← Tous les articles

Antrim County was caught because it was absurd. What about the errors that aren't?

Antrim County's error got caught because it was laughably obvious. The elections that should terrify you are the ones where the numbers look completely fine.

It is the morning of April 9, 2009, and three Finnish municipalities are about to find out that 232 of their voters have effectively been erased.

The previous autumn, Karkkila, Kauniainen, and Vihti had run a pioneering electronic-voting pilot alongside their traditional paper ballot. Voters who chose the electronic option made their selection on a machine, waited — or thought they were waiting — and left. But the system had a problem embedded in its design: after choosing a candidate, voters had to complete a separate confirmation step, and the instructions failed to make this clear. Many removed their smartcard before the vote was saved.

The machine did not tell them anything had gone wrong.

No warning. No error message. No receipt. Two hundred and thirty-two people walked out of polling stations believing they had voted, when in fact they had not. Finland's Supreme Administrative Court, in decision KHO:2009:39, annulled the affected municipal elections and ordered them re-run. Finland never extended the pilot.

Here is the thing to hold onto: those votes were not stolen. They were not altered. They simply ceased to exist — silently, invisibly, politely. And no one knew until after the fact, when the loss was already irreversible.

That is not a software horror story. That is a verifiability story. The voters had no way to confirm their ballot had been captured. The system had no way to prove it had recorded anything. The only mechanism for discovering the problem was the absence of 232 people from the final tally — and that discrepancy only surfaced because someone was looking for it.

What if no one had looked?

The Antrim Lesson People Missed

You have probably heard of Antrim County, Michigan. On election night 2020, one of the most reliably Republican counties in the state briefly showed Joe Biden winning by roughly 3,000 votes. The error was glaring — the kind of result that makes county officials' phones ring at 11 p.m. It was caught, corrected, and the certified outcome was unaffected.

We have written about that case before, from the angle of what it says about hand counts. But there is a prior question that Antrim raises and most coverage never seriously asks.

The error was caught because it was absurd. Everyone who knew anything about Antrim County knew those numbers were wrong before they had finished reading them. The county's political history was the error-detection mechanism. There was no automated cross-check, no cryptographic receipt, no independent verification pipeline. There was collective incredulity.

That is not a system. That is luck wearing the costume of a system.

Now ask yourself: what about the plausible error? What about a county where the result is unexpected but not implausible — where someone lost who was expected to be competitive, in a race decided by a few hundred votes? What about the error that does not flip a county, just shaves a percentage point off a candidate's margin in a competitive district? What about the canvass figure that is quietly wrong in a way that does not offend anyone's intuitions?

Those errors are not caught by incredulity. They are caught, if they are caught at all, by independent verification. And independent verification is precisely what most reporting and canvassing processes do not provide.

What the Dutch Decided — and Why

In 2007, the Dutch government commissioned an independent expert panel — the Adviescommissie inrichting verkiezingsproces, chaired by F. Korthals Altes — to examine its election process after years of controversy over voting computers. The panel published its final report, Stemmen met vertrouwen ("Voting with Confidence"), on September 27.

The commission laid down a principle that sounds obvious once you hear it and is quietly violated almost everywhere: there are no secrets in the election process, and questions must be answerable, with the answers checkable and verifiable. It concluded that paper ballots counted by hand in a polling station are preferable from the standpoint of transparency and checkability, and that any electronic method is only acceptable if it produces a paper record the voter can verify.

The Netherlands then withdrew its 1997 regulation approving voting machines and returned to paper ballots entirely.

Notice what the Dutch panel was not saying. It was not saying the machines were rigged. It was not saying any election had been stolen. It was saying something harder and more fundamental: a result that cannot be independently verified is not trustworthy, regardless of whether tampering occurred. The absence of proof of fraud is not the same as proof of integrity. And an unverifiable system produces both the same result.

