← All posts

232 votes vanished into a computer, and a court ordered a whole new election

A court ordered a whole new election — not because anyone proved fraud, but because 232 voters pressed "confirm" and their votes simply never arrived.

It is the morning of April 9, 2009, and a judge in Helsinki has just done something Finland had never done before: ordered three municipalities to hold their elections again, from scratch.

No ballots were burned. No stuffed boxes. No conspiracy. Just 232 people who walked into a polling station, made their choice on a touchscreen, and left believing they had voted — when in fact the machine had discarded what they did.

Their votes were gone, and they never knew it.

The Finnish Supreme Administrative Court, in decision KHO:2009:39, was unambiguous: the electronic voting pilot run in Karkkila, Kauniainen, and Vihti during the 2008 municipal elections was fatally defective. Voters who chose to use the electronic option had to wait for a final confirmation step after making their selection. Many didn't. The instructions were faulty. The machine's design was confusing. So some removed their smartcard before the vote was saved — and the ballot vanished silently into nothing.

The system gave them no receipt. No "your vote was recorded." No way to know whether the machine had kept what they gave it.

That silence is what this post is about.


The machine took your vote and said nothing

Think about what "voting" actually means at the mechanical level. You make a choice. You record that choice in a durable form. Someone — or something — counts the durable record. The count becomes the result.

Every one of those steps has to work. Break any link in that chain, and the count is no longer a count of what voters decided. It is a count of what the machine happened to preserve.

In Finland's pilot, the break happened between step one and step two. Voters made their choice. But 232 of them left before the machine confirmed it had been saved — because nothing in the design told them they needed to wait, and nothing told them afterward that it had failed.

Two hundred and thirty-two votes, gone. Silently. Against the voters' will.

The court found this was not a minor administrative glitch. It was a structural defect in the voting method itself. It annulled the elections. Finland did not run the electronic pilot again.

That decision should be read slowly. The court did not need evidence of fraud. It did not need to prove the missing votes would have changed the outcome. The standard it applied was simpler and harder: a voting method is only legitimate if each cast vote is verifiably recorded. If voters cannot confirm their ballot was captured, the method fails — full stop.


"Confirmation" is not a UX problem. It is a constitutional one.

The easy framing is that Finland had a software bug. Fix the instructions, add a clearer confirmation screen, run a better pilot next time. Problem solved.

But that framing misses what the court actually said.

The question was not whether the interface could be improved. The question was: what does a voter get to verify, and when? In the Finnish system, the answer was: nothing, and never. The voter pressed a button and trusted the machine. There was no independent, durable artifact — no paper, no cryptographic receipt, no precinct-level record — that the voter could inspect to confirm the machine had done what they asked.

That is not a fixable UX problem. That is a category error in how the system was designed.

Compare it to the standard the German Federal Constitutional Court articulated in the same year — March 3, 2009, just weeks before the Finnish ruling — when it struck down the use of Nedap electronic voting machines in the 2005 Bundestag elections. The German court held that the essential steps of voting and counting "can be examined by the citizen reliably and without any specialist knowledge." Not examined by auditors. Not examined by the vendor. By ordinary citizens. Because anything less makes democratic legitimacy contingent on trusting the right experts — which is not democracy, it is delegation.

Finland's 232 missing votes are exactly what the German court was describing in the abstract. When the recording step is invisible and unconfirmable, the voter has no recourse. They cannot know whether their vote was one of the 232 that vanished. Neither can anyone else, until someone runs the totals and discovers that 232 people are recorded as having started the process but not finished it.

Notice: the error was only caught because the system logged incomplete sessions. What if it hadn't? What if the machine had simply not counted without leaving any trace? How would anyone have known?


The number that should make you uncomfortable

Two hundred and thirty-two votes. In three small municipalities. That sounds manageable.

Now run the math in a different direction.

