← All posts

Correction fluid decided an election — until the courts noticed

A small bottle of white correction fluid altered enough tally sheets to void an entire presidential election — and the courts said no amount of official reassurance could fix that.

It is the morning of February 3, 2020, and five judges in Blantyre, Malawi have just done something that has rattled every election authority on the continent: they have thrown out a sitting president's election victory.

Not because ballots were stolen. Not because votes were hacked. Because someone had a bottle of Tipp-Ex.

That single detail — correction fluid, the kind students use to fix homework — turned out to be enough to make an entire presidential result legally unverifiable. The Constitutional Court of Malawi nullified the May 2019 election of President Peter Mutharika after finding that official result sheets had been altered with correction fluid, that duplicate tally forms existed, and that stacks of forms were unsigned or improperly handled. The Supreme Court of Appeal upheld that ruling on May 8, 2020, in Mutharika & Electoral Commission v Chilima & Chakwera (MSCA Constitutional Appeal No. 1 of 2020). A fresh election was ordered.

The Electoral Commission had declared Mutharika the narrow winner. The courts' answer was precise: a narrow winner on documents that can be quietly overwritten is not a winner the law can verify.


The document is the election

Here is the thing most people do not think about on election night, when the graphics are spinning and the anchors are talking margins: every number you see originated as a mark on a physical sheet of paper somewhere, filled in by a human being in a polling station, at 10 p.m., with whatever pen was at hand.

That sheet is the election. Not the television graphic. Not the database at the national tallying centre. Not the press release from the Electoral Commission.

If that sheet can be altered — with a pen, with a correcting fluid, by simply replacing it with a duplicate — then everything downstream of it is built on sand. The database is wrong. The graphic is wrong. The press release is wrong. And crucially, no amount of auditing the database will surface the problem, because the database reflects the altered sheet.

This is not an abstract risk. In Malawi, the courts found it happening at scale: widespread use of correction fluid across official tally forms, duplicates in circulation, unsigned documents entering the count. The result was a presidential election that could not be reconstructed from its own source documents.

The lesson is not that Malawi is uniquely corrupt. The lesson is that a tally sheet with no tamper-evidence is an attack surface, anywhere in the world, and that the fragility is invisible until someone challenges the result in court.


What 'tamper-evident' actually means

You have probably handled a tamper-evident seal without thinking about it. The plastic strip on a medicine bottle. The wax on a legal document. The numbered zip-tie on a ballot bag after polling closes.

These are not just ceremony. They serve a specific verification function: if the seal is broken or the document is altered, the evidence of tampering is itself visible. You do not have to trust that no one touched the bottle; you can see that the ring is intact.

An official tally sheet that can be overwritten with correction fluid has none of this. The alteration leaves no obvious trace. The "corrected" figure looks exactly as authoritative as the original. A form signed only after the correction cannot attest to what the original figure was.

The stronger version of tamper-evidence for a paper document is multi-signature: if the form is signed by agents representing multiple parties, in ink, before anyone leaves the polling station, then any subsequent alteration requires either forging all those signatures or getting all those agents to agree to the change. Either path is far harder than a bottle of Tipp-Ex.

Go further: the form could be immediately photographed by each party's agent on their own phone and uploaded. Now the "original" exists in multiple independent copies the moment it is created. A later alteration to the physical sheet can be caught by comparing it to any of those copies.

Further still: a system could require that results forms are digitally signed with a key that each agent holds independently, and that the signed data is transmitted to a public repository the moment the polling station closes. Now the result is cryptographically locked to the moment of counting. No correction fluid can touch it.

None of these are exotic. All of them exist. Most of the world does not use them.


Kenya, 2017: the same problem, one level up

Malawi's vulnerability was at the level of the physical form — the paper that a polling station fills in. But the same principle operates at every level of the chain.

In Kenya in 2017, the Supreme Court voided a presidential election not because the polling-station forms were obviously altered but because the transmission and handling of those forms at the national level could not be verified. Under Article 86 of Kenya's constitution, voting must be "accurate, verifiable, secure, accountable and transparent." The Court found that not all polling-station result forms had been electronically and simultaneously transmitted as required by law, that forms lacked consistent security features, and that the final national tally form bore no watermark or serial number. The chairperson had declared the result before all underlying forms were in hand.

See the Supreme Court of Kenya's judgment in full.

The deeper point — identical in both cases — is this: an election result is a chain of custody, not a number. Every link in that chain, from the moment a voter marks a ballot to the moment a winner is declared, must be independently verifiable. Break one link and the chain as a whole cannot be trusted, even if every other link is perfect.

Malawi's chain broke at the most basic link: the source document. Kenya's broke in transmission and aggregation. The vulnerability is different; the failure mode is the same.


