The DOJ charged a US citizen over a GrapheneOS duress password that wiped his phone at the border
Samuel Tunick's Pixel erased itself during a CBP inspection at Atlanta's airport. Prosecutors call that destroying property to prevent its seizure.
Samuel Tunick’s phone erased itself in front of federal agents at Atlanta’s airport. Prosecutors say that was a crime. The Justice Department charged the Atlanta resident with destroying property to prevent its seizure, in what security researchers describe as the first US case built around a phone’s duress password.
The charge turns a documented privacy feature into alleged criminal conduct. GrapheneOS, the hardened Android build that runs on Google Pixel hardware, lets you set a second passcode that destroys the device instead of unlocking it. Customs officers searched 55,318 travelers’ devices in fiscal 2025, and 13,590 of those travelers were US citizens, a record year. Anyone who has ever wondered what happens if you actually use a wipe code at a checkpoint now has one concrete answer, and it comes with a docket number.
What the indictment says
On January 24, 2025, Tunick re-entered the United States through Hartsfield-Jackson Atlanta International Airport and got pulled into secondary inspection. Officers asked for his passcode. When they typed in the code he handed over, according to the defense filing reported by TechCrunch, “the screen went blank, flashed several times and the phone appeared to restart.” They seized the Pixel anyway, then told him he was free to enter the country.
A grand jury in the Northern District of Georgia indicted him in November 2025. The count is 18 U.S.C. § 2232(a), a statute aimed at anyone who takes action “for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control.” Maximum exposure is five years. The indictment language, quoted by Privacy Guides, accuses him of acting “to delete the digital contents of a Google Pixel cellular phone.”
Tunick pleaded not guilty. Prosecutors didn’t seek pretrial detention, so he went home after his December 2025 hearing with travel restricted to north Georgia. His lawyers have since moved to suppress everything the stop produced. That motion says agents refused his requests to speak with a lawyer, never advised him of his rights, and claimed no warrant was needed because he had not technically crossed the border yet. It also says officers told him they were hunting for child exploitation imagery without articulating a basis, and that the real interest was his association with Defend the Atlanta Forest, the movement opposing the police training campus known as Cop City. The Justice Department and CBP declined to comment to TechCrunch. A ruling isn’t expected before the end of October 2026.
How a duress password works
GrapheneOS documents the feature in plain language. The project’s features page says the OS “provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered,” and that “the wipe does not require a reboot and cannot be interrupted.” The credential works anywhere the system asks for your unlock code, lockscreen included. You configure it under Settings, Security and privacy, Device unlock, Duress Password.
What gets destroyed is key material, not bytes. Modern Android leans on full-disk encryption and its file-based successor: everything at rest is ciphertext, readable only through keys derived from your credential and held in hardware. Delete those keys and the ciphertext is noise. That’s why the operation finishes faster than a spinner could render, and why there’s no progress bar for anyone to interrupt. From the outside it looks like a botched unlock followed by a reboot, which is the entire design goal, and which matches what the defense motion describes.
No other mainstream phone ships this. Google has never put a duress PIN in AOSP or on Pixels, as Android Authority noted in its writeup of the case. Apple doesn’t either. iOS has Emergency SOS, which disables Face ID and Touch ID until you type the passcode, so it locks the phone down rather than erasing it. On F-Droid you’ll find Duress and Wasted, which watch for a trigger and then call Android’s Device Administration API to factory-reset. They run as ordinary apps holding accessibility and device-admin permissions, and Duress’s own listing notes it doesn’t work in safe mode.
The reaction was immediate. TechCrunch’s story pulled more than 3,100 upvotes and 540 comments on r/privacy, where the highest-rated replies read the prosecution as aimed at Tunick’s activism rather than at his handset.
Where the law actually stands
Three unsettled doctrines meet in this case. Start with Riley v. California, the 2014 Supreme Court decision that unanimously required a warrant before police search a phone seized during an arrest. Riley said a modern phone holds “the privacies of life,” but it did not decide what happens at a port of entry.
That gap is filled by the border search exception, and the circuits disagree about how far it stretches. On July 13, 2026 the Fourth Circuit held in U.S. v. Belmonte Cardozo that a by-hand search of a phone at the border is routine and needs no suspicion at all, while a forensic extraction does. EFF, which had urged the opposite, responded that “a person’s privacy interests in the personal data on a phone or laptop are extraordinarily different than their limited privacy interests in the contents of their suitcase.” Tunick’s case sits in the Eleventh Circuit, which went further than any other in United States v. Touset in 2018: no suspicion required, forensic searches included.
