A federal prosecution in Atlanta is putting an unusually consequential question before the courts: can a traveler be criminally charged for using a phone’s built-in duress password—a security feature designed to erase personal data when the device is unlocked under coercion? The case against Atlanta resident Samuel Tunick is believed by digital-security experts to be the first known U.S. prosecution built around that scenario, transforming a niche privacy setting in GrapheneOS into a test of border-search power, encrypted-device security, and evidence-destruction law. The Guardian
Tunick has pleaded not guilty to a one-count indictment alleging that he destroyed the “digital contents” of his phone to prevent federal personnel from searching and seizing them. The charge follows a January 24, 2025 secondary inspection at Atlanta’s Hartsfield-Jackson airport, after Tunick returned from the Dominican Republic. His defense team’s motion to suppress says agents demanded access to his devices, and alleges that the passcode he eventually supplied triggered the phone’s wipe process.
This is not simply a dispute over whether a particular phone was searched lawfully. It is a potentially defining confrontation between the right to configure personal technology for security and the government’s claim that a user who activates a wipe mechanism during a border inspection may be destroying property to frustrate a lawful seizure.
For Windows and Android users, the lesson is not that every traveler suddenly faces a similar prosecution. It is that the familiar ideas behind device security—PINs, encryption, factory resets, remote erase tools, and privacy-focused operating systems—may carry sharply different practical and legal consequences when an interaction shifts from ordinary loss prevention to a border encounter.

A smartphone displays a lock and warning amid airport security screening and global cybersecurity imagery.The allegation: a passcode that did not unlock the phone​

According to the defense filing, federal agents had arranged to question Tunick as he returned to the United States, and Customs and Border Protection placed him into secondary inspection. The filing says he was questioned, physically searched, and repeatedly pressed for the passcode to his phone while he sought to speak with a lawyer and said he did not want to continue the interview. The motion to suppress frames these events as a custodial interrogation that violated his constitutional rights; those are defense allegations, not findings by the court.
The government’s core theory is simpler and more severe. The indictment alleges that Tunick destroyed the phone’s digital contents before officers could search and seize them, conduct that prosecutors say violates 18 U.S.C. § 2232(a). The defense motion identifies the charge as arising from the alleged wiping of the handset in response to agents’ request for a password.
The account in the motion is striking because the agents were not allegedly handed a non-working or incorrect code. Instead, they were allegedly given a code that the operating system accepted as meaningful. When entered, the phone’s screen reportedly went blank, flashed several times, and appeared to restart. The court filing presents that behavior as the basis for the government’s claim that the device was intentionally wiped.
That distinction matters. A forgotten passcode, a locked device, or a person declining to unlock a phone raises one set of legal and practical questions. A code designed to initiate irreversible erasure raises another: whether the act is characterized as an exercise of privacy protection, as the destruction of evidence, or as both depending on the facts and the court’s interpretation.

The political context is part of the legal dispute​

Tunick’s defense asserts that the government’s underlying interest lay in his alleged connections to Defend the Atlanta Forest, the movement that opposed the Atlanta Public Safety Training Center, commonly called “Cop City.” The filing argues that agents’ references to suspected child sexual abuse material were a pretext for investigating his political associations. The motion to suppress makes clear that this is an argument advanced by the defense, which the government may contest.
Reporting on the suppression hearing adds that Tunick had been placed on a terrorism watchlist connected to his alleged association with the movement, and that officials described the airport questioning as routine border activity aimed at finding prohibited material. The Guardian’s account of the hearing underscores why the dispute cannot be reduced to a technical curiosity: the litigation sits amid a larger conflict over protest policing, surveillance, and the use of federal investigative authorities.
A judge’s eventual resolution of the suppression motion will therefore matter independently of the criminal charge. The court must consider not only what happened to the device, but also the circumstances of the questioning, the asserted requests for counsel, the character of the detention, and the government’s authority to search or seize the phone at the airport.

