Vote-buying is really a verification problem in disguise
Vote-buying isn't a crime problem — it's a market problem. And every market needs proof of delivery. Kill the proof, and you kill the trade.
It is the morning of April 26, 2021, and somewhere in Albania, a transaction is being completed that has nothing to do with a ballot box.
Money or a favor changes hands. The understanding is clear: vote as you're told, and come back with proof. The proof could be a photograph. A signature. A witnessed act. A party operative standing close enough to see.
Across the country that day, the OSCE/ODIHR election observation mission is taking notes. Its final report will document "widespread" allegations of vote-buying by political parties, a string of investigations opened, pressure on voters, and the misuse of state resources. Among its recommendations: guarantee a genuinely free and secret vote, prevent any form of pressure on voters to disclose how they voted, and intensify efforts to identify, investigate, and prosecute vote-buying.
That last recommendation is the one that sounds right and almost always fails.
The problem isn't criminals. It's a market structure.
Think about what vote-buying actually requires, mechanically.
You have a candidate with money and a need for votes. You have a voter willing to sell. But you have exactly the same problem as any buyer in any market: how do you know you got what you paid for?
A promise to vote is worthless. You need delivery confirmation. You need proof.
The entire apparatus of vote-buying — the watchers at the booth, the photographed ballot, the witnessed mark, the operative who walks you to the polling station — is a supply chain for proof. Take away the proof, and the market collapses. Not because buyers or sellers suddenly became virtuous. Because the transaction becomes an unenforceable bet.
This is not a new observation. The United Kingdom reached it in 1872. The Ballot Act 1872 replaced open, public voting with a secret ballot marked in a private compartment and placed in a sealed box. The reasoning was unambiguous: when landlords could watch tenants vote and employers could watch workers, an open market in votes existed with real enforcement. The secret ballot didn't end corruption through moral suasion. It ended it by destroying the proof mechanism.
The Australian Electoral Commission puts it plainly: the secret ballot was implemented in the 1850s because people "voted publicly, which left them vulnerable to intimidation and coercion." The design innovation was structural, not prosecutorial.
The villain isn't a bad person. It's a system that lets anyone prove how someone else voted.
Albania 2021: a market looking for a proof mechanism
What the OSCE found in Albania in 2021 was a market trying to adapt to incomplete secrecy.
Where the secret ballot holds — where no one can prove how you voted — the market has no product to sell. Where secrecy can be compromised, the market fills the gap. Party operatives near booths. Requests to photograph the ballot. Pressure to "confirm" the vote afterward. Each of these is an attempt to reconstruct the proof that secrecy destroyed.
The Albanian election machinery was not uniquely broken. The vote-buying was "widespread" and triggered "a number of investigations." But prosecutions rarely stick. ODIHR's recommendation to "intensify" prosecutorial efforts was not new — it appears, in almost identical form, in reports from countries across three continents.
The reason is structural. Vote-buying at scale involves thousands of small transactions, each individually deniable, each requiring proof that is itself illegal to demand and difficult to preserve. Criminal law is designed for cases, not market-clearing mechanisms. It can take down kingpins but cannot reliably price the market out of existence.
Only one thing reliably does that: a ballot whose secrecy is genuinely unbreakable.
Kyrgyzstan 2017: the same mechanism, a different setting
Six months before Albania's 2021 election, on October 15, 2017, polls opened across Kyrgyzstan for a presidential race that OSCE/ODIHR assessed as competitive. Eleven candidates. A field that included former prime ministers.
The mission's final report is careful and fair: the election was broadly competitive. But it documented cases of pressure on voters, vote-buying, and misuse of public resources — and, critically, it urged the authorities to "guarantee the right to a free and secret choice and to prevent any form of pressure on voters to disclose how they voted."
That phrase — "disclose how they voted" — is the tell. It names the proof mechanism directly.
Someone was asking voters to demonstrate their choice after the fact. That request only makes sense if a transaction had been made, and the buyer needed delivery confirmation. The pressure to disclose is not incidental to vote-buying. It is vote-buying's enforcement arm.
