Blockchain-based voting is often pitched as an integrity upgrade. In high-stakes public elections, that framing is too generous. A distributed ledger can make some records harder to tamper with after the fact, but it does not secure the voter’s device, stop malware on a home computer, prevent coercion in an unsupervised setting, or create the paper evidence needed to correct a wrong outcome. The National Academies put the core problem plainly in September 2018: no known technology can guarantee the secrecy, security, and verifiability of a marked ballot transmitted over the Internet. In May 2025, the U.S. Election Assistance Commission doubled down on the opposite design center: auditable, software-independent systems with a paper record of every vote and paper ballots required for certification under VVSG 2.0.

Integrity is decided before a vote ever reaches the chain

The decisive attack surface in remote voting is the vote-capture layer, not the ledger layer. If a phone, browser, operating system, or network path is compromised, the blockchain faithfully preserves a corrupted input. That is why the most important finding in the best-known U.S. blockchain voting case was not about consensus failure. It was about endpoint compromise. The 2020 USENIX paper on Voatz found vulnerabilities that could allow adversaries to alter, stop, or expose a user’s vote, including attacks that remained viable regardless of the app’s purported use of blockchain, biometrics, hardware-backed enclaves, and mixnets.

MIT’s parallel summary made the same point in more operational language. Researchers reported that a remote attacker with access to the voter’s device could alter or discover the vote, that a hacked server could change votes, and that the protocol did not appear to verify genuine votes against the back-end blockchain in the way the marketing implied.

For a Web3 audience, the category error is familiar. In token markets, fully diluted supply can look clean while tradable float is thin and concentrated. In elections, an immutable ledger can look reassuring while the real control points sit somewhere else entirely: voter identity, device security, ballot secrecy, audit evidence, and recovery procedures. The optics are ledger-deep. The risk is operational.

Even cryptographically sophisticated online voting builders admit the boundary. Helios, one of the best-known verifiable online voting systems, explicitly says online elections are appropriate only when one does not expect a large attempt at defrauding or coercing voters, and recommends against using Internet vote capture for U.S. federal and state elections because home computers are not trusted to withstand significant attacks.

What blockchain can improve, and what it cannot

Election layer What blockchain can help with Why that is still insufficient What high-integrity systems need instead
Public publication of ballots or receipts An append-only ledger can act as a tamper-evident bulletin board for published artifacts. Public verifiability does not require blockchain. Systems such as Helios and Belenios already provide publicly verifiable tallies and public ballot-box style checking without relying on a blockchain narrative. Open protocols, independent verification tools, and public scrutiny of tally evidence.
Server-side tamper resistance Replication across nodes can reduce dependence on one database administrator. If the voter device or application is compromised, the network only preserves the wrong ballot more durably. That was the central lesson from Voatz. Software independence and voter-verifiable evidence that does not rely on trusting the capture software.
Transparency optics A visible ledger can make stakeholders feel that nothing is hidden. Public elections require secrecy and resistance to coercion, not just visible logs. Visibility is not the same thing as privacy-preserving evidence. Private and independent voting, plus audit paths that can be checked without exposing how any individual voted.
Recounts and outcome correction Hashes and timestamps can show whether a published record changed. A wrong outcome still needs a correction path. In election administration, the gold standard is evidence that can escalate to a hand review, not immutable publication alone. Paper records, software independence, and audits that continue until the result is confirmed or every ballot is reviewed.

Live deployments show the boundary very clearly

Voatz is the cleanest U.S. cautionary example because it was not just a paper proposal. In the 2018 midterms, West Virginia became the first U.S. state to allow select voters to cast ballots on a mobile phone through the Voatz app. The 2020 USENIX analysis concluded that the system had vulnerabilities that could let adversaries alter, stop, or expose votes, and recommended abandoning near-future plans to use the app for high-stakes elections.

Switzerland offers a second useful lesson. After Swiss Post published source code for its new system in February 2019, researchers uncovered significant security flaws. The Swiss Federal Chancellery said the system was therefore not available for the May 19, 2019 vote. The important point is not that transparency failed. It is that transparency worked, and what it revealed was that election-grade verifiability is much harder than marketing-grade immutability.

Estonia shows a different boundary. Estonia has conducted binding national Internet voting since 2005, and official descriptions emphasize digital identity, encryption keys, digital signatures, a voter application, and a vote-collecting server rather than a blockchain architecture. In the March 8, 2023 parliamentary election, Estonia counted 312,181 i-votes and 301,620 paper-ballot votes. Estonia also allows a voter to supersede an earlier i-vote by voting with a paper ballot on election day, which underlines the operational reality: remote voting systems survive on institutional procedure, legal fallback, and trust management, not on distributed-ledger branding.

What public-election integrity actually requires

U.S. election standards now center on software independence. VVSG 2.0 states that an error or fault in voting-system software or hardware cannot be allowed to cause an undetectable change in election results. The guidelines say all conformant systems must be software independent, and identify two paths to get there: independent voter-verifiable paper records, or cryptographic end-to-end verifiable systems.

That detail matters because it reframes the blockchain debate. The question is not whether a ledger is decentralized. The question is whether a wrong outcome can happen without leaving evidence that forces detection. That is a much stricter standard than “the records were written to chain.” VVSG 2.0 even makes the transition explicit by noting that paperless DRE systems are non-conformant under this framework.

Cryptographic verification is promising, but it is not operationally mature enough to be waved through on brand alone. VVSG 2.0 said there were no verified end-to-end cryptographic protocols available within the current market at the time of adoption, and on December 23, 2025, the EAC and NIST initiated a public process to solicit, evaluate, and approve such protocols for certification use.

Paper evidence remains the correction layer because audits can escalate. California’s official risk-limiting audit process states that the review continues until the software can confirm the election results based on the manually reviewed ballots, or until all ballots cast in the election are reviewed. That is the practical difference between auditability and immutability. Immutability can preserve a record. Auditability can overturn a wrong result.

The institutional direction of travel in the United States is also clear. On May 28, 2025, the EAC said more than 98% of jurisdictions already use systems with a paper record of every vote and formally affirmed support for 100% paper-based systems because auditable, software-independent systems are necessary to safeguard elections.

Where blockchain can be defensible

Blockchain can still be defensible in narrower settings. The best fit is not a national or state public-office election. The best fit is a lower-coercion environment where convenience matters, the threat model is smaller, and the organization is willing to trade some security margin for participation or transparency. Helios says exactly that about online elections, and Belenios describes its own scope as ranging from scientific councils to sport associations while emphasizing a public ballot box and publicly verifiable tally.

Even in those settings, blockchain is optional rather than foundational. Belenios shows that you can get vote privacy, voter eligibility controls, a public ballot box, and public tally verification without using a blockchain at all. That is an important design lesson for Web3 builders. If the objective is verifiability, the scarce resource is sound protocol design plus usable verification, not necessarily a chain.

For readers coming from token governance, this is where the election-security literature becomes especially useful. At FinDaS Tokenomics, the same discipline applies in token economy design: do not confuse an immutable settlement layer with a complete governance system. In onchain governance, it often sits in key control, participation asymmetry, and concentration of voting weight. The common failure is structural. People focus on the visible ledger and miss the actual locus of control.

The right questions are not about blockchain first

Any proposal that says “blockchain secures elections” should be forced through a narrower checklist.

The evidence base is not subtle. Blockchain can contribute tamper-evident publication and, in some cases, better public observability. It does not by itself ensure election integrity. For public elections today, the defensible architecture remains software-independent voting, paper evidence, and audits that can correct an outcome when the machines are wrong. The chain can be part of the furniture. It is not the foundation.