Germany's Federal Constitutional Court reached essentially the same conclusion the same year. In its March 2009 ruling on Nedap voting machines used in the 2005 federal election, the court held that every essential step of voting and result determination must be examinable by ordinary citizens "without any specialist knowledge." A system that hides its work inside electronic memory fails the public-verifiability test — not because the machines necessarily miscounted, but because no one could independently confirm they had not.

Both countries were articulating the same principle Finland's disaster illustrated in practice: if voters cannot independently confirm their vote was recorded, and if observers cannot independently confirm the totals are accurate, then confidence in the result depends entirely on trusting the people running the system. That is not a democracy's foundation. That is a faith-based process wearing democracy's clothes.

The Canvass Problem Nobody Wants to Name

In most American jurisdictions — and in many democracies — the results pipeline works roughly like this. Precincts report to a county. Counties compile and report to a state. The state canvass aggregates, reviews, and eventually certifies a result. At each step, officials check their own work.

This is the part of the process that Antrim County exposed, quietly and uncomfortably. No external, independent mechanism stopped wrong numbers from being published. The error surfaced because the numbers were politically implausible. And the subsequent hand audit — the thing officials cited as confirmation — still differed from the machine tabulation by about a dozen votes out of roughly 15,700 cast.

A dozen votes. In a race where the margin is measured in hundreds, a hand count method that is itself off by a dozen is not a proof. It is a narrower uncertainty range worn as a badge of certainty.

This is not a partisan claim. This is arithmetic. A verification method that carries its own irreducible error cannot settle a question where the margin falls within that error. A hand count is better than no check at all, and paper ballots are far better than paperless machines. But "we hand-counted it" and "the canvass confirmed it" are the beginning of a verification conversation, not its conclusion.

The deeper problem is structural. The canvass — the official process that is supposed to be the systematic check — is conducted by the same officials who produced the initial totals, using the same equipment, under the same administrative chain of command. When those officials catch an error, that is valuable. When they miss one, there is no independent trip wire.

Malawi's courts put this starkly in 2020. The Constitutional Court nullified the 2019 presidential election — upheld by the Supreme Court of Appeal in Mutharika & Electoral Commission v Chilima & Chakwera — after finding widespread use of correction fluid on official tally sheets, duplicate result forms, and improperly handled canvass documents. The Electoral Commission had declared a winner. The courts looked at the paper trail and found it could not be trusted as a verifiable record of what voters had actually decided.

Correction fluid. The official record of a presidential election had been altered with an instrument sold in every office-supply store. The announced result was not verifiable against the source documents because the source documents could not be trusted. Announcing a winner is not the same as proving the count.

The Scale of What "Plausible" Hides

Consider Venezuela in July 2017. The government held a vote for a National Constituent Assembly and announced the turnout figures. Two days later, Smartmatic — the technology company that had provided Venezuela's automated voting systems since 2004, and which had run this specific election — issued a public statement. Its chief executive said the company knew "without any doubt" that the turnout figure announced by the National Electoral Council had been manipulated, and estimated the difference between actual and announced participation at "at least one million votes."

The vendor. The company whose machines ran the election. Publicly disowning the official numbers.

And the public had no independent means to check either claim, because independent audit was unavailable. The machines had run. The totals had been announced. There was no tamper-evident, publicly checkable record against which anyone could reconcile the figures.

This is the outer limit of the unverifiable result. But the principle scales all the way down. A result that can only be verified by trusting the authority that produced it is unverifiable, whether we are talking about a presidential election in Caracas or a county canvass in Michigan. The mechanism is the same; only the magnitude differs.

In Kenya, the Supreme Court understood this clearly enough to void an entire presidential election over it. In Raila Odinga & another v IEBC (2017), the court found that not all polling-station result forms had been electronically transmitted as required, that the forms lacked consistent security features, and that the final tally had been declared before all underlying documentation was received. The chain from individual polling station to national result was broken — and when that chain cannot be independently verified, the court held, the result itself is legally unsound. The election was annulled.

The court's reasoning was not "fraud was proven." It was: "the count cannot be independently checked, and therefore cannot be accepted." That distinction matters enormously.