You cannot successfully buy what you cannot verify was delivered.
Philippines 1997: when proof leaves a paper trail
The Philippines case is the cleanest illustration of how proof-of-delivery actually works — because the evidence ended up in court.
On July 21, 1997, the Supreme Court of the Philippines decided Nolasco v. COMELEC, affirming the disqualification of Florentino Blanco, apparent winner of the 1995 mayoral race in Meycauayan, Bulacan. The evidence: envelopes containing money, marked with the candidate's name, distributed to voters. Sworn statements from recipients who admitted receiving cash to vote for him.
The Court held that the mere act of offering or promising something in exchange for a vote constitutes vote-buying under Section 261(a) of the Omnibus Election Code. Blanco was disqualified. The vice-mayor, not the runner-up, took office.
It is a genuine win. But look at what it required: physical envelopes. Named recipients. Sworn testimony. A paper trail improbable enough to survive a Supreme Court review.
Now think about what you don't see: the tens of thousands of transactions that leave no envelope, no sworn statement, no trail at all. Criminal prosecution is a scalpel. The problem is a market. In Meycauayan, the envelopes happened to be traceable. In most elections, they aren't.
The Court's ruling answers what happened after the fact. It does not answer what happens in a race where the vote-buyer is careful enough to avoid paper, or in a jurisdiction where the courts lack the Philippines Supreme Court's independence.
The architectural defense — making it structurally impossible to prove how someone voted — is what collapses the market before the first envelope is prepared.
Why secrecy is a security property, not a courtesy
The U.S. Court of Appeals for the First Circuit spelled this out with unusual clarity in Rideout v. Gardner (2016), reviewing New Hampshire's ban on photographing your own marked ballot.
The state's defense of the ban was straightforward: a ballot photograph lets a voter prove how they voted to a third party, which reopens the market for purchased votes. The court traced the history directly — secret-ballot reforms were adopted to "combat widespread vote buying and voter intimidation," practices that depend on the buyer or coercer being able to verify the vote.
The court struck the ban down on First Amendment grounds. But it accepted the state's premise completely: a photo of a marked ballot is a proof-of-delivery mechanism. Secrecy defeats vote-buying not by moral suasion but by making the sale unverifiable. Any feature that lets a voter prove their specific choice to someone else — a phone camera, a receipt, a traceable electronic record — re-opens the market.
This is why ballot secrecy is a security feature, not a courtesy to shy voters. The secret is load-bearing.
The gap that markets exploit
Here is the architecture of a working vote-buying market, drawn from Albania, Kyrgyzstan, and the Philippines together:
- A transaction is made before the vote — cash, jobs, favors.
- A proof mechanism is established — a photograph, a witness, a disclosure requirement.
- Delivery is confirmed — the operative checks, the voter shows.
- The market clears — votes were purchased at scale.
Destroy any single link in that chain, and the market degrades.
The secret ballot destroys link 2. When there is genuinely no way to prove how you voted — when the booth is private, the ballot is unmarked by any identifier, the box is sealed, and no one can compel you to disclose afterward — the proof mechanism does not exist. The transaction becomes an unenforceable promise. A bet on someone else's honor.
But ballot secrecy fails in practice when it fails physically. In Georgia (the country), OSCE/ODIHR's 2024 election report found potential compromises of ballot secrecy in over 30 percent of its observations — through how ballots were marked, how they were inserted into boxes, and how polling stations were physically laid out. Where the booth faces the wrong way, where the ballot surface is visible to a watcher, where the box deposit is observed, the market can see its product.
In Bulgaria, international monitors at the 2023 parliamentary elections documented "longstanding concerns over vote-buying and controlled voting" that were "present and reported," and found ballot secrecy compromised in 7 percent of observations. Law enforcement told the mission that obtaining evidence of vote-buying remains challenging and most cases never advance past the pre-trial stage.
