
Security Vulnerabilities Found in Dominion ICX Voting Machines Ahead of 2026 Elections
The video demonstrates security vulnerabilities in the Dominion ICX voting machine, used in over 17 U.S. states, including Georgia, California, and Arizona, ahead of the 2026 elections. Researchers acquired a decommissioned machine from Goodwill for $100 and obtained configuration files, security keys, and setup tools from Elections Source (electionsource.com) for $150, including a 'technician key' enabling 'god mode' access with a default password (12345678). The system uses symmetric AES encryption and HMAC keys stored on smart cards, allowing attackers to decrypt, modify, and re-encrypt election databases—altering candidate names, party affiliations, or ballot questions without detection. The machine’s Android-based terminal permits HTML manipulation of on-screen text, while QR codes on printed ballots only record vote positions, not candidate names, enabling undetectable vote swapping. Audits may catch mismatches between front-end displays and back-end tallies, but presentation-layer changes (e.g., bold text, strikethroughs) or removed candidates would evade detection. Researchers emphasized that no real-world exploits have been confirmed, but the vulnerabilities stem from poor key management, reusable passwords, and lack of certificate-based signing. The only suggested safeguard for voters is to manually verify printed ballots against on-screen selections.