
Something unexpected happened when Samuel Tunick handed border agents his phone passcode at Atlanta’s Hartsfield-Jackson airport in January 2025: the screen went blank, flashed several times, and the device wiped itself clean. Now Tunick is facing federal charges — and his case has become the first known prosecution in the United States tied to the use of a GrapheneOS duress password during a warrantless border search.
Key takeaways
- Samuel Tunick is the first known American federally charged for using a duress password to wipe his phone during a border search.
- U.S. Customs and Border Protection stopped Tunick at Hartsfield-Jackson airport in January 2025 without a warrant, relying on the border search exception to the Fourth Amendment.
- The duress PIN is a feature of GrapheneOS, a hardened Android OS for Google Pixel phones — when entered, it instantly and irreversibly deletes encryption keys and wipes the device.
- Tunick faces charges under 18 U.S.C. § 2232, a rarely invoked federal statute that prohibits knowingly destroying property to prevent authorities from seizing it.
- His attorneys argue the detention and seizure were unlawful; a federal judge is expected to rule on a motion to suppress evidence later this year.
Samuel Tunick Charged for Using a Duress Password at the U.S. Border
The facts, as described in court filings, are striking in their simplicity. Tunick, an Atlanta activist, was returning from the Dominican Republic when U.S. Customs and Border Protection pulled him into a secondary inspection room. Agents demanded access to his phone — no warrant, no court order. Under the so-called border search exception, the U.S. government has long maintained it can search and seize devices without judicial approval until a traveler is formally permitted entry into the country.
Tunick’s attorneys confirmed that his phone was running GrapheneOS. When agents entered the code he provided, the phone wiped itself. The government’s indictment — which reportedly contains a typo, reading “Untied States Code” — accuses him of providing “a passcode to border agents that caused the phone to delete the digital contents” before the device was seized.
Details of the Border Search Incident
According to Tunick’s motion to suppress, filed by his legal team, agents took him into secondary inspection on January 24, 2025. He was repeatedly denied access to an attorney and was never informed of his legal rights — a denial his attorneys describe as unlawful. The motion also alleges the government claimed it was investigating possible child exploitation imagery on his device, but without evidence to justify that suspicion. His attorneys argue the real focus was his association with Defend the Atlanta Forest, an environmental movement opposing a law enforcement training facility in Atlanta known as “Cop City.”
Agents seized the wiped phone anyway and then released him into the country.
Legal Charges and Statute Applied
Prosecutors charged Tunick under 18 U.S.C. § 2232, a federal statute that makes it unlawful to knowingly destroy or damage property to prevent its seizure by authorities. Matthew Dodge, an assistant federal public defender on Tunick’s legal team, told TechCrunch that seeing this statute in an indictment was “incredibly rare.” Security experts, including Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and digital security expert Runa Sandvik, said they had never seen similar charges brought in connection with duress passwords.
Tunick has pleaded not guilty.
GrapheneOS Duress Password: What It Does and Why It Exists
The GrapheneOS duress password is exactly what it sounds like: a PIN designed to trigger data destruction under coercive conditions. When entered in place of the normal unlock code, it deletes the device’s encryption keys and irreversibly wipes all contents — instantly. There is no undo.
Technical Description of the Duress Feature
GrapheneOS is a hardened Android operating system built for Google Pixel phones, widely used by journalists, activists, and security researchers who need stronger-than-stock protections. The OS added the duress PIN in June 2024, explicitly targeting scenarios where someone might be forced — by law enforcement or anyone else — to hand over their device. According to GrapheneOS’s own documentation, the feature is designed to prevent coercive extraction of data during arrests or border searches.
Edward Snowden, the former NSA contractor turned privacy advocate, has publicly praised GrapheneOS and described himself as a daily user, tweeting “I use GrapheneOS every day” and highlighting its privacy features.
The Collision Between a Privacy Tool and Federal Law
What makes this case genuinely novel is the legal tension it exposes. The duress feature was built for exactly the situation Tunick found himself in. From GrapheneOS’s perspective, and from the perspective of privacy advocates, using the feature is an act of self-protection. But prosecutors reframed the same action as a federal crime: knowingly destroying property — the phone’s data — to prevent its seizure.
That interpretive gap is now sitting before a federal judge. Runa Sandvik, speaking to TechCrunch, put the stakes plainly: “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” Her practical advice — download the data you need once you arrive — underscores how this case could reshape how privacy-conscious travelers approach border crossings, well before any legal precedent is formally set.
Legal and Privacy Implications of the Case
The constitutional questions here run deep. Border searches occupy a legal gray zone where Fourth Amendment protections are significantly diminished. The government’s position — that Tunick had not yet crossed the border and was therefore subject to warrantless search — is a standard CBP posture, but it has never before been tested against a case involving deliberate data destruction via a built-in software feature.
Constitutional and Procedural Issues Raised
Tunick’s motion to suppress argues the entire detention was unlawful: no warrant, no Miranda warning, no access to counsel. If the judge agrees, the evidence could be excluded — and with it, potentially, the government’s case. The ruling, expected later this year, will be closely watched by digital rights lawyers, security researchers, and anyone who travels internationally with sensitive data on their device.
Perspectives from Advocacy and Expert Communities
The Electronic Frontier Foundation, which has published detailed public guides on device rights at the U.S. border, has been a consistent voice on these issues. The EFF’s guidance warns travelers about the risks of carrying unlocked or accessible devices through border checkpoints. This case puts that guidance into stark legal relief: a tool that EFF and other advocates recommend in principle may now carry criminal liability in practice.
Bill Budington of the EFF noted he had not previously seen charges brought in connection with duress password use. The rarity of the prosecution — under a statute that defense attorneys describe as almost never used in this context — suggests the government is actively seeking new legal ground.
What happens next in this courtroom could determine whether a privacy feature becomes a federal liability — and whether travelers can legally protect their own data at the border, or whether doing so becomes, by definition, a crime.
FAQ
What is a duress password on GrapheneOS?
A duress password on GrapheneOS is a PIN that, when entered instead of the normal unlock code, deletes the device’s encryption keys and wipes its contents instantly and irreversibly.
Why was Samuel Tunick charged federally?
Samuel Tunick was charged under 18 U.S.C. § 2232 for allegedly providing border agents with a passcode that caused his phone to wipe its digital contents, which prosecutors characterize as knowingly destroying property to prevent its seizure.
What rights was Tunick denied during the border search?
According to his attorneys, Tunick was denied access to a lawyer and was not read his Miranda rights during the warrantless border phone search at Hartsfield-Jackson airport.
What is the legal basis for warrantless phone searches at U.S. borders?
U.S. Customs and Border Protection claims authority to search phones at the border without a warrant under the border search exception to the Fourth Amendment, asserting that a traveler has not legally entered the United States until formally permitted to do so.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

3 hours ago
17









English (US) ·