Georgia's elections are neither the rigged machine one side imagines nor the flawless system the other insists on. Real protections exist — and the state has repeatedly weakened them by choosing cost and convenience over security margin. Getting this right isn't partisan. It's about building a system whose results anyone can verify, no matter who wins.
The most serious breach in the state's history came from one party's operatives; the most viral fraud hoax came from the other's. That symmetry is the point. This report lays out what's true, names where the corners were cut, and proposes a way to close the gaps — with every claim labeled:
I. What actually protects a Georgia ballot
Start with the good news, because it's real. Georgia conducted statewide risk-limiting audits of the 2022 and 2024 general elections — all 159 counties — and after 2024 also audited all 5.2 million ballot images before certifying.1 For the 2022 Senate runoff audit it did something genuinely good: it published a cryptographic hash of the machine tallies before the hand count began, so the public could confirm nothing was altered mid-audit.1 These are practices worth keeping — more than many states do.
But here's the catch that defines everything else. Georgia is one of only two states that require every in-person voter to use a ballot-marking device — a Dominion touchscreen, first used statewide in 2020, bought for $107 million, recently rebranded "Liberty Vote." The machine prints a paper ballot carrying both readable text and a QR code — and the QR code is what the scanner counts.2
That single choice is the seam through which every risk enters. As the nonpartisan group Verified Voting and computer scientists like Andrew Appel and J. Alex Halderman document: a risk-limiting audit can only confirm the paper was tabulated correctly — it cannot detect whether the machine printed what the voter actually intended, and few voters carefully check the printout.14 So Georgia audits the half of the loop a machine can't corrupt and leaves unaudited the half it can. The paper trail is only as trustworthy as the machine that prints it.
II. Where the state cut its own corners
The through-line is not fraud. It is officials, again and again, choosing the cheaper or more convenient path over the safer one — and it crosses administrations.
Known vulnerabilities, deliberately left unpatched. A 2021 security analysis of Georgia's exact machine by Halderman and Auburn's Drew Springall — filed under seal, unsealed June 2023 — found a flaw that could spread malware from a county's central system to every ballot-marking device in the county.6 In June 2022, CISA documented nine vulnerabilities in that machine.7 In fairness, both halves must be said: CISA found no evidence any were exploited, and they are not remotely exploitable — an attacker needs physical or insider access.7 And also: a fix existed — a federally certified update, March 2023 — yet Georgia announced it would not patch until after the 2024 presidential election, citing the labor.6 "Your locks have a known flaw and here is the new lock" met with "we'll change it after the big event" is a choice — the definition of adopting a risk you didn't have to.
Coffee County: the breach that proved the locks matter. The most serious documented compromise of Georgia's system, verified down to surveillance-camera timestamps. On January 7, 2021, a forensics firm hired through Trump attorney Sidney Powell's organization — billed $26,000 — was escorted into the Coffee County elections office by the local GOP chair and copied virtually the entire voting system: server, poll pads, ballot-marking devices, scanner — roughly half a terabyte.89 Operatives returned January 18 and later that month, and the copied software — the same system used statewide — was distributed to more than a dozen people across several states.8
The response was slow at every stage — the state didn't seize the key computer until over two and a half years later.8 On accountability: Powell and bail bondsman Scott Hall pleaded guilty in 2023 and those convictions stand — but on November 26, 2025 the entire Fulton County case was dismissed, dropping the remaining charges, after the district attorney was disqualified and the special prosecutor concluded a sitting president couldn't realistically be tried in Georgia and that pursuing the remaining defendants "would not be in the state's interest."10 Two guilty pleas; everything else dropped for reasons unrelated to whether the breach happened. It happened — and experts warned in court that distributing perfect copies of the state's software increases the risk to future elections.8
The mandate the state passed and then refused to fund. Georgia's legislature did the right thing on paper: SB 189 (2024) banned QR-code tabulation, requiring machines to count the text a voter can read, effective July 1, 2026.2 Then it appropriated no money to comply — not in 2025, not in 2026 — against a cost estimated near $66 million.3 The deadline arrived and passed with nothing done. In June 2026, lawmakers passed SB 3EX, which Governor Kemp signed June 25, 2026, delaying the ban to January 1, 2028, adding hand recounts of the top two statewide races within a 0.5% margin, and stripping the Secretary of State of authority over choosing the next voting system.45 November 2026 will run on the very QR-code equipment the state already voted to abandon. A security mandate with no funding isn't a reform; it's a press release.
The Musk question, answered honestly
Nothing corrodes an election-integrity argument faster than mixing a real concern with a debunked one. So, precisely:
Debunked: Starlink changed the 2024 vote count. The viral claim that Elon Musk's satellites flipped votes was rated Pants on Fire by PolitiFact and disproven by AFP, FactCheck.org, Snopes, and CISA; U.S. tabulators aren't connected to the internet, and Georgia's Secretary of State called it "100% false."1112 The only documented Starlink use in 2024 election infrastructure anywhere connected pollbooks — not vote counters — in one California county. DEBUNKED Worth noting for anyone who thinks this is a one-party problem: this hoax spread largely through left-leaning accounts. Election disinformation isn't partisan, and neither is the discipline to reject it.
