When the voting-machine company itself says: don't trust these numbers
In 2017, the company that built Venezuela's voting machines told the world the official turnout figure was a lie — by at least one million votes. Nobody could prove otherwise.
It is the evening of July 30, 2017, and Venezuela's National Electoral Council has just announced that 7.5 million people voted in the National Constituent Assembly election. The number lands in newsrooms around the world. Governments issue statements. The opposition calls it fabricated. And then, two days later, something happens that has almost no precedent in the history of elections anywhere on earth.
The company that built the machines — that wrote the software, that managed the servers, that counted every electronic vote — walks up to a microphone and says: we know, without any doubt, that the number is wrong. Not by a rounding error. Not by a few thousand votes. By at least one million.
That company was Smartmatic.
The vendor disowns the count
On 2 August 2017, Smartmatic issued a public statement about the Constituent Assembly election held two days earlier. Its chief executive said the company knew "without any doubt" that the turnout figure announced by Venezuela's National Electoral Council had been manipulated, and estimated the gap between the actual and announced participation at "at least one million" votes.
Read that again slowly.
The people who built the system, who understood its architecture better than anyone alive, said the official number could not be trusted. Not a political opponent. Not a foreign government. Not a researcher working from the outside. The vendor.
Smartmatic had been Venezuela's automated voting technology partner since 2004. It had run elections across the country's complex geography. It knew what the machines recorded. And what the machines recorded, according to Smartmatic, did not match what the government announced.
Following that statement, Smartmatic withdrew from Venezuela's subsequent 2017 regional and municipal elections and ceased all operations in the country in 2018.
The question that statement leaves hanging — permanently, as it turns out — is: what did the machines record? Because without an independent audit, nobody outside the government has ever been able to answer that.
The gap nobody can close
Here is the structural problem. A voting system produces records. Those records are held by whoever runs the system. When that authority announces a result, the only people who can check whether the announcement matches the records are the people holding the records.
In Venezuela in 2017, those people were the government that wanted the 7.5 million figure to stand.
Smartmatic could say — and did say — that something was wrong. But even Smartmatic's statement had a limit. The company could speak to what it knew from its own access and knowledge of the system's architecture. It could not itself publish the underlying machine logs, precinct-by-precinct totals, or a cryptographically verifiable audit trail. Not because it was hiding anything, but because a result that only one party can check is structurally uncheckable by everyone else.
That is the sentence worth screenshotting: A result that only one party can check is structurally uncheckable by everyone else.
This is not a Venezuelan problem. It is not a problem that lives only in authoritarian states. It is the default condition of any election system — however well-intentioned its administrators — that does not publish a tamper-evident, machine-readable, independently verifiable record of every vote at every stage of the count.
Why you should care even if you don't live in Caracas
The Venezuela case is extreme. The scale of the alleged manipulation — if Smartmatic's estimate is right — is not a rounding error; it is a million votes. The political context is not ambiguous.
But the mechanism of the problem is universal, and it shows up in milder forms in elections that nobody disputes.
In Antrim County, Michigan in 2020, wrong results were published on election night — not because of fraud, but because of a configuration error. The numbers were caught only because the result was glaringly implausible for a county whose partisan lean everyone knew. A subtler error — one that nudged a close race without flipping a county's color — might have passed entirely unnoticed. Even the hand audit that followed was off by about a dozen votes, a reminder that no verification method is perfectly clean.
In Sarasota County, Florida in 2006, roughly 18,000 votes simply vanished from a Congressional race decided by 369 votes. The machines were paperless. Federal auditors could not find a malfunction, but they also could not rule one out — because there was nothing independent to check against. The machines' word was all there was.
In both cases — one honest error, one permanent mystery — the failure mode was identical to Venezuela's at a structural level: the only evidence of what happened was held by the same system that produced the result.
What 'the vendor confirmed it' actually means
Here is a version of events that sounds reassuring: the election authority runs the count, the vendor certifies the system, an audit confirms the result, and the Secretary of State announces everything matched.
Now here is the harder version: the election authority announces a result. The vendor certified a system before the election, not the specific count afterward. The audit is run by the same authority that holds the ballots. The Secretary of State's announcement is based on reports from that authority. Every link in that chain of confirmation runs through the same set of hands.
This is not a conspiracy theory. It is just a description of how most election audits actually work. The auditors are often trustworthy, careful, and acting in good faith. But 'trustworthy people confirmed it' is not the same as 'anyone could independently check it,' and those two things are not interchangeable when a result is close or contested.
Germany's Federal Constitutional Court drew exactly this line in 2009, ruling that electronic voting is only legitimate when ordinary citizens — not just specialists — can examine each essential step of the count for themselves. Not because the Court suspected fraud. Because a result that requires expertise to verify, and that expertise lives only with the authority running the count, does not meet the minimum standard of a public, democratic election.
