← All posts

The election that got thrown out: what happens when nobody can trace a ballot

Austria cancelled a presidential election — not because anyone cheated, but because nobody could prove they hadn't. That distinction is the whole argument.

It is the morning of July 1, 2016, and the Austrian Constitutional Court has just done something that had never happened in the country's postwar history: annulled a presidential election.

Not because it found fraud. Not because votes were stolen or tallied incorrectly. Because roughly 77,000 postal ballots had been handled by the wrong people, opened at the wrong time, counted before the legally required officials and witnesses were present — and the winning margin was only about 30,000 votes.

The math was simple and devastating. The number of ballots processed outside the rules exceeded the margin of victory. The Court could not rule out manipulation. And because it could not rule it out — because the chain of custody was broken in ways that made verification impossible — the result had to go.

A fresh election was scheduled for December 4, 2016. The original May vote, in which Alexander Van der Bellen had narrowly defeated Norbert Hofer, was simply erased from the record.

No fraud was found. The ballots were still there. The votes were, in all likelihood, exactly what voters intended. But "in all likelihood" is not good enough for a democratic election. The Court's standard was not 'did manipulation happen?' It was 'can we prove it couldn't have?' When the answer is no, the result cannot stand.

That distinction — between catching fraud and designing a system that makes fraud independently disprovable — is the most important thing this post is going to say. Hold onto it.


When the chain of custody breaks, 'probably fine' isn't enough

The Austrian case (VfGH W I 6/2016-125) is striking precisely because it had nothing to do with a close call on a voting machine, a software glitch, or a partisan operatives scheme. It was a procedural failure. Ballots moved through hands that weren't authorized to touch them. Envelopes were opened before the clock said they could be. The sequence of custody — the chain of who held the ballots, when, under what witnesses — was interrupted.

Electoral rules about handling aren't bureaucratic fussiness. They are the mechanism by which an election result becomes independently checkable. When the rules are followed correctly, an auditor can reconstruct the ballot's journey from voter to sealed box to final count and confirm at every step that no unauthorized hand intervened. When the rules are skipped, that reconstruction becomes impossible. You are left with officials saying "it was fine" — which is a claim, not a proof.

The Austrian court's logic is worth sitting with. It did not require evidence of actual manipulation; it required the absence of procedural violations large enough to have enabled manipulation. That is a harder standard — and the right one.


North Carolina 2018: when the chain breaks on purpose

Austria involved accidental procedural failures. Now consider what happens when someone deliberately exploits the weakest link in the ballot's journey.

In North Carolina's 9th Congressional District in 2018, that link was the absentee ballot. The State Board of Elections declined to certify the apparent result and launched an investigation. What it found, and what it unanimously declared on February 21, 2019, was a "coordinated, unlawful and substantially resourced absentee ballot scheme" operating in Bladen and Robeson counties.

The operative at the center, McCrae Dowless, was later indicted on felony charges. The method: workers allegedly collected absentee ballots from voters — ballots that were supposed to travel directly from the voter to the election office — intercepted them, and either altered, completed, or simply discarded them. A new election was ordered and held in 2019. A different candidate won.

This was one of the rarest events in American electoral history: a U.S. House election voided because of ballot fraud. And the fraud was almost embarrassingly simple. It didn't require hacking a server or bribing an official. It required exploiting the part of the absentee process where the ballot is, by design, outside official custody — in the mail, or in a voter's home, or in the hands of whoever knocked on the door.

Mail ballots travel. That is their whole point. But travel is exactly where a chain of custody is hardest to maintain and easiest to break.

The lesson here is not "ban absentee voting." Millions of people rely on it. Elderly voters, disabled voters, voters overseas — they have no practical alternative. The lesson is: every segment of a ballot's journey needs to be tamper-evident and independently verifiable, including — especially — the segment between the voter's kitchen table and the election office door.


What 'tamper-evident' actually means for a ballot

Think of it physically. A ballot starts as a blank piece of paper in a controlled print facility. It travels to a voter, either by mail or across a counter. The voter marks it, seals it, signs the envelope. It travels back. Someone at the election office verifies the signature, opens the outer envelope, removes the inner envelope, opens that, and extracts the ballot for counting.

Each of those steps is an opportunity for something to go wrong — or to be made to go wrong. Signature verification can be waived or faked. Outer envelopes can be resealed. Inner envelopes can be substituted. Ballots themselves can be intercepted before they reach the return envelope.

A tamper-evident system is one where any interference at any of those steps leaves a mark that an independent observer can detect. A sealed evidence bag that has been opened looks different. A signature log that has been altered shows the change. A batch of ballots whose serial numbers don't match the issued inventory sets off a discrepancy.

None of this requires exotic technology. Some of it is simply good physical security — the kind that has governed evidence handling in criminal investigations for decades. What it does require is that the procedures are designed with traceability in mind, followed consistently, and checked by someone who is not part of the chain being checked.

That last part is the one most often missing.


England 2015: when postal voting becomes an attack surface

North Carolina in 2018 was not an isolated case. In April 2015, an English Election Court presided over by Commissioner Richard Mawrey QC voided the May 2014 election of Lutfur Rahman as executive Mayor of the London Borough of Tower Hamlets, under the Representation of the People Act 1983.