The Finnish pilot involved a modest number of voters in a local election. The 232 lost ballots represented roughly 2% of the electronic votes cast. Two percent is not a rounding error. In a close race — and many races are decided by less than 2% — silent dropout at that rate flips results.

More important: this was the failure rate of a system that was caught. The only reason we know about those 232 votes is that the system kept enough metadata to reconstruct what happened. The court had something to examine.

Now consider the cases where there is nothing to examine.

In Sarasota County, Florida in 2006, roughly 18,000 votes went unrecorded in a single congressional race decided by 369 votes. The machines were paperless touchscreens — no independent record, no trail. The GAO tested the systems and could not identify a malfunction, partly because there was nothing independent to test against. The undervotes might have been voter choice. They might have been machine failure. Nobody could tell.

Finland's error was caught. Sarasota's never was. The difference was not the quality of the officials. It was what the system left behind.


What "voter-verifiable" actually has to mean

Here is where it gets precise — and where most election discussions go wrong.

"Voter-verifiable" has become a phrase that officials and vendors attach to almost anything with a paper component. But not all paper is the same.

A ballot-marking device that prints your choices and then encodes them in a QR code gives you a piece of paper. But in 2020, a federal court reviewing Georgia's system found that the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter." The machine tabulates from the barcode. The voter reads the human text. If those two things disagree, the voter has no way to know. A hand recount of the paper audits the barcode's output, not the voter's intent.

That is a paper trail. It is not voter verification.

Genuine voter verification means the artifact that is counted is the same artifact the voter can independently inspect and confirm. A hand-marked paper ballot satisfies this. A human-readable printout that is tabulated from a human-readable record satisfies this. A QR code the voter cannot read does not. A touchscreen with no paper at all — like Sarasota's — does not.

The Dutch government's 2007 Korthals Altes Commission put it plainly in its report "Stemmen met vertrouwen" (Voting with confidence): "There are no secrets in the election process." Any electronic method is acceptable only if it produces a paper vote the voter can check. The Netherlands dropped its voting machines entirely and returned to hand-marked paper ballots. Not because of fraud. Because the standard of checkability had not been met.

The Finns reached the same destination two years later, by a different route. Their touchscreens produced no checkable record at all. The commission's theoretical standard became a real court's concrete ruling: hold the elections again.


The problem that doesn't announce itself

Here is the genuinely unsettling part of the Finnish case: the system failed silently.

No alarm went off. No error message appeared. No poll worker noticed. The 232 voters walked out of the polling station having done everything they believed was required. The failure was invisible to the people it harmed, invisible to the officials running the election, and invisible to everyone else until someone examined the logs after the fact.

Silent failure is the worst kind of failure in a voting system, because by the time you find it, the election is over and the damage is done.

Compare this to a scenario where a stack of paper ballots blows out of a polling station in a gust of wind. Obvious. Recoverable. Witnesses. A chain of custody that can be reconstructed or, in the worst case, documented as broken. A court can examine the physical record. Observers can count what remains.

Electronic silent failure leaves none of that. It leaves a number that looks complete, produced by a process that looks like it worked, in a system that gives no external signal that anything went wrong.

This is why the case for voter-verifiable confirmation is not a design preference. It is a minimum requirement for knowing whether an election happened at all.

When independent researchers examined Estonia's national internet-voting system during the 2013 municipal elections, they found that a well-resourced attacker or a dishonest insider could plausibly compromise votes or voter privacy without detection. The published paper recommended Estonia discontinue the system. Estonia's authorities disputed the conclusions — but the critical word in that exchange is without detection. A silent attack on a live national election. No alarm. No error log. No 232 voters identified after the fact.

The researchers were able to raise the concern precisely because at least some of the system's code and procedures were available for independent examination. Inspectability is what made the concern statable. Without it, the question "did this work correctly?" has only one available answer: trust us.