What 'the audit confirmed it' actually means

When an election authority says an audit confirmed the result, that statement is only as strong as what was audited against.

If the auditors checked machine totals against the tally sheets, and the tally sheets had been altered before the audit, the audit confirms the altered result. It catches nothing.

This is the irreducible limitation of any audit that works backward from a single chain of documents. An audit can only detect alterations that left a detectable trace — in the specific documents the auditors are looking at, using the specific methods they apply. If the source document is the point of attack, auditing the derivative records tells you nothing about the source.

Georgia's 2020 hand count — roughly five million ballots, county by county, over less than six days — is the strongest version of a paper audit. It checked machine tabulations against the physical ballots themselves, not against tally sheets. The variation was about a tenth of one percent. That is an extraordinary result, and it means something precise: the ballots the machines counted were, with high confidence, the ballots voters marked.

But that confidence depends entirely on the integrity of the physical ballot chain. If the ballots themselves had been altered or substituted before the recount, the hand count would have confirmed the fraud, not caught it. Georgia's hand count worked because the ballot chain was intact. In Malawi, the tally-sheet chain was not.

The gap between "audit confirmed the result" and "the result is verifiably correct" is exactly the size of every unexamined assumption in the audit's chain of custody.


The alterable tally sheet is a gap with a name

At TrustVoting, we track a specific class of vulnerability called the alterable tally sheet — the gap that opens when a result's source document can be overwritten, duplicated, or replaced without the alteration being detectable by an independent party.

Malawi is the sharpest court-documented example, but the underlying condition — tally sheets that carry no cryptographic signature, no multi-party attestation, no immutable timestamp, and no independently held copy — is common across dozens of electoral systems. The Malawi case is notable not because it was unusual but because the courts had enough evidence to act on it.

The question is how many elections have the same vulnerability and no one with standing to challenge it, or no court willing to act, or no evidence that survived the count.

See how common this gap is across the world →


The structural answer: verifiability no official can override

Here is the argument made clean.

The problem in Malawi was not that election officials were untrustworthy. The problem is that the system required you to trust them. The tally sheet had no property that let anyone else — a losing party's agent, a journalist, a citizen — independently verify that the number on the sheet was the number recorded at the moment of counting.

When a system requires trust, it is vulnerable to whoever controls the trusted element. Tipp-Ex is cheap. So is a duplicate form. So is a sympathetic electoral commissioner who decides which version of a contested sheet enters the count.

The structural answer is to design systems where trust is not required, because independent verification is possible.

What does that look like in practice?

It means that results forms are signed by agents of all contesting parties, in the polling station, before anyone leaves — and that those signatures are on the record used to compile the national result. This is not a new idea; it is a standard practice in well-run elections, and its absence in Malawi was part of what the courts noticed.

It means that signed forms are photographed and the images uploaded immediately, so that any subsequent alteration to the physical document is detectable by comparison.

It means that the uploaded data is cryptographically signed with a key held by an independent party — not the electoral commission — so that the "official" record cannot be quietly changed between upload and publication.

It means that the published result, at the precinct level, is immediately downloadable in machine-readable form by anyone, so that the sum of precinct results is independently computable without asking anyone's permission.

None of these properties require trusting the electoral commission to have counted honestly. That is precisely the point. Verifiability means anyone can check the arithmetic. It does not mean anyone has to take the arithmetic on faith.


What is still not checkable — and what would change that

Here is what the Malawi courts could verify: that correction fluid had been applied to official forms, that duplicates existed, that signatures were missing. Here is what they could not verify: what the original, unaltered figures actually were.

That information is gone. The election cannot be reconstructed from the source documents that should have been its foundation, because the source documents were overwritten. The courts' only remedy was to void the result and hold a new vote.

A system with independently held, cryptographically locked copies of each polling-station result, created the moment of counting and held by parties outside the electoral commission's control, would allow a court — or a journalist, or a losing candidate's legal team — to compare the "official" figure with the original signed record and see exactly where the alteration occurred and by how much.

That comparison is currently impossible in most of the world's elections. The source documents are held by the same authority that compiled the result from them. The audit checks the authority's records against the authority's records.

What would make it checkable by anyone: signed, independently held, publicly accessible precinct-level results, published the moment each polling station closes, in a form no authority can quietly alter after the fact.

That is not a utopian wish. It is an engineering specification. Some of the components already exist. What is missing, in Malawi and in most of the world, is the institutional and legal framework that requires it — and the independent technology to deliver it.

A court with enough evidence can void a result. A system with genuine verifiability would never need to.

Read the 2-minute version of this gap →

See the full gap index →


Sources