# Exploiting re-voting in the Helios election system
Maxime Meyer, Ben Smyth
2026-09-05
## Abstract
Election systems must ensure that representatives are chosen by voters. Moreover, each voter should have equal influence. Traditionally, this has been achieved by permitting voters to cast at most one ballot. More recently, this has been achieved by tallying the last ballot cast by each voter. We show this is not achieved by the Helios election system, because an adversary can cause a ballot other than a voter’s last to be tallied. Moreover, we show how the adversary can choose the contents of such a ballot, thus the adversary can unduly influence the selection of representatives.
Adida, Ben, Olivier de Marneffe, Olivier Pereira, and Jean-Jacques Quisquater. 2009. “Electing a University President Using Open-Audit Voting: Analysis of Real-World Use of Helios.” In *EVT/WOTE’09: Electronic Voting Technology Workshop/Workshop on Trustworthy Elections*. USENIX.
Adida, Ben, and C. Andrew Neff. 2006. “Ballot Casting Assurance.” In *EVT’06: Electronic Voting Technology Workshop*. USENIX.
Alvarez, R. Michael, and Thad E. Hall. 2010. *Electronic Elections: The Perils and Promises of Digital Democracy*. Princeton University Press.
“American Convention on Human Rights, ‘Pact of San Jose, Costa Rica’.” 1969.
Backes, Michael, Cătălin Hriţcu, and Matteo Maffei. 2008. “Automated Verification of Remote Electronic Voting Protocols in the Applied Pi-calculus.” In *CSF’08: 21st Computer Security Foundations Symposium*, 195–209. IEEE.
Bernhard, David, Olivier Pereira, and Bogdan Warinschi. 2012. “How Not to Prove Yourself: Pitfalls of the Fiat-Shamir Heuristic and Applications to Helios.” In *ASIACRYPT’12: 18th International Conference on the Theory and Application of Cryptology and Information Security*, 7658:626–43. LNCS. Springer.
Bernhard, Matthew, Josh Benaloh, J. Alex Halderman, Ronald L. Rivest, Peter Y. A. Ryan, Philip B. Stark, Vanessa Teague, Poorvi L. Vora, and Dan S. Wallach. 2017. “Public Evidence from Secret Ballots.” In *E-Vote-ID’17: 10th International Conference for Electronic Voting*, 84–109. LNCS. Springer.
Clarkson, Michael R., Stephen Chong, and Andrew C. Myers. 2008. “Civitas: Toward a Secure Voting System.” In *S&p’08: 29th Security and Privacy Symposium*, 354–68. IEEE.
Cohen, Josh Daniel, and Michael J. Fischer. 1985. “A Robust and Verifiable Cryptographically Secure Election Scheme.” In *FOCS’85: 26th Symposium on Foundations of Computer Science*, 372–82. IEEE.
Cortier, Véronique, David Galindo, Stéphane Glondu, and Malika Izabachène. 2014. “Election Verifiability for Helios under Weaker Trust Assumptions.” In *ESORICS’14: 19th European Symposium on Research in Computer Security*, 8713:327–44. LNCS. Springer.
Cortier, Véronique, and Ben Smyth. 2011. “Attacking and fixing Helios: An analysis of ballot secrecy.” In *CSF’11: 24th Computer Security Foundations Symposium*, 297–311. IEEE.
———. 2013. “Attacking and fixing Helios: An analysis of ballot secrecy.” *Journal of Computer Security* 21 (1): 89–148.
“Disinformation and ‘fake news’: Interim Report.” 2018.
“Document of the Copenhagen Meeting of the Conference on the Human Dimension of the CSCE.” 1990.
Gjøsteen, Kristian. 2012. “The Norwegian Internet Voting Protocol.” In *VoteID’11: 3rd International Conference on e-Voting and Identity*, 1–18. Springer.
Gumbel, Andrew. 2005. *Steal This Vote: Dirty Elections and the Rotten History of Democracy in America*. Nation Books.
Hardt, D. 2012. “The OAuth 2.0 Authorization Framework.” RFC 6749. Internet Engineering Task Force.
