top of page

Nigeria's Election Machines May Be Running Decade-Old Software. The Bigger Threat Is That No One Can Check.

Researchers say INEC's own manuals suggest BVAS may run software released a decade ago. INEC has not confirmed the device's operating system.
Researchers say INEC's own manuals suggest BVAS may run software released a decade ago. INEC has not confirmed the device's operating system.

A Nigerian election researcher says INEC's own official documents suggest the Bimodal Voter Accreditation System (BVAS) may still be running Android 6 or Android 7. Those operating systems were released in 2015 and 2016 and stopped receiving Google security patches years ago. The claim is probable but unconfirmed, and that is precisely the problem. Eight days before the Osun governorship election and five months before the 2027 general elections begin, Nigerians cannot independently verify what software protects their votes. In the perception war that defines modern election security, that opacity is a vulnerability all by itself.


What the Researcher Found

Oluwafemi Adebayo, Head of Research and Strategy at the Kimpact Development Initiative, made the disclosure this week during an interview on Arise Television. His team began digging after the August 1 mock accreditation exercise in Osun State, where multiple BVAS devices reportedly stopped recognizing fingerprints, faces, and voter cards less than 40 minutes into the exercise.


INEC Chairman Professor Joash Amupitan attributed the failure to older voter cards, particularly those issued in 2011, and said technicians resolved it within an hour by adjusting the system's similarity score. Adebayo found that explanation insufficient. INEC's own manuals show that officials can identify a voter three ways: by surname, by the last six digits of the Voter Identification Number, or by scanning the QR code on the card. If the card is not essential, why did old cards halt accreditation?


That question led Kimpact to the device's technological foundation. Because INEC publishes no technical specifications, the team analyzed screenshots in the commission's official manuals. The interface, icons, and widgets, Adebayo concluded, point toward Android 6 or Android 7. His finding remains an inference from visual evidence, not a confirmed fact. Nevertheless, it is an inference INEC has neither confirmed nor denied.

"If the inference holds, Nigeria's frontline election device runs software that stopped receiving security patches nearly a decade ago."

Why an Aging Operating System Matters

Android 6 lost Google support in August 2018. Android 7 followed soon after. Android 17 rolled out in June 2026. A device stuck a decade behind faces three concrete risks:


  1. Unpatched vulnerabilities. Devices without security updates accumulate known, documented weaknesses that attackers can study at leisure.

  2. Degraded performance. Modern biometric matching relies on processors and software optimizations that old platforms cannot support. Slow or failed accreditation disenfranchises voters and feeds election-day chaos.

  3. No vendor accountability. When an operating system reaches end of life, no one is contractually responsible for fixing what breaks. The 176,846 polling units planned for 2027 would inherit that risk at national scale.


However, BVAS operates offline on election day, which limits remote attack paths. The realistic threat model is quieter: supply chain tampering, insider manipulation during configuration, and the slow erosion of reliability that turns technical glitches into political crises.


The Real Vulnerability Is Opacity

Here is the strategic point practitioners should not miss. Adversaries targeting the 2027 elections, whether domestic political actors or foreign influence operators, do not need to compromise a single BVAS unit to succeed. They need only convince enough Nigerians that the system cannot be trusted.

"Adversaries do not need to hack BVAS. They only need to weaponize doubt about it."

Every unanswered technical question becomes raw material for that campaign. When a credible researcher must reverse-engineer the electoral commission's software version from screenshots in a training manual, the information vacuum is already doing the adversary's work. In my opinion, INEC's silence on BVAS specifications is now a greater strategic liability than any single flaw in the device itself.


What Must Happen Before 2027

INEC has floated a full audit of its election technology and a nationwide mock presidential election. Those are the right instincts. They should become commitments:


  • Publish the baseline. Disclose the BVAS operating system, patch level, and hardware specifications. Security through obscurity failed decades ago.

  • Commission an independent audit. Nigerian universities, professional bodies, and credible international partners can verify the platform without compromising it. Publish the findings.

  • Upgrade or replace before January 2027. If the fleet runs end-of-life software, a remediation plan with public milestones must start now.

  • Institutionalize transparency. Sovereign electoral capacity means owning, understanding, and defending your own technology stack, not outsourcing trust to vendor assurances.


An Analyst's View

I have tracked Nigeria's election technology since the card reader era, and the pattern repeats: a glitch appears, officials announce it has been resolved, and the underlying architecture remains a black box. The Kimpact finding matters less for what it proves than for what it reveals about the process. A national election system whose software version must be inferred from icon styles invites both attacks and conspiracy theories. The 2027 election will be fought as much over trust as over votes. Transparency is not a courtesy to civil society. It is a national security requirement.


The Bottom Line

The Android 6 or 7 claim remains unconfirmed. The accountability gap it exposes is not. INEC can close that gap with disclosure, independent verification, and a funded upgrade path. The alternative is entering Nigeria's most consequential election with infrastructure no citizen can inspect, and every adversary can exploit, if not technically, then psychologically.


OSRS can help. Our team provides election security assessments, electoral technology risk analysis, and strategic advisory services for government, law enforcement, and institutional leaders preparing for the 2027 cycle. Contact us to schedule a briefing or election infrastructure readiness assessment.


Enjoyed this article? Share it with a colleague who needs to see it. Stay informed by subscribing to our email list and following us on Google News, Twitter, and LinkedIn for more exclusive cybersecurity insights and expert analyses.


Dr. Sunday Oludare Ogunlana, Founder and CEO of OGUN Security Research and Strategic Consulting LLC (OSRS), Professor of Cybersecurity, is a national security scholar specializing in intelligence studies, counterterrorism, and emerging technology threats. He advises government, academic, and private-sector organizations on security strategy. Learn more at www.ogunsecurity.com.


Intelligence. Protection. Strategy.

bottom of page