That last sentence could appear word-for-word in reports from Albania, Kyrgyzstan, and the Philippines. The prosecutorial approach is not failing for want of effort. It is failing because it is the wrong tool for a market problem.
Kill provability and you kill the market
The strongest version of ballot secrecy is not just legal — it is designed in.
A vote that is cryptographically anonymous, cast in a process where no identifier connects the ballot to the voter, where no party can ever link a specific choice to a specific person, is a vote that cannot be purchased. Not because the law forbids it. Because the transaction has no enforcement mechanism. The buyer cannot verify delivery. The coercer cannot verify compliance. The market has no product.
This is the affirmative case for end-to-end verifiable voting systems designed around anonymity — not anonymity as a privacy gesture, but anonymity as a structural market-killer.
Note what "verifiable" means here, carefully. It does not mean "the buyer can verify." It means the voter can verify their own ballot was counted — and no one else can verify how that voter chose. Verifiability for the voter, opacity for the vote-buyer, are the same design requirement pointing in opposite directions. A system that achieves both solves the problem Albania, Kyrgyzstan, and the Philippines all share.
The inverse is also true. Any voting system that creates a traceable link between voter and choice — a QR code that encodes voter identity, a receipt that proves a specific choice, a photograph, an observable deposit — is a system that creates product for the vote-buying market. It doesn't matter whether the designer intended it. Markets are opportunistic.
What remains unverifiable — and what would change it
Here is the honest reckoning. The OSCE sends observers to Albania, Kyrgyzstan, North Macedonia, Bulgaria, and Georgia. They document vote-buying. They recommend prosecutions. The next report, four years later, documents vote-buying. They recommend prosecutions.
Criminal enforcement cannot scale to a market. And international monitoring reports — however meticulous — are claims about what observers could see. What happened inside the transaction, inside the vote-buyer's ledger, inside the operative's contact list, is not in the report.
What no one can independently verify, across all three countries studied here, is how many transactions successfully cleared the market. Not because investigators didn't try. Because the secret ballot — where it held — destroyed the evidence by design. And where it didn't hold, the evidence exists but rarely reaches a conviction.
The things that would make this checkable by anyone are not mysterious. Polling-station layouts that physically guarantee private marking and deposit, independently observed. Ballot designs that carry no voter-linked identifier. Electronic systems with cryptographic anonymity proofs that can be independently verified without trusting the vendor or the authority. Instant, precinct-level publication of results in machine-readable form, so that patterns consistent with coordinated vote-purchasing can be detected statistically, not only reported anecdotally.
None of those fixes require trusting an official's assurance that everything was fine. They replace trust with structure.
The vote-buying market in Albania in 2021, in Kyrgyzstan in 2017, and in Meycauayan in 1995 was not a failure of individual virtue. It was a failure of architecture. Fix the architecture, and you fix the market.
See how this problem shows up across different countries — and which systems are most exposed — at our global election integrity map. For the two-minute version of what verifiable elections actually require, start at /simple. To explore the specific gaps in current systems, /gaps maps them by category.
Sources
- OSCE/ODIHR, Republic of Albania Parliamentary Elections 25 April 2021 — ODIHR Election Observation Mission Final Report
- OSCE/ODIHR — Kyrgyz Republic, Presidential Election, 15 October 2017: Final Report (8 Mar 2018)
- Supreme Court of the Philippines — Nolasco v. COMELEC, G.R. Nos. 122250 & 122258 (21 Jul 1997), LawPhil
- U.S. Court of Appeals for the First Circuit — Rideout v. Gardner, No. 15-2021 (opinion, Sept. 28, 2016)
- UK primary legislation — Ballot Act 1872 (35 & 36 Vict. c. 33), legislation.gov.uk
- Australian Electoral Commission — A short history of voting and the secret ballot
- OSCE/ODIHR — Georgia, Parliamentary Elections, 26 October 2024: Final Report (20 Dec 2024)
- OSCE/ODIHR — Republic of Bulgaria, Early Parliamentary Elections 2 April 2023, Final Report (Warsaw, 27 July 2023)