Documented, but not (yet) in Georgia: federal voter-data centralization. Separately and for real: in January 2026 the Justice Department acknowledged a DOGE employee at the Social Security Administration signed a "Voter Data Agreement" with a voter-fraud advocacy group, and by early 2026 more than ten states had handed over their full voter files — including driver's-license and partial Social Security data — under agreements whose contractors are not bound by the data-safeguard terms.13 But two rounds of research found no documented evidence that Georgia shared its voter file, or that any Musk-affiliated operation touched Georgia's election systems. CONFIRMED ABSENCE The real, documented risk is a national data-centralization pattern with weak safeguards — not a Georgia intrusion. Say exactly that, and no more.
III. The better way
The encouraging part: the fixes are well understood, endorsed across the nonpartisan expert community, and — because the state is about to spend tens of millions on new equipment anyway — affordable to get right at the exact moment Georgia has to choose.
- Make hand-marked paper ballots the default, with accessible devices for voters who need them — the architecture recommended by Verified Voting, Halderman, Appel, and the National Academies.14 It removes the one component audits can't check, and costs less per election than a touchscreen for every voter. The forced 2026–28 equipment decision is the moment to switch instead of buying the same problem again.
- Fund what you mandate. Every requirement arrives with the money and the realistic timeline to do it. SB 189 is the cautionary tale in the state's own memory.
- Count what the voter can read. Text-based tabulation — already the law — must actually take effect on a real, funded schedule. Never count a vote from a code only a machine can read.
- Strengthen the audits. Cover all statewide contests with binding escalation to a full hand count when close, and keep the good transparency practices — publishing tally hashes and ballot images.
- Put a patch clock in the law. A fixed deadline for applying vendor and CISA-flagged security patches, with public disclosure when one is missed. No more 18-month deferrals by press release.
- Chain of custody with teeth. Badge-logged, videoed, two-person access to election-management rooms; fixed timelines for investigating breaches; annual independent physical-security audits. Coffee County happened because the physical locks — and the will to enforce them — weren't there.
- Keep equipment decisions with professionals, in the open. Election-equipment selection belongs with administrators under transparent public procurement — not the ad-hoc legislative body SB 3EX just created.
- Don't feed the aggregators. Decline to hand Georgia's full voter file, with sensitive personal data, into federal programs whose contractors aren't bound by the safeguards the state would demand of itself.
An election system earns trust not by asking for it but by being checkable — by producing a result a skeptic of either party can audit back to a piece of paper the voter actually verified.
Georgia is closer to that than its loudest critics claim and further than its defenders admit. The state is about to spend real money on new voting equipment no matter what. It can buy the same unverifiable design a second time — or ballots its citizens mark, machines its citizens can check, audits that cover the whole loop, and locks that are actually guarded. We can do this better, and the deadline that forces the choice is already here.
A note on method and sourcing
This report is deliberately nonpartisan, because the verified record is: the gravest breach traces to one party's operatives, the biggest hoax to the other's, and the pattern of cutting corners spans administrations. Claims marked verified survived independent, adversarial multi-source fact-checking against primary sources — the Coffee County record (down to surveillance timestamps and the November 2025 case dismissal), the CISA advisory and the unpatched-vulnerability decision, the SB 189 / SB 3EX legislative history, and the Starlink debunking. Where the record is silent — notably any Georgia-specific Musk or DOGE election connection — we report the silence as a finding rather than filling it.
Sources (numbered links match the footnote markers above):
- Georgia Secretary of State — Elections audit information
- Ga. General Assembly — SB 189 (Act 697, 2024) enrolled text
- Votebeat — Georgia's QR-code voting-machine deadline and the funding gap
- The Current — Kemp signs elections bill (SB 3EX), locking in QR-code machines for November
- WABE — Hand-recount provision amended to close calls only
- Princeton CITP — Security analysis of the Dominion ImageCast X (Halderman & Springall)
- CISA — ICS advisory ICSA-22-154-01 (Dominion ImageCast X)
- Lawfare — What the heck happened in Coffee County, Georgia
- Washington Post — Coffee County breach: surveillance-footage investigation
- Georgia Recorder — Fulton County election-interference case dismissed (Nov 26, 2025)
- PolitiFact — No, Starlink wasn't used to rig the 2024 election
- FactCheck.org — Musk's Starlink was not connected to vote tabulation
- Brennan Center — Confidential agreements show the plan for states' voter data
- Verified Voting — Statement on ballot-marking devices and risk-limiting audits