'The audit confirmed it' is a claim, not a proof

There is a version of this story that ends comfortably. Officials discover the problem. The court acts. New elections are held. The system is improved. Check.

But that version asks you to treat the detection and response as the lesson, when the harder lesson is what was not detectable.

In Antrim County, Michigan in 2020, wrong results were published and caught — but they were caught because they were implausibly wrong for a county whose politics everyone knew. A subtler error, one that shifted a close race by a few hundred votes without making the county look like it had flipped parties, might have passed unnoticed. And the subsequent hand recount — the "gold standard" check — still differed from the machine tabulation by about a dozen votes out of roughly 15,700 cast. A difference of twelve votes, produced by the most trusted manual method available.

In a race decided by a dozen votes, a method that is itself off by a dozen votes cannot settle the question. "The audit confirmed it" and "the Secretary of State says it's fine" are reassurances. They are not proof. Proof requires that the underlying process be independently verifiable by anyone — not just the officials whose job it is to tell you everything is fine.

The Finnish court understood this. It did not wait for proof of fraud. It did not accept official reassurances that the system had generally worked. It asked: can a voter independently confirm their ballot was captured? The answer was no. That was enough.

Georgia in 2020 ran a full hand count of roughly five million ballots — the largest such exercise in U.S. history — and the variation between the machine count and the hand count was about a tenth of one percent. That is evidence that paper plus an audit lets anyone check a close result. It is the model: a durable, human-readable record, counted independently, by observers who can see every ballot. It works because the artifact being counted is the same artifact anyone can inspect.

The question after Finland, after Sarasota, after Antrim County, is always the same: what does the system leave behind, and who can check it?


What would actually make this checkable

The Finnish case is clean in one respect: once the court ordered new elections, the error was corrected. The 232 voters had a remedy.

But a remedy after the fact is not the same as a system that cannot fail silently in the first place. Here is what "cannot fail silently" requires:

First: the voter must be able to verify, before leaving the polling place, that their ballot was recorded. Not a screen that says "thank you for voting." A confirmation that ties to an independently checkable artifact — a physical paper the voter can inspect, a cryptographic commitment the voter can verify later against a published record, or both.

Second: the artifact being counted must be the same artifact the voter confirmed. A QR code the voter cannot read fails this test. A hand-marked paper ballot the voter marked themselves passes it.

Third: independent auditors — not officials, not vendors, not party representatives, but genuinely independent outside parties — must be able to check the complete chain from voter confirmation to final tally. Not spot-check. Not trust a certification. Actually check, with access to the raw records, at any time.

Fourth: the results must be published at the granular level — precinct by precinct, in machine-readable form — the moment each precinct's count is complete. Not after the canvass. Not bundled into state totals. Precinct-level results that anyone can download, sum, and cross-check against official totals are the minimum unit of public verifiability.

None of this is theoretical. Colorado's statewide risk-limiting audits provide statistical confidence that is tied to how close the race actually is — more checking in tighter races, less in landslides, all grounded in a paper record. The framework exists. The missing piece, almost everywhere, is the political will to apply it universally and the infrastructure to publish results fast enough for audits to happen before the news cycle moves on.


The shareable takeaway

A vote is only trustworthy if it is verifiably recorded — verified by the voter, confirmed in a durable artifact, and checkable by anyone against a public record.

Finland's court did not need to prove fraud. It proved something more fundamental: an election where voters cannot confirm their ballots were captured is not a verifiable election. It is a count of whatever the machine happened to preserve.

232 votes. Three municipalities. One ruling. But the principle it established applies to every jurisdiction running any system — electronic or paper — where the voter has no independent way to confirm their choice made it through.

The question you should be asking about your own election system is not "has fraud been proven?" It is: "what would I have to show me, right now, that my vote was recorded as I cast it?"

If the answer is "nothing" — or "trust us" — that is the gap that needs closing.

See how common this gap is across the world | Read the 2-minute version | Explore specific verification failures


Sources