READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Trump Administration Found Real Vulnerabilities in Puerto Rico Voting Machines, Then Killed the Follow-Up Contract

Trump Administration Found Real Vulnerabilities in Puerto Rico Voting Machines, Then Killed the Follow-Up Contract
A small cybersecurity firm hired under Tulsi Gabbard's ODNI found a dozen serious flaws in Dominion voting systems used in Puerto Rico, but no proof any vote was ever changed. When the company got ready to expand the probe ahead of the midterms, federal officials pulled the funding instead. That's a real accountability failure, regardless of who benefits from it. Verdict: legitimate vulnerabilities found, zero evidence of manipulation, and a security expansion killed right when it mattered most.

A cybersecurity firm hired to inspect Dominion voting machines used in Puerto Rico found more than a dozen serious software flaws. Then, just as it geared up to expand that work before the November midterms, the federal government cut it off.

That's the account Mojave Research CEO Jason Wareham and Chief Technology Officer Manbir Gulati gave Friday at the DEF CON hacker convention's Voting Village in Las Vegas, according to Defense One. The two executives laid out technical findings and answered questions from reporters about a federal contract that grew, then abruptly died.

What Mojave found

Mojave spent roughly six weeks examining Dominion systems tied to Puerto Rico's 2024 elections. According to Defense One's account of the DEF CON presentation, the firm identified at least a dozen high- or critical-severity software vulnerabilities.

Passwords were reused across systems. Firewalls were disabled. Cryptographic protections meant to secure the machines were, in the company's assessment, poorly implemented. In Puerto Rico specifically, researchers found active cellular hardware modems that opened additional pathways into software that was supposed to be isolated from outside networks.

Those are legitimate, specific technical findings from a firm that got hands-on access to real voting infrastructure.

But Mojave also said it found no evidence any of those weaknesses had actually been exploited, and no evidence any votes were changed. Wareham's team wanted more time to be certain before drawing broader conclusions.

Where the request came from

Mojave wasn't originally an election-security contractor. According to Defense One, the company was already doing unrelated technical work for the Office of the Director of National Intelligence when, under then-Director Tulsi Gabbard, ODNI officials approached Mojave last year about examining voting machines and data from Puerto Rico.

Reuters reported in February that the May 2025 operation connected to a joint ODNI-FBI effort investigating allegations that Venezuela had hacked Puerto Rico's voting systems. Gabbard's office denied that Venezuela was the driving motivation and said the work centered on technical vulnerabilities, not a specific foreign-interference theory. The probe, according to that reporting, produced no clear evidence of Venezuelan interference.

The allegation of Venezuelan hacking was a claim made by unnamed sources feeding Reuters' reporting, not something proven by Mojave's own findings. Mojave's technical work stands on its own regardless of whether the Venezuela angle panned out, and it didn't.

Wareham described how ODNI initially asked whether his team of reverse engineers and forensic specialists could travel to Puerto Rico and image a voting system that had actually been used in an election, without the vendor supervising the process. He agreed, expecting a relatively contained project.

The expansion, then the shutdown

That contained project grew. Federal officials asked Mojave to scale its team from roughly 10 people to about 60, according to Wareham. Gulati said the company received authorization to proceed with a follow-on effort, brought on new personnel, and got funding approved to buy equipment for examining more voting systems ahead of the 2026 midterms this November.

A contracting officer had reportedly been assigned to finalize the new agreement. Then, as Mojave prepared to move forward, the work was shut down.

Defense One's reporting doesn't specify who made the shutdown decision or give an official reason on record. That's the biggest hole in this story, and it's a significant one. Without a named official explaining why funding for a legitimate vulnerability-testing expansion got killed weeks before a midterm election, readers are left with the contractors' account and nothing to weigh it against.

The fair question skeptics will raise

Critics of expanded federal poking-around in state and territorial election systems have a real point worth stating plainly. Election administration is constitutionally a state and local function, and there's a legitimate worry about federal agencies embedding cybersecurity teams inside voting infrastructure without full transparency to state election officials or the public. It's the same federalism argument raised for years by state election officials wary of DHS involvement going back to 2016.

But that concern cuts against the shutdown just as much as it cuts against the original contract. If the worry is federal overreach into voting systems, the answer isn't to quietly kill a vulnerability assessment that already found real flaws. It's transparency about what was found, who has access to the data, and why the follow-up got cancelled.

What's unresolved

Mojave found genuine, specific software vulnerabilities in machines used in a U.S. election. It found zero evidence those vulnerabilities were exploited. And the federal government, after ramping the project up sixfold, pulled the funding right as the company prepared to check more systems before another national election.

No official has gone on record explaining the decision. No agency has said whether Puerto Rico's election officials or Dominion were informed of the specific flaws Mojave documented, or whether they've been patched.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Defense OneThe government was ready to expand its voting-security work. Then it pulled the plug