the same day, arguing the MIT team examined an Android build "at least 27 versions old … not used in an election," never connected to Voatz's live servers, and so never registered, received a ballot, or cast a vote. It says the researchers "fabricated an imagined version of the Voatz servers, hypothesized how they worked, and then made assumptions … that are simply false," and notes roughly 100 researchers had tested the real platform through its public bug bounty.

ACT IV — THE AUDIT AND THE EXPULSION (MAR 2020)

A company that says "you tested the wrong version" has one clean move available: commission an audit of the right version, in the open. Voatz makes it. Then reads the result.

  1. MAR 2020

    Trail of Bits: 79 findings, MIT confirmed

    Trail of Bits publishes its full report on a review Voatz itself commissioned: 79 findings, roughly a third of them high-severity. Its verdict: "Our assessment confirmed the issues flagged in previous reports by MIT and others, discovered more, and made recommendations to fix issues and prevent bugs from compromising voting security." The audit of the right version, in the open, largely agrees with the teardown of the wrong one.

  2. MAR 2020

    HackerOne cuts ties

    HackerOne removes Voatz from its bug-bounty platform — a step CyberScoop reports as a first for the company — citing Voatz's hostile posture toward the researchers who had been probing it. The bug bounty Voatz kept invoking as proof of openness is the door that closes on it.

ACT V — THE BRIEF (SEP 2020)

A vendor bruised by uninvited research has one more venue to appeal to. Not a conference. Not a journal. The Supreme Court of the United States.

  1. SEP 3, 2020

    The amicus brief

    Voatz files an amicus brief in Van Buren v. United States, urging the Supreme Court toward a broad reading of the Computer Fraud and Abuse Act — the reading under which uninvited security research can be a federal crime. Its position: "necessary research and testing can be performed by authorized parties," namely consulting firms and organized bug-bounty participants. Security researchers and the Center for Democracy & Technology respond that the brief "fundamentally misrepresents widely accepted practices in security research and vulnerability disclosure."

    The full arc, in one filing: the company that reported a prod to the FBI now asks the highest court in the land to keep the prodding illegal unless the prodder asked first.

  2. EPILOGUE

    Still operating

    In June 2021 the Supreme Court narrowed the CFAA anyway — against the reading Voatz urged. The MIT paper stands in the USENIX proceedings; the Trail of Bits findings stand on Trail of Bits's own servers; voatz.com is live. The archive keeps the tape running.

both sides, on the record

The findings (theirs, not ours): MIT's Specter, Koppel, and Weitzner concluded an attacker could alter, block, or observe a vote, and that a compromised server could change votes — keep the app away from high-stakes elections [1] [2]. Trail of Bits, in a review Voatz commissioned, logged 79 findings and stated it "confirmed the issues flagged in previous reports by MIT and others" [4].

The referral: when someone tested the live app in 2018, the activity was reported to the authorities and the FBI investigated — an inquiry reporting later tied to a University of Michigan election-security course, closed with no charges [6] [7].

The documented conduct: after the field rejected its claims, Voatz asked the Supreme Court to keep uninvited security research legally exposed, and HackerOne removed it from its platform — both matters of public record [5] [8].

The company's position, in its own words: the MIT team analyzed an Android build "at least 27 versions old … not used in an election," never connected to Voatz's servers, so it never registered, received a ballot, or cast a vote; the researchers, Voatz says, "fabricated an imagined version of the Voatz servers" and reasoned from false assumptions [3]. On the referral, CEO Nimit Sawhney: "The Voatz system worked as designed and intended. The attempt was detected, thwarted at the gate and reported to the authorities" [7].

Its strongest cards are real: no source shows any actual election result was altered; no researcher was charged; and Voatz did commission the independent Trail of Bits audit and ran a public bug bounty that it says roughly 100 researchers used [3] [4]. On the CFAA, Voatz frames its brief not as anti-research but as pro-authorized-research — consulting firms and bug-bounty participants — its words, quoted [5].

Scope of the record: the security findings are expert findings — named, published, and, in the commissioned audit's case, Voatz's own procurement — but no court or regulator has adjudicated Voatz's product or its conduct, and nothing on this page alleges personal wrongdoing by Nimit Sawhney. The company operates today [9].

YOU DECIDE

Scoped to the claims, never the company — and never the man. The claim "the MIT teardown proves nothing, wrong version" is Voatz's strongest, and it is partly true: a lab teardown of a 27-versions-old build is not proof a live election was hacked, and none has been shown. But the claim collided with an audit Voatz chose to buy: Trail of Bits, on the current platform, logged 79 findings and said it confirmed MIT. The claim "we welcome research" reads against a public record in which an intrusion was reported to the FBI, a bug-bounty platform expelled the company, and a Supreme Court brief argued to keep uninvited research a crime. Nothing here is adjudicated. Nothing here is a fraud finding.