The judgment in Erlam & Ors v Rahman & Anor [2015] EWHC 1215 (QB) found the election tainted by corrupt and illegal practices including personation, postal-vote fraud, bribery, and what the court described as general corruption so extensively prevailing that it could reasonably be supposed to have affected the election. Rahman was removed from office.

The postal-vote fraud finding is particularly relevant here. Postal and remote voting move the ballot outside the one environment — the polling station — that is specifically designed with physical security controls: official staff, screened booths, sealed boxes, witnessed procedures. Once a ballot is in the wild, the voter can be watched, pressured, or helped in ways that no rule prevents unless enforcement is active and evidence survives.

The Austrian case showed that accidental chain-of-custody failures are enough to void a result. Tower Hamlets and North Carolina showed what deliberate exploitation of the same gaps looks like. In both cases, the mechanism was the same: a segment of the ballot's journey that was not tamper-evident, not independently auditable, and therefore attackable.


The deeper problem: 'an audit confirmed it' is not the same as verifiable

After North Carolina voided its result, many observers noted that the fraud was caught — isn't that the system working? In a narrow sense, yes. The State Board investigated, found the scheme, and ordered a new election. Democracy repaired itself.

But look at what it took: whistleblowers, a prolonged investigation, a Board willing to withhold certification under enormous political pressure, and ultimately the will to void the entire race and start over. That is a very high-friction, fragile mechanism for catching fraud. It worked once. It might not work in a jurisdiction with less scrutiny, a closer race, or officials less willing to act.

Compare that to what a tamper-evident, cryptographically traceable ballot system would provide: an auditor — any auditor, not just an official one — could check that every ballot issued has a corresponding return, that no ballot in the count lacks a valid chain of custody, and that the sequence of handling matches the documented log. Not because they trust the officials who ran the process, but because the process generates independently checkable evidence.

The Austrian Constitutional Court was essentially demanding this standard in 2016, in the language of constitutional law. Its ruling said: the result must be checkable by a standard higher than 'the officials say it was fine.' The postal-ballot rules exist precisely to generate that checkable record, and when they're broken, the record disappears.

This is the same principle that runs through other verifiability failures — the Windham, New Hampshire case, where an optical scanner silently miscounted hundreds of validly-marked ballots because fold lines happened to cross the vote targets, and the error was only recoverable because durable paper ballots existed for a hand audit. Or Georgia's 2020 statewide hand count, which confirmed the machine tally to within about a tenth of a percent — reassuring, but also a reminder that the reassurance derived its force from the physical paper, not from trust in the officials who ran the machines.

In each case, the verification was downstream and reactive. Someone had to notice something was wrong, or mandate a check after the fact. The architecture of a trustworthy election makes verification proactive, automatic, and independent of whoever ran the process.


What the chain of custody should look like — and what's still missing

The Austrian and North Carolina cases together describe a blueprint for what needs to exist, stated in the negative: here is what breaks when it isn't there.

Issued-ballot accountability. Every ballot issued by an election authority should have a unique, logged identifier. When ballots are returned, the returned set should reconcile against the issued set. Discrepancies — extra ballots, missing ballots, batch totals that don't add up — should be flagged automatically, not caught only if an investigator goes looking.

Continuous custody documentation. Every transfer of ballots between parties — voter to mail, mail to election office, election office to processing, processing to tabulator — should be documented in a way that an independent observer can verify. Signatures, timestamps, witness attestations, sealed packaging. Not as a formality, but as evidence that survives investigation.

Independent verification at each step. The person verifying that step N was performed correctly should not be the same person who performed it. This sounds obvious; in practice, understaffed election offices often collapse these roles under time pressure.

Machine-readable, publicly auditable logs. The documentation should be structured data, not narrative reports. An investigator — or a voter, or a journalist — should be able to download a file and check the arithmetic themselves, without needing to file a records request and wait.

None of this requires abandoning mail voting. The Austrian system had postal ballots and had detailed procedural rules for handling them. The rules were sufficient; the compliance was not. The fix is compliance that is verifiable, not compliance that is asserted.

Here is what is still not checkable in most jurisdictions: the segment between the voter and the return envelope. A voter who is pressured to hand their unsealed ballot to a third party — exactly what allegedly happened in Bladen County — leaves no trace in the official record if the procedural rules governing that segment are not enforced at the point of collection. That gap is structural, and it is the same gap in Austria, North Carolina, and Tower Hamlets alike.

No election authority has fully closed it. Most have not seriously tried.


The takeaway you should screenshot

An election that cannot be independently verified is not more trustworthy because officials say it went fine. The Austrian Constitutional Court voided a presidential election — with no fraud found — because broken procedures made verification impossible. North Carolina voided a congressional race because a broken chain of custody made fraud possible. The fix is the same in both cases: a system where every ballot's journey generates independently checkable evidence, not one where 'we followed the rules' is something only the rule-followers can confirm.

The question to ask about any absentee or mail voting system is not "do we trust the election officials?" It is "can an independent observer reconstruct the chain of custody for every ballot, without taking anyone's word for it?" Until the answer is yes, the North Carolina and Austria lessons remain open.

See how widespread these chain-of-custody gaps are globally — or read the two-minute version of ballot traceability.


Sources