What Independent Verification Actually Requires

Risk-limiting audits are a step in the right direction, and Colorado's pioneering 2017 statewide RLA showed the concept works: you size the hand-verification sample to the closeness of the race, provide a defined statistical confidence level, and tie the result to a durable paper record. Georgia's 2020 statewide hand count of roughly five million ballots demonstrated that even at enormous scale, paper provides an independent check.

But an audit is only as strong as the independence of the process and the integrity of what it is auditing against. If the paper records entering an audit have themselves been handled in ways that cannot be verified — if the chain of custody from polling station to canvass to audit has gaps — then the audit is checking one unverifiable artifact against another.

The GAO made this point indirectly in its September 2005 report on electronic voting systems, finding that federal efforts to ensure security and reliability were underway but that key activities remained incomplete, and recommending that standards, certification procedures, and vulnerability-sharing mechanisms still needed to be built. The report was issued five years after the crisis that prompted HAVA, which itself was supposed to be the fix. Recognizing the problem and passing a statute are not the same as solving it. Building the verification apparatus takes sustained, independent pressure on every step of the pipeline.

What genuine independent verification requires:

First, tamper-evident source records. Not just paper, but paper that is sealed, signed, and handled under a chain of custody that independent observers can confirm at every step. A tally sheet that can be overwritten with correction fluid is not a tamper-evident record.

Second, real-time public reporting. Every precinct result, the moment it is finalized, in machine-readable form that anyone can download and reconcile. Not a press release. Not a PDF. A raw data file that any analyst, journalist, or independent observer can aggregate themselves and check against the official total. The U.S. Election Assistance Commission urges officials to make results downloadable in formats like .csv and .xml — but urging is not requiring, and most jurisdictions still do not.

Third, independently checkable cryptographic commitment. This is what moves "trust the officials" to "verify the math." When a result is cryptographically committed at each step of the pipeline — precinct to county to state — any alteration at any step breaks the chain in a way that is detectable without access to any secure system. Anyone with the published data can check the arithmetic. The verification power moves from insiders to the public.

The German Constitutional Court asked for verifiability by ordinary citizens without specialist knowledge. That is the design target. Not "auditable by experts given enough time and access" but verifiable by anyone, in the open, using publicly available data.

The Moment Nobody Flags

Return to Finland for a moment. Two hundred and thirty-two votes. A small number, in three small municipalities, in a local election. The Supreme Administrative Court annulled the elections and ordered them re-run. That was the right outcome.

But notice what made the annulment possible: someone counted. The absence of those 232 votes was detectable because someone could compare the electronic tally against other records. The problem surfaced because a discrepancy was visible.

Now imagine the same design flaw in a system with no independent comparison point — no paper ballot cast alongside the electronic one, no parallel count, no mechanism for detecting the gap. The votes would simply not be there. The announced total would be lower than the true intention of the electorate by some unknowable amount. And it would look completely normal.

That is the Antrim lesson that Antrim itself did not illustrate, because Antrim's error was too obvious. The dangerous error is the one that looks fine. The dangerous gap is the one nobody flags. And the only defense against that error — the only one that works regardless of whether officials are honest, competent, or paying attention — is a system whose results are independently verifiable by parties who have no stake in the outcome.

Not trust. Verification.

Not "the Secretary of State says it's fine." A publicly accessible, cryptographically committed, machine-readable result that any observer can check against the source records, at any time, without asking permission.

That is not the system most democracies have today. It is the system they need.


The shareable version: Antrim's error was caught because the result was politically absurd. A plausible error in a close race — a few hundred votes, a clean-looking canvass, a hand count that differs by a dozen — might never surface. The fix is not more officials checking officials' work. It is publicly verifiable, machine-readable results that anyone can audit independently. Not trust. Proof.

See how common the reporting and canvassing gap is across the world →

Read the 2-minute version of why unverifiable results are the core problem →

Explore specific verification gaps by country →


Sources