Envelopes of cash, and a court that called it what it was
A Philippine mayor won an election, handed out envelopes of cash to prove it, and a supreme court took his job away — but the real lesson is why cash envelopes can never fully be outlawed.
It is the morning of July 21, 1997, and the Supreme Court of the Philippines has just settled something that, on its surface, looks like a clear win for electoral integrity. Florentino Blanco had apparently won the mayoral race in Meycauayan, Bulacan. He had the votes. He had the ceremony. Then the Commission on Elections moved to disqualify him, and the Supreme Court agreed.
The evidence was not circumstantial. There were envelopes. Inside each one: money. On the outside: markings that connected the gift to the candidate. And there were sworn statements — from recipients themselves — admitting they had taken cash in exchange for their vote. In Nolasco v. COMELEC (G.R. Nos. 122250 & 122258), the Court held that this constituted vote-buying under Section 261(a) of the Omnibus Election Code, that the mere act of offering something of value in consideration for a vote is the offense, and that Blanco was out. The vice-mayor succeeded him. Case closed.
Except it wasn't. Not really.
The verdict that changed nothing structural
Here is the uncomfortable truth the ruling papers over: Florentino Blanco got caught because his operation was brazen. Envelopes with markings. Sworn recipients. A paper trail neat enough for a court to follow. That is not how most vote-buying works.
Most vote-buying works in whispers, in driveways, in the back rooms of community organizers. A hundred small transactions, each one deniable. A gift that is also a bribe, a favor that is also a demand, a social relationship that makes refusal feel dangerous. The Philippine Supreme Court could punish one man for one documented scheme. It could not — and no criminal statute can — punish a million small exchanges that leave no envelope to photograph.
The math is brutal. The Omnibus Election Code carries criminal penalties. Those penalties scale linearly. The transactions do not. In a country with tens of millions of voters spread across thousands of municipalities, a legal system that works case by case, defendant by defendant, is bringing a gavel to a flood.
This is not a criticism of the Philippine courts. They did exactly what courts are supposed to do: applied the law to the facts, found liability, imposed a consequence. The problem is architectural. And the architecture is global.
Why vote-buying needs a verification mechanism to work
Before asking how to stop vote-buying, it helps to understand precisely why it works — because the mechanism is not obvious.
If you hand someone fifty pesos and tell them to vote a certain way, you have a problem: you have no way of knowing whether they actually did it. The ballot is secret. You cannot follow them into the booth. You cannot check the tally by name. Your fifty pesos might buy a vote, or it might buy a polite nod and then whatever the person was going to do anyway.
This is the structural genius of the secret ballot, invented in Australia in the 1850s and spread globally over the following decades precisely to break the market for votes. The Australian Electoral Commission documents this directly: because people voted publicly, they were vulnerable to intimidation and coercion, and the secret ballot was the counter-measure. The UK's Ballot Act 1872 enshrined the same logic in statute: mark your ballot in a private compartment, deposit it in a sealed box, and the transaction between buyer and voter becomes an unenforceable bet.
A vote that cannot be proven cannot be sold. That is the sentence worth screenshotting.
The U.S. Court of Appeals for the First Circuit spelled out the same mechanism in Rideout v. Gardner (2016), reviewing New Hampshire's ban on ballot selfies. The state's argument: a photograph of a marked ballot lets a voter prove how they voted, which restores the buyer's ability to verify the purchase. The court traced the history back through anti-bribery reforms and agreed on the mechanism, even while striking down the specific ban on First Amendment grounds. The logic stands regardless of the outcome: any feature that lets a voter prove their specific choice to a third party reopens the market for coercion.
This is why vote-buying is not primarily a law-enforcement problem. It is a design problem.
When the seal is broken — and what follows
The Philippine case is the theoretical argument made concrete. But it is not alone, and the global pattern is striking.
In Georgia — the country, not the state — OSCE/ODIHR observers at the October 2024 parliamentary elections found that vote secrecy was potentially compromised in over 30% of their observations: ballots marked in ways that could be observed, deposited in ways that could be tracked, polling stations laid out in ways that made privacy impossible. Where secrecy fails in practice, the market reopens in practice. The monitors documented instances of intimidation and vote-buying in the same election.
In Albania's 2021 parliamentary elections, ODIHR recorded widespread allegations of vote-buying across multiple parties, with investigations opened and pressure applied to voters. In Kyrgyzstan's 2017 presidential race, the same body found vote-buying and pressure on voters to disclose how they voted — which is the operational step that makes cash-for-votes auditable for the buyer. In North Macedonia's 2025 local elections, monitors flagged voter tracking on and around election day: someone, somewhere, was keeping a list of who voted and matching it against expected returns.
These are not failed states. Albania, Georgia, and North Macedonia are European countries with functioning electoral commissions, printed laws, and criminal codes that prohibit exactly what was happening. The laws existed. The market existed anyway. That is the point.
Bulgaria — an EU member state — had the same problem documented in ODIHR's report on its 2023 parliamentary elections: longstanding vote-buying concerns "present and reported" during the election, with law enforcement itself acknowledging that most cases do not progress past the pre-trial stage.
The prosecution ceiling
Why do prosecutions stall? The ODIHR finding from Bulgaria is instructive: "obtaining evidence of vote-buying remains challenging." This is not a bug in Bulgarian law. It is a feature of the transaction.
Vote-buying is a bilateral private agreement between a buyer who wants a specific outcome and a seller who wants cash. Both parties have an incentive to keep it quiet. The buyer does not want prosecution. The seller does not want to return the money or be labelled an informant. The transaction leaves no document, no digital trail, no envelope with markings — unless, as in Meycauayan, someone is sloppy.