Weigh the costly signals: Voatz spent real money on a Trail of Bits audit and a Supreme Court filing. The researchers spent a paper and a laptop. One of those audits, the one the company paid for itself, is the hardest sentence on this page to explain away.

The archive does not judge. The archive merely keeps the tape running.

evidence locker

PRIMARY RECORD

  1. MIT News — "MIT researchers identify security vulnerabilities in voting app" (Feb 13, 2020) ATTRIBUTED — the MIT findings, in the institution's own release; Specter, Koppel, Weitzner named. news.mit.edu/2020/voting-voatz-app-hack-issues-0213
  2. USENIX Security 2020 — Specter, Koppel & Weitzner, "The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz" FACT — the peer-reviewed paper itself. usenix.org/conference/usenixsecurity20/presentation/specter
  3. Voatz — "Voatz Response to Researchers' Flawed Report" (Feb 13, 2020) SELF-PUBLISHED — the "27 versions old," "fabricated an imagined version" rebuttal, verbatim. voatz.com/2020/02/13/voatz-response-to-researchers-flawed-report/
  4. Trail of Bits — "Our Full Report on the Voatz Mobile Voting Platform" (Mar 13, 2020) ATTRIBUTED — the commissioned audit: 79 findings; "confirmed the issues flagged in previous reports by MIT and others." blog.trailofbits.com/2020/03/13/…-voatz-mobile-voting-platform/
  5. Voatz — amicus brief, Van Buren v. United States, U.S. Supreme Court No. 19-783 (Sep 3, 2020) FACT — the brief on the CFAA and "authorized parties," on the public docket. supremecourt.gov/DocketPDF/19/19-783/…_Voatz Amicus Brief.pdf

PRESS & REACTION

  1. CNN Politics — "FBI investigating if attempted 2018 West Virginia voting app hack was linked to Michigan college course" (Oct 4, 2019) ATTRIBUTED — the FBI investigation; the University of Michigan election-security course link; no charges. cnn.com/2019/10/04/politics/fbi-voting-app-hack-investigation/
  2. StateScoop — "Alleged mobile voting app hack linked to University of Michigan" (Oct 7, 2019) ATTRIBUTED — Mac Warner's detection, U.S. Attorney Mike Stuart, and CEO Sawhney's "thwarted at the gate and reported to the authorities." statescoop.com/alleged-mobile-voting-app-hack-linked-university-michigan-report/
  3. CyberScoop — "HackerOne cuts ties with mobile voting firm Voatz after it clashed with researchers" (Mar 2020) ATTRIBUTED — the bug-bounty expulsion. cyberscoop.com/voatz-hackerone-bug-bounty-election-security/
  4. NBC News — "Voatz smartphone voting app has significant security flaws, MIT researchers say" (Feb 2020) ATTRIBUTED — contemporaneous reporting of the MIT findings and Voatz's dispute. nbcnews.com/tech/security/…-n1136546
  5. CyberScoop — "Security researchers slam Voatz brief to the Supreme Court on anti-hacking law" (Sep 2020) ATTRIBUTED — the infosec and CDT reaction to the amicus brief. cyberscoop.com/voatz-supreme-court-cfaa-security-research/
  6. TechTarget — "Voatz, MIT researchers spar over blockchain e-voting app" ATTRIBUTED — the Trail of Bits audit set against Voatz's rebuttal. techtarget.com/searchsecurity/news/252478923/…

SUBJECT'S OWN CHANNELS — THE COMPANY, UNEDITED

  1. voatz.com SELF-PUBLISHED — the operation, still open for business. voatz.com
  2. X — live search: "Voatz" "MIT" LIVE SEARCH — the discourse, ongoing. Account-level and search links only; no fabricated permalinks. x.com/search?q=%22Voatz%22%20%22MIT%22
The standard. Everything above is sourced to a Supreme Court docket, a peer-reviewed USENIX paper, the audit Voatz itself commissioned, the company's own publications, and named press reporting. Facts are stated as facts; the vulnerability findings are stated as MIT's and Trail of Bits's and wear their authors; the FBI referral is stated exactly as the sources establish it, with no charge implied against any researcher and no motive assigned to the company. The company is distinguished from its CEO, expert findings are distinguished from adjudication, and the defense — the old-build rebuttal, the unaltered elections, the uncharged researcher, the commissioned audit — is presented at full strength. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.