Princeton fellow uses AI agents to undo Georgia's ballot shuffle

Max Springer, a postdoctoral research fellow at Princeton's Center for Information Technology Policy, argues in a blog post that a known ballot-scanner flaw has become far easier to exploit now that AI coding agents exist. He says that using AI tools and only public records he reconstructed the order in which about 1.5 million ballots were cast in Georgia's May 2026 primary, covering 98.9% of the in-person ballots. He describes himself as not a security researcher and says he has never been to Georgia.
The flaw itself is old. In October 2022 a team of researchers reported that certain ballot scanners used across the US assign each electronic ballot record a seemingly random number, to keep the published record anonymous. The algorithm that generates the number is deterministic and can be exactly reversed, which reveals the sequence in which ballots were cast. Springer compares it to shuffling a deck by repeatedly moving the top card to the middle and then announcing the method out loud. Knowing the order is only one piece; paired with public records of when voters cast ballots (logbooks, poll watchers), a simple procedure maps ballots back to voters.
Springer's point is about the barrier to entry. Turning a vulnerability paper into working code on the right dataset, he says, would take a trained programmer weeks to months, and that gap was a form of protection. For $20 he accessed what he calls the most powerful coding agents and pointed one at the paper, asking whether the method could be used in Georgia. He says he developed no new attack and found no new exploit. Within a couple of hours he had a pipeline to analyze and identify secret ballots across the state, and the agent told him what further information it would need to identify real voters' ballots. At no point, he says, did the agent refuse or raise concerns.
He says he never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. He fed the agent two public files named in the paper: each county's early-voting list, and the cast-vote record (CVR) file, which holds every ballot and its selections but no voter names. Neither file breaks the secret ballot alone. Combined after deshuffling, they let the agent date each ballot and build buckets of ballots and possible voters. If three Democrats voted at one precinct on the same morning, the three ballots must be theirs, though not which is whose. In small rural counties where only one Democrat voted on a given early-voting day, that person's ballot is identified with certainty.
With just those two files, Springer says the in-person cast order could be recovered in 114 of the 139 Georgia counties he examined: 1.52 million ballots, or 98.9% of in-person ballots in those counties. He separates two tiers. "Uniquely identified" means a forced match, where the voter was the only one of their party, in their precinct, of a certain ballot type, on a given day; from the public files alone that is about 1% of all early in-person voters analyzed. "Tied to a specific ballot" is stronger and needs one more public record: the scanner's public audit log and check-in records for individual voting locations, which give the order and timestamps of check-ins. With those, in Heard County, one of Georgia's smallest, the agent matched the majority of the 650 early in-person voters to a specific ballot and the rest to within a single swap. The same result held at Ball Ground, a busy vote center in Cherokee County, across all 1,860 early voters.
Springer says he could repeat this in any affected county, given even a coarse record of the order in which voters scanned. Such a record can come from CCTV footage or poll watchers, he writes, and most precinct scanners display a public running count of ballots submitted: if you note your own number and your spouse is directly behind you, their secret ballot is gone. Georgia is one of 21 states using affected scanners. He stresses that the secret ballot is what makes coercion pointless, since a vote that cannot be proven cannot be sold or compelled.
On remediation he says: less than you would hope. A corrected software version was developed and certified in March 2023, yet the data he analyzed is from May 2026. Disclosure and even a direct fix have not resolved the issue because election officials have been slow to adopt it. He writes that AI coding tools have changed the stakes, and that officials must patch with far more urgency while researchers must reconsider how they handle responsible disclosure. Concretely, jurisdictions using Dominion scanners should install version 5.17 or newer. He adds that none of the results produced by these machines are in question; the issue is voter privacy, not the accuracy of counts.
Key facts
- Springer says he reconstructed the cast order of about 1.5 million ballots in Georgia's May 2026 primary, 98.9% of in-person ballots, using AI coding agents and public records.
- The method reverses a deterministic ballot-shuffling flaw disclosed in October 2022; a corrected software version was certified in March 2023 but uptake by election officials has been slow.
- In 114 of the 139 counties he examined the in-person cast order was recoverable (1.52 million ballots); about 1% of early in-person voters analyzed were uniquely identified from the two public files alone.
- With check-in and audit-log records added, the agent matched most of Heard County's 650 early voters to a specific ballot and the rest to within a single swap; the result held for all 1,860 early voters at Ball Ground in Cherokee County.
- He recommends that jurisdictions using Dominion scanners install version 5.17 or newer before the next election; he says election results themselves are not in question.
Why it matters
The secret ballot is what makes vote buying and coercion pointless, and Springer says that guarantee is lost in affected counties. His larger argument is about AI. A flaw that was long seen as too technically demanding to bother fixing quickly can now be turned into working code in a couple of hours by someone with no security background, he says, using agents available for $20. In his words, the clock on remediation now runs at an entirely different speed.
Who it affects
Voters in the 21 US states that use the affected scanners, Georgia among them. Within Georgia the exposure is greatest in small counties where few people vote on a given day and where neighbors know each other. Election officials and scanner vendors are the ones who must act, and the author also directs his message at security researchers who publish vulnerabilities.
How to use it
This is a warning rather than a tool. Springer's concrete advice is that jurisdictions using Dominion scanners install version 5.17 or newer of the software, and that affected scanners be corrected before the next election, not after the next headline. He also says researchers should reconsider how they handle responsible disclosure now that AI lowers the technical barrier.
How solid is it
This is a first-person blog post, written by a postdoctoral fellow who holds a PhD in Applied Mathematics from the University of Maryland and who says he is not a security researcher. The underlying flaw comes from a 2022 report by other researchers, and Springer says he built nothing new. The figures (114 of 139 counties, 98.9%, 1.52 million ballots, the Heard County and Ball Ground results) are his own and are given in the post. The source gives no response from Dominion, Georgia election officials or the Secretary of State.
Risks and caveats
Only about 1% of early in-person voters were uniquely identified from the two public files alone; the stronger voter-to-ballot matching needed extra records such as the scanner's public audit log and check-in records, and Springer shows it for two locations while saying it could be repeated elsewhere. The source does not say he identified how any real, named voter voted, only that the agent told him what further information it would need. It does not say the exploit has been used in a real attack or to influence any election, and it does not say how many jurisdictions have not applied the fix. It does not name the AI tool he used. The 1.5 million figure in the intro and the 1.52 million figure for the 114 recoverable counties are both the author's own numbers. Vote counts themselves are not in question, he says; the harm is to privacy.
“Affected scanners should be corrected before the next election, not after the next headline.”
— Max Springer, Princeton Center for Information Technology Policy