Courts can void a result when the evidence is overwhelming, as in the Philippine case or in the 2015 Tower Hamlets judgment in London, where Election Court Commissioner Richard Mawrey found postal-vote fraud and bribery so extensive it could reasonably be supposed to have affected the result. But those are the outliers — the brazen cases, the ones where someone kept records or left witnesses.
The cases that courts can prosecute are not the cases that define the scale of the problem. They are just the cases that got caught.
And "getting caught" in vote-buying nearly always requires either extraordinary carelessness (the envelope) or extraordinary courage (the witness). Neither scales.
The architectural answer
So what actually removes the market?
The answer is not more investigators, though investigators help at the margins. The answer is not heavier penalties, though penalties deter the most visible operations. The answer is what the Australians understood in 1856 and what the first circuit court articulated in 2016: make the vote unprovable.
Not unverifiable in the sense of lacking a count anyone can check — the opposite of that. Unprovable to the buyer. A voter should be able to verify, themselves, that their ballot was counted correctly. A buyer should be categorically unable to verify that the voter kept the deal.
This sounds paradoxical but it is not. Cryptographic voting research has spent two decades developing exactly this property, called receipt-freeness: a system where the voter gets a verifiable receipt that lets them confirm their vote was counted, but where that receipt cannot be shown to a third party as proof of a specific choice. The commitment is mathematically structured so the voter can check but cannot demonstrate. The market fails because delivery cannot be confirmed.
This is the architectural fix that pure enforcement cannot replicate. It does not require catching anyone. It does not require a prosecutor willing to pursue a case that rarely produces usable evidence. It removes the enforcement mechanism from the buyer's side of the transaction entirely.
What "verified" has to actually mean
It is worth being precise here, because the word "verified" is doing a lot of work in election security discourse and not always the right work.
Georgia's hand count of roughly five million ballots in 2020 is often cited as the gold standard of verification — and in one sense, it is. Five million ballots, 159 counties, 41,881 batches, result confirmed to within a tenth of a percent. That is a genuine check on machine tabulation, and it matters.
But that form of verification addresses a different question than the one vote-buying poses. A hand count can tell you that the machine read the ballots correctly. It cannot tell you whether the vote on the paper reflects what the voter actually wanted — or what the voter was paid to mark.
Colorado's risk-limiting audit framework is similarly valuable: it statistically tests whether the machine output matches the paper record, scaling the sample to the margin. Again, genuinely useful. Again, answering a different question.
The question vote-buying poses is upstream of counting. It is about whether the marked ballot reflects a free choice or a purchased one. No audit, hand count, or risk-limiting procedure can recover a vote that was voluntarily sold. Counting it correctly is not the same as counting it freely.
This is why the architectural defense — unprovability — is not a substitute for good counting procedures. It is prior to them. You need both: a count that can be independently verified against physical records, and a process that makes the individual vote impossible to prove to any buyer.
The two requirements do not conflict. They address separate attack surfaces.
What is still not checkable — and what would fix it
Return to Meycauayan, Bulacan, 1995. Florentino Blanco is out. The vice-mayor is in. The envelopes are in the case file. Justice, formally, was done.
But here is what the court record cannot tell you: how many voters in that race made a free choice, and how many made a purchased one. The recipients who gave sworn statements were the visible fraction of a likely much larger transaction network. The court could count the envelopes it was shown. It could not count the deals it was not shown.
That gap — between the provable and the actual — is what no criminal statute has ever fully closed and what verification technology is beginning to make closeable. Not by surveillance. Not by tracking voters. By design: a system where every cast vote is cryptographically committed, independently tallied, and publicly auditable against an encrypted record that the voter can verify but cannot prove to a buyer.
The question every election system should have to answer is not 'did we catch anyone?' It is 'is there anything in this system's design that a buyer could use to verify delivery?'
If the answer is yes — because a ballot can be photographed, because a marked paper can be smuggled out, because a receipt links to a specific voter's choice — the market is open. If the answer is no, the market collapses under its own unverifiability.
That is the lesson the Philippine Supreme Court taught without quite saying it. Penalties punish the caught. Architecture defeats the uncatchable.
What remains unverifiable in most elections today: whether the individual ballot reflects a free choice, or a coerced one. What would make it checkable: a system that publishes cryptographic proofs anyone can audit, while making individual vote choices unprovable to a third party — receipt-free by design, verifiable by math. See how this gap appears across elections worldwide or read the two-minute version.
Sources
- Supreme Court of the Philippines — Nolasco v. COMELEC, G.R. Nos. 122250 & 122258 (21 Jul 1997), LawPhil
- Australian Electoral Commission — A short history of voting and the secret ballot
- UK primary legislation — Ballot Act 1872 (35 & 36 Vict. c. 33), legislation.gov.uk
- U.S. Court of Appeals for the First Circuit — Rideout v. Gardner, No. 15-2021 (opinion, Sept. 28, 2016)
- OSCE/ODIHR — Georgia, Parliamentary Elections, 26 October 2024: Final Report (20 Dec 2024)
- OSCE/ODIHR, Republic of Albania Parliamentary Elections 25 April 2021 - ODIHR Election Observation Mission Final Report
- OSCE/ODIHR — Kyrgyz Republic, Presidential Election, 15 October 2017: Final Report (8 Mar 2018)
- OSCE/ODIHR — North Macedonia, Local Elections 2025: ODIHR EOM Final Report (7 Apr 2026)
- OSCE/ODIHR — Republic of Bulgaria, Early Parliamentary Elections 2 April 2023, Final Report (Warsaw, 27 July 2023)
- Election Court judgment — Erlam & Ors v Rahman & Anor [2015] EWHC 1215 (QB) (BAILII)
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia
- Colorado Secretary of State — A new kind of election audit: Colorado is first to complete it