Presidential candidate of the African Democratic Congress (ADC), Atiku Abubakar, has raised the alarm over the alleged use of outdated software on the Bimodal Voter Accreditation System (BVAS), warning that hackers could exploit vulnerabilities in the system to compromise the 2027 general elections.
Atiku said the continued use of an old operating system on BVAS devices, combined with recent accreditation failures, had raised serious questions about the security and reliability of Nigeria’s election technology.
In a statement issued by his media office on Tuesday, the former vice-president referred to technical problems recorded during the mock accreditation exercise ahead of the August 1 Osun governorship election.
He also cited comments by the Independent National Electoral Commission (INEC) Director of ICT, Lawrence Bayode, who reportedly disclosed during an Arise TV programme on Monday that BVAS devices currently operate on Android 10.
Atiku said Android 10 reached end-of-life status in 2023 and no longer receives regular security updates and patches.
He questioned why INEC had not upgraded the BVAS operating system ahead of the 2027 elections, particularly with several off-cycle elections providing opportunities to test an improved system.
The ADC candidate warned that continuing to run critical election infrastructure on outdated software could leave BVAS devices exposed to cyberattacks.
According to him, hackers could potentially bypass the BVAS application, gain access to the device’s file system and tamper with cached voter accreditation logs or polling-unit result files before they are transmitted.
Atiku also raised concerns about the transmission of polling-unit results to the INEC Result Viewing (IReV) portal through public telecommunications networks.
He warned that outdated security and cryptographic components could make the transmission process vulnerable to cyberattacks, including attempts to intercept, block or manipulate election data.
The former vice-president further expressed concern over the biometric functions of BVAS, which use fingerprints and facial recognition to authenticate voters.
He argued that an outdated biometric framework could affect the reliability of voter verification and potentially expose the system to attempts to circumvent its security features.
Atiku also warned that software bugs, memory leaks and other problems associated with legacy systems could cause BVAS devices to crash during periods of heavy usage.
Such failures, he said, could trigger widespread technical glitches, delays in voter accreditation and confusion at polling units.
Questioning INEC’s preparedness for the 2027 election, Atiku said the commission’s handling of the BVAS issue was troubling, particularly given the importance of election technology to the credibility of the electoral process.
He insisted that BVAS and IReV must undergo regular upgrades, rigorous testing and independent scrutiny before the next general election.
Atiku also backed calls by cybersecurity experts for an independent and comprehensive audit of the BVAS system.
He said the audit should cover both the hardware and software components of the devices, including their source code and security architecture.
“Running critical national infrastructure on an end-of-life operating system creates a broad attack surface,” Atiku said.
“To safeguard election integrity, it is vital to perform an independent, comprehensive code and hardware audit of the BVAS devices.”
With preparations for the 2027 general elections already underway, Atiku’s warning has added fresh pressure on INEC to demonstrate that its electronic voting infrastructure is secure, reliable and capable of withstanding cyber threats.















