The presidential candidate of the African Democratic Congress (ADC), Atiku Abubakar has raised concerns over the use of an “outdated” operating system on the Bimodal Voter Accreditation System (BVAS) ahead of the 2027 general election.
In a statement issued by his media office on Tuesday, Atiku said the mock accreditation failures recorded during the August 1 Osun governorship election exercise, coupled with recent comments by Lawrence Bayode, director of ICT at the Independent National Electoral Commission (INEC), had exposed vulnerabilities in the electoral technology.
Bayode had said on Arise Television on Monday that BVAS, which was first introduced into Nigeria’s elections in 2021, currently runs on Android version 10.
Atiku said what was omitted from Bayode’s disclosure was that Android version 10 had reached its end of life in 2023 and no longer receives updates or security patches.
The former vice-president said using an outdated operating system to run critical election technology could expose the system to cyber and operational risks.
He questioned why INEC, despite its budgetary allocation, had not updated the BVAS software ahead of the 2027 elections or used the forthcoming off-cycle elections, including the Osun governorship poll, to test an updated version.
“Why INEC with its humongous budget cannot update the BVAS software long before the 2027 general elections or even before the series of off-season elections like the Osun State governorship election during which the updated version would have been test run,” Atiku said.
He described the handling of the BVAS issue as suspicious and alleged that it could undermine the integrity of future elections.
Atiku said running BVAS on an outdated operating system could potentially expose the devices to attacks capable of compromising voter accreditation and election result files.
He alleged that criminal elements or hackers could potentially gain access to the device’s file system and alter cached voter logs or polling-unit result files before transmission.
The ADC candidate also raised concerns over the transmission of polling-unit results to the INEC Result Viewing (IReV) portal through public telecommunications networks.
He said outdated cryptographic foundations could increase the risk of man-in-the-middle attacks, potentially allowing sophisticated actors to intercept, block or manipulate data transmitted over the network.
Atiku also expressed concern over the biometric functions of BVAS, which handles fingerprint and facial recognition.
He said an outdated biometric framework could reduce the system’s accuracy and resilience against attempts to circumvent biometric verification.
The former vice-president further warned that software bugs or memory leaks in legacy systems could cause BVAS devices to crash during peak voting periods, resulting in technical glitches and delays in voter accreditation.
He said election technology required regular upgrades and independent scrutiny to ensure public confidence in the electoral process.
Atiku backed calls by cybersecurity experts for an independent and comprehensive audit of BVAS devices ahead of the 2027 elections.
He said the audit should cover both the hardware and software components of the system, including its code and security architecture.
“Running critical national infrastructure on an end-of-life operating system creates a broad attack surface,” he said.
“To safeguard election integrity, it is vital to perform an independent, comprehensive code and hardware audit of the BVAS devices.”