Then there’s the Fifth Amendment question of whether the government can force you to produce a passcode at all. Courts have been carving at the “foregone conclusion” doctrine from Fisher v. United States (1976) for over a decade without converging, and state supreme courts have landed on opposite answers about whether a passcode is testimonial.
Tunick’s prosecution adds a fourth question that nobody has answered: whether typing a wipe code counts as destroying property under § 2232(a). French security researcher Christophe Boutry and EFF technologist Bill Budington both told TechSpot they had not seen a similar case. Boutry called the charge “concerning” and said it “sends the message that [GrapheneOS] is criminal by default.” How the judge resolves it is the judge’s call, and guessing at the outcome here would be worth nothing.
What this means for you
EFF’s Digital Privacy at the U.S. Border guide has been the standard reference for years, and its core advice hasn’t changed: data you don’t carry can’t be searched. The practitioner playbook is short.
- Travel with a clean device and pull your working data down after you land.
- Power the phone all the way off before the checkpoint, so it sits in a before-first-unlock state with no keys in memory.
- Turn biometrics off and use a passphrase, because a face is easier to compel than a memory.
- Back up before you fly, since a seized device can be gone for weeks.
- Don’t lie to an officer. EFF’s guidance is blunt: “do not lie to a border agent.”
Runa Sandvik, who runs the security firm Granitt and works with journalists, gave TechCrunch the same first item: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going.” She also said the case “serves as a reminder that authorities may argue you knowingly destroyed data.”
That second line is the part worth sitting with. EFF’s border guide warned years before this indictment that agents “could view deliberately hiding data from them as illegal,” and Tunick’s case is that warning with a case number attached. A wipe protects the contents of a phone. It does nothing about the argument over the wipe itself, which is a legal exposure your opsec plan cannot encrypt away. None of this is legal advice, and anyone who crosses borders with sensitive material for work should be talking to a lawyer, not to a checklist.
The judge in the Northern District of Georgia isn’t expected to rule on the suppression motion before the end of October. Whatever comes back will be one district court’s answer, in the one circuit that already lets officers forensically image a laptop on no suspicion whatsoever. That’s a narrow ruling on a narrow record. Every Pixel owner who has that toggle switched on will read it anyway.
Share this article
Quick reference
- duress password
- A second unlock code that destroys a device's data instead of opening it. GrapheneOS wipes the encryption keys and any installed eSIMs the moment one is entered.
- border search exception
- The rule letting US agents search people and property at the border with no warrant and, in most circuits, no suspicion. How far it reaches into phones is still contested.
Sources
- US accuses American of allegedly wiping his phone using a 'duress' password during border search — TechCrunch
- The US is charging an American citizen for wiping his phone at the border — The Verge
- GrapheneOS features: Duress PIN/Password — GrapheneOS
- 18 U.S. Code § 2232: Destruction or removal of property to prevent seizure — Cornell Legal Information Institute
- Digital Privacy at the U.S. Border: Protecting the Data On Your Devices — Electronic Frontier Foundation
- The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required — Electronic Frontier Foundation
- CBP Enforcement Statistics Fiscal Year 2025 — U.S. Customs and Border Protection
- Atlanta activist charged with wiping phone before CBP search — Privacy Guides
- United States v. Touset, No. 17-11561 (11th Cir. 2018) — Justia
Frequently Asked
- What exactly is Samuel Tunick charged with?
- One count under 18 U.S.C. § 2232(a), destruction or removal of property to prevent seizure. The indictment says he acted to delete the digital contents of a Google Pixel phone so the government could not take it into custody. The statute carries up to five years. He pleaded not guilty.
- What does a duress password do on GrapheneOS?
- It is a second unlock credential. Typing it anywhere the OS asks for your PIN or password destroys the encryption keys for the data partition and any installed eSIMs. GrapheneOS says the wipe needs no reboot and cannot be interrupted.
- Do iPhones or stock Android phones have a duress PIN?
- No. Apple ships Emergency SOS, which disables Face ID and Touch ID until you enter the passcode, but that locks the phone rather than erasing it. Google has never shipped a duress PIN in AOSP or on Pixels. Third-party apps like Duress and Wasted exist on F-Droid.
- Can border agents search a phone without a warrant?
- Under the border search exception they generally can, but the standard depends on the circuit. The Fourth and Ninth Circuits require individualized suspicion for forensic extractions. The Eleventh Circuit, which covers Georgia, held in United States v. Touset that no suspicion is needed even for a forensic search.
- Is it illegal to use a duress password?
- No court has held that. This appears to be the first US prosecution built on the scenario, and it is an open question rather than settled law. The judge has not ruled on the defense motion to suppress.