J. Richer, Ed. 2015. “OAuth 2.0 Token Introspection.” RFC 7662. Internet Engineering Task Force.
Juels, Ari, Dario Catalano, and Markus Jakobsson. 2002. “Coercion-Resistant Electronic Elections.” Cryptology ePrint Archive, Report 2002/165.
Kiayias, Aggelos, Thomas Zacharias, and Bingsheng Zhang. 2015. “End-to-End Verifiable Elections in the Standard Model.” In *EUROCRYPT’15: 34th International Conference on the Theory and Applications of Cryptographic Techniques*, 9057:468–98. LNCS. Springer.
Kremer, Steve, and Mark D. Ryan. 2005. “Analysis of an Electronic Voting Protocol in the Applied Pi Calculus.” In *ESOP’05: 14th European Symposium on Programming*, 3444:186–200. LNCS. Springer.
Kremer, Steve, Mark D. Ryan, and Ben Smyth. 2010. “Election verifiability in electronic voting protocols.” In *ESORICS’10: 15th European Symposium on Research in Computer Security*, 6345:389–404. LNCS. Springer.
Küsters, Ralf, Tomasz Truderung, and Andreas Vogt. 2011. “Verifiability, Privacy, and Coercion-Resistance: New Insights from a Case Study.” In *S&p’11: 32nd IEEE Symposium on Security and Privacy*, 538–53. IEEE.
Lijphart, Arend, and Bernard Grofman. 1984. *Choosing an electoral system: Issues and Alternatives*. Praeger.
Maaten, Epp. 2004. “Towards Remote e-Voting: Estonian Case.” *Electronic Voting in Europe-Technology, Law, Politics and Society* 47: 83–100.
Pereira, Olivier. 2016. “Internet Voting with Helios.” In *Real-World Electronic Voting: Design, Analysis and Deployment*. CRC.
Post, Gerald V. 2010. “Using Re-Voting to Reduce the Threat of Coercion in Elections.” *Electronic Government, an International Journal* 7 (2): 168–82.
“Putin’s Asymmetric Assault on Democracy in Russia and Europe: Implications for U.S. National Security.” 2018.
Quaglia, Elizabeth A., and Ben Smyth. 2018. “Authentication with Weaker Trust Assumptions for Voting Systems.” In *AFRICACRYPT’18: 10th International Conference on Cryptology in Africa*. Vol. 10831. LNCS. Springer.
Saalfeld, Thomas. 1995. “On Dogs and Whips: Recorded Votes.” In *Parliaments and Majority Rule in Western Europe*. St. Martin’s Press.
Smyth, Ben. 2012. “Replay Attacks That Violate Ballot Secrecy in Helios.” Technical Report 2012/185, Cryptology ePrint Archive.
———. 2018a. “A Foundation for Secret, Verifiable Elections.” Cryptology ePrint Archive, Report 2018/225.
———. 2018b. “Ballot secrecy: Security definition, sufficient conditions, and analysis of Helios.” Technical Report 2015/942, Cryptology ePrint Archive.
Smyth, Ben, and Véronique Cortier. 2011. “A note on replay attacks that violate privacy in electronic voting schemes.” RR-7643. INRIA.
Smyth, Ben, Steven Frink, and Michael R. Clarkson. 2015. “Election Verifiability: Cryptographic Definitions and an Analysis of Helios and JCJ.” Technical Report 2015/233, Cryptology ePrint Archive.
Smyth, Ben, and Alfredo Pironti. 2013. “Truncating TLS Connections to Violate Beliefs in Web Applications.” In *WOOT’13: 7th USENIX Workshop on Offensive Technologies*. USENIX Association.
Smyth, Ben, and Susan Thomson. 2014. “Helios Re-voting Attack.” YouTube video, linked from .
“Universal Declaration of Human Rights.” 1948.
[^1]: Kremer & Ryan capture both requirements in a single, informal definition, namely, “only...voters can vote, and only once" (Kremer and Ryan 2005), whereas Backes *et al.* decouple that definition into “only...voters can vote" and “every voter can vote only once" (Backes, Hriţcu, and Maffei 2008). (We refer to voters and non-voters, whereas Kremer & Ryan and Backes *et al.* distinguish non-voters from ‘legitimate voters’ and ‘eligible voters.’)
[^2]: We concede that non-voters may indirectly influence the decision, e.g., voters may be swayed by disinformation (“