The Kenya Supreme Court annulled a presidential election in 2017 for the same structural reason: not because it could prove the numbers were wrong, but because the digital chain from polling station to national tally could not be independently checked against tamper-evident source records. The principle is not 'someone did something wrong.' It is 'no one outside the room can confirm they didn't.'
The DR Congo test case: when the observers can't get in
In November 2011, the Democratic Republic of Congo held presidential and legislative elections. The European Union Election Observation Mission was on the ground, deployed across the country. Its final report reached a conclusion that should be read alongside Venezuela's: the results were not credible.
What the EU mission found was not ballot-stuffing on camera. It was structural opacity. The electoral commission lacked transparency in how it compiled and published provisional results at the local and national level. Observers were denied access to the relevant court decisions that were supposed to adjudicate disputes. The absence of a functioning Constitutional Court meant there was no independent body to scrutinize the count publicly.
Nobody could check the numbers. Not because someone hid a smoking gun — but because the architecture of the process didn't include a window that outsiders could look through.
That is the DRC in 2011. That is Venezuela in 2017. And that, in a less dramatic register, is every election system that publishes a final total without publishing the precinct-level, machine-readable, tamper-evident records that would let any interested person reconcile the total themselves.
Announcing a winner is not proving the count. Those are different things.
Why the vendor's word was never meant to be enough
Smartmatic's 2017 statement was extraordinary precisely because vendors almost never say this. The incentive structure runs entirely the other way: a vendor whose system is associated with a disputed result loses contracts. Speaking out was, commercially, an act of self-destruction.
But even if every vendor in every election were equally willing to tell uncomfortable truths, vendor testimony is not independent verification. A vendor knows its own system. It does not know what an election authority did with the output after the system handed it over. It cannot audit the transmission, the aggregation, the final compilation. In Venezuela, Smartmatic could say the announced number was wrong. It could not produce the verified number.
That gap — between 'something is wrong' and 'here is what's right, and here's the evidence' — is what independent, cryptographically verifiable audit architecture is designed to close. Not by trusting the vendor. Not by trusting the authority. By publishing records that are tamper-evident by construction, so that any party — a journalist, an opposition candidate, a foreign observer, a member of the public — can run the numbers themselves and arrive at the same answer.
Colorado ran the first statewide risk-limiting audit in U.S. history in 2017. The process generated statistical evidence — tied to physical paper ballots — that any statistician could replicate. Georgia hand-counted roughly five million presidential ballots in 2020. The paper existed; the count was public; the methodology was checkable. These are better than nothing. They are not the ceiling.
The ceiling is a system that publishes a cryptographic commitment to every cast ballot at the moment it is cast — so that the final total can be verified not by counting again, but by proving, mathematically, that nothing was added, removed, or changed between the voter and the result. That kind of verifiability does not require trusting any official, any vendor, or any audit team. It requires only that the math is correct.
What is still not verifiable — and what would change it
Here is what nobody outside the Venezuelan government has been able to independently confirm since July 30, 2017: the actual turnout in the National Constituent Assembly election.
Smartmatic said the official figure was off by at least a million votes. The government said it wasn't. There is no independent audit trail. There is no cryptographic commitment published before the count began. There is no precinct-level, machine-readable result file that a third party could download and reconcile against the announced total.
The case is closed — not because the question was answered, but because no mechanism exists to answer it.
That is not a problem unique to Venezuela. It is the problem that lives inside any election system that confuses announcing a result with proving one. The fix is not better officials. The fix is not a more honest vendor. The fix is a system designed so that what the machines recorded, what the tally aggregated, and what the authority announced can all be checked against each other by anyone — before, during, and after the count — using evidence that no single party controls.
A vendor should never again have to be the one to say: trust me, the number is wrong. The architecture should make that checkable by everyone.
See how common the gap between announced results and independently verifiable ones is across the world: explore the atlas. Or read the two-minute version of why verifiability beats trust: the short version. For a global map of cases where results could not be independently confirmed, see the gaps database.
Sources
- Smartmatic, 'Statement on the recent Constituent Assembly Election in Venezuela' (2 August 2017)
- European Union Election Observation Mission, Democratic Republic of Congo 2011 — Final Report
- Michigan Department of State — Final numbers from Antrim County audit
- U.S. GAO (GAO-08-97T) — Testing of Voting Systems in Florida's 13th Congressional District
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Supreme Court of Kenya, Presidential Election Petition No. 1 of 2017, [2017] KESC 42 (KLR)
- Colorado Secretary of State — A new kind of election audit: Colorado is first to complete it
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia