"Ultimately, I made the worst decision of my life in a business context," Jason Wareham said.
Jason Wareham's account at DEF CON
At DEF CON’s Voting Village in Las Vegas, Mojave Research CEO Jason Wareham and Chief Technology Officer Manbir Gulati described a six-week federal engagement that began with a narrow assignment and ended with a halted program. The company had been asked to image and analyze Dominion voting systems used in Puerto Rico’s 2024 elections; Mojave’s team expanded from roughly 10 people to an operation that federal officials had authorized to grow toward about 60, Wareham said. Then — as Mojave prepared to press forward — the government issued a stop-work order and no additional funding.
The ODNI request and the Puerto Rico operation
Mojave’s work originated inside the Office of the Director of National Intelligence under then-director Tulsi Gabbard, where the company was already performing unrelated technical work. ODNI asked whether Mojave’s reverse engineers and forensic specialists could travel to Puerto Rico and capture an image of a voting system used in an election, “without the vendor overseeing the process,” Wareham said. Reuters reported the operation was tied to an effort involving ODNI and the FBI to investigate allegations that Venezuela had hacked Puerto Rico’s voting systems; Gabbard’s office denied Venezuela drove the work and said the examination focused on technical vulnerabilities. The probe produced no clear evidence of Venezuelan interference, according to reporting cited by Mojave.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechnical findings: at least a dozen severe vulnerabilities, but no proof of vote changes
Mojave’s review produced a roughly 100‑page preliminary document describing the Puerto Rico system as “deeply insecure,” according to Gulati. Researchers identified at least a dozen high‑ or critical‑severity software vulnerabilities in the commercial software installed on the system and were able to successfully execute five of them. The company reported that many fixes for those flaws already existed, “in some cases well before the system was used in the election.”
Beyond patchable bugs, Mojave found systemic deployment weaknesses: reused and embedded passwords, disabled firewalls, open ports and what Gulati called cryptography “in shambles.” In Puerto Rico, he said, active cellular hardware modems created additional pathways into software thought to be isolated. Despite the catalogue of problems, Mojave “did not find evidence that those weaknesses were actively exploited or that votes were altered,” Gulati emphasized repeatedly.
White House‑adjacent pressure, Kurt Olsen, and the shutdown
Wareham described a bifurcated response inside government: ODNI employees overseeing the technical work wanted the research to continue, he said; a separate “White House‑adjacent” group, he said, was dissatisfied that Mojave had not produced evidence supporting claims of 2020 election manipulation. Reuters reported that Kurt Olsen, identified as a prominent 2020 election‑denier and a Trump adviser involved in post‑2020 investigations, pressed Mojave to broaden its work in search of evidence that could support those claims and later turned against the firm when its research failed to find proof the Puerto Rico machines had been hacked. Wareham said an ODNI official told him the allegation that Mojave was secretly funded by George Soros came from Olsen; Wareham compiled a funding accounting and rejected the claim.
The firm said it briefed the White House on some findings around September and believed it was moving toward a remediation and deeper‑analysis effort timed before the November midterms. Instead, Wareham said, a record‑long government shutdown coincided with a stop‑work order and the termination of the planned expansion. ODNI has said Mojave’s contract ended because the company completed its voting‑machine analysis. The White House, ODNI and Olsen did not return requests for comment.
What this means for technologists, ODNI, and Liberty Vote
- Technologists and security teams: Mojave’s account underscores how patchable bugs and poor deployment practices can coexist; Gulati warned that some issues “could extend beyond a single voting machine company,” though Mojave has not examined enough other systems to prove that.
- ODNI and investigators: The agency commissioned hands‑on forensic work and, according to Mojave, supported it — even as other actors pushed for particular findings. Mojave has sought public release of its report and said it may emerge through a Freedom of Information Act request; ODNI’s FOIA logs are publicly available only through January 2025, the company said.
- Liberty Vote (the company that acquired Dominion’s election business): Mojave said it has been in discussions with Liberty Vote and that Liberty told researchers it does not plan to make changes before November. Liberty replied that “Liberty Vote is not in receipt of any such report so, therefore, we cannot provide any comment.”
Wareham said Mojave wanted another six months to a year to dig deeper into the data; instead the company announced it has filed paperwork to create the Machine Assurance Institute, aiming to bring researchers and election-technology companies together to “independently verify voting infrastructure.” Manbir Gulati cautioned against conflating voter‑file data disclosures with access to systems that can change ballots, saying of a recent presidential declassification that “The China thing isn’t really much of anything” and reiterating, “There is no evidence that I know of that says China successfully or any other country has successfully infiltrated our systems and manipulated votes in any way.”
The record left by Mojave’s halted program is concrete: a detailed internal report, a catalog of known and exploited vulnerabilities, a halted remediation plan and competing accounts over why federal work stopped as midterms approach. The named next steps are equally tangible — a possible FOIA release of Mojave’s report, Liberty Vote’s receipt (or non‑receipt) of that report, and the progress of the Machine Assurance Institute — and whether those steps will produce fixes before the November election remains an open, immediate question.