What a GrapheneOS duress password actually does​

The feature at the heart of the prosecution is neither a Hollywood-style “self-destruct” button nor a hidden backdoor. GrapheneOS is an Android-derived operating system focused on privacy and security, available for supported Google Pixel devices. The project describes its software as building on the Android Open Source Project while adding security hardening and privacy features. GrapheneOS’s feature overview documents its approach and supported security controls.
Its duress feature allows an owner to define a second PIN or password distinct from the normal unlock credential. Entering that secondary credential wherever Android requests device credentials triggers an irreversible wipe of the device, including installed eSIMs, according to the project’s own documentation. GrapheneOS’s duress-password documentation says the process cannot be interrupted and does not require a reboot.
This is an important technical point. A GrapheneOS duress password is not intended to grant a fake, limited, or sanitized view of a handset. It is designed to remove the user’s local data and encryption material from the device. Once the wipe has begun, the goal is not plausible deniability about the existence of data; it is the elimination of readable on-device data.
GrapheneOS also says users need both a duress PIN and a duress password to enable the feature, reflecting Android’s differing credential-entry contexts. The project warns that the real unlock credential takes precedence if it is identical to the duress credential, meaning the secondary code must be distinct to work as intended. GrapheneOS’s implementation notes are unusually explicit about these operational details.

Why the feature exists​

The threat model is straightforward: someone may be coerced into entering a device credential. That coercion could be physical, criminal, personal, or governmental. Security products have long tried to address the possibility that an attacker does not need to defeat encryption if they can instead compel the owner to decrypt the device.
GrapheneOS’s approach treats that moment as an emergency condition. The owner can provide a valid device credential, but the result is data destruction rather than access. In security terms, that is a powerful capability precisely because it is irreversible; in legal terms, it is risky because the same irreversibility can be framed as intentional obstruction.
The broader security rationale is not difficult to understand. Phones now store authentication tokens, work documents, password-manager data, health information, private photographs, location history, encrypted messages, cloud-session credentials, and often years of personal communications. The Supreme Court has recognized that mobile phones differ qualitatively from ordinary physical containers because of the depth and breadth of information they can hold, a concern echoed in Tunick’s defense filing. The defense motion invokes that privacy interest in arguing against the search and seizure.

The federal statute at the center of the case​

The law cited in the Tunick prosecution, 18 U.S.C. § 2232(a), prohibits knowingly destroying, damaging, wasting, disposing of, transferring, or otherwise acting with respect to property for the purpose of preventing or impairing the government’s lawful authority to take it into custody or control. A conviction can carry a fine, imprisonment of up to five years, or both. The text of 18 U.S.C. § 2232 supplies the statutory language.
That wording creates a critical qualifier: the government’s authority must be lawful. The statute does not merely say that any destruction occurring during an encounter with officials is a crime. It ties liability to an intent to impede the government’s lawful seizure or custody of property.
For prosecutors, the apparent argument is that a phone’s contents are part of the property officers were entitled to seize and inspect, and that triggering a wipe after the demand for access intentionally defeated that authority. The allegation is technologically novel, but the statutory framing is familiar: destruction intended to stop a lawful seizure.
For the defense, the motion to suppress attacks the foundation of that argument. It contends that officers violated Tunick’s Fifth, Sixth, and Fourth Amendment rights through the manner of interrogation, the denial of counsel, the alleged lack of Miranda warnings, and the warrantless search and seizure. The filing asks the court to suppress statements and evidence, including the asserted wipe itself.

A first-of-its-kind prosecution, but not a blank legal slate​

Experts cited in reporting on the case said they had not encountered a previous prosecution directed at use of GrapheneOS’s duress-password feature in this way. The Guardian reported that cybersecurity specialist Christophe Boutry and Electronic Frontier Foundation technologist Bill Buddington had not seen a comparable case.
That novelty does not mean the court must invent law from scratch. The legal ingredients are established: border searches, compelled device access, the testimonial nature of passcodes, evidence suppression, and statutes prohibiting destruction to frustrate seizure. What is new is the combination of these issues inside a smartphone’s security architecture.
The result could turn on narrow factual findings rather than a sweeping declaration about privacy software. Did Tunick knowingly provide the duress credential? Was there intent to impair an authorized seizure? Was the search or questioning lawful? Did the encounter become custodial? Was the device’s deletion process already under way before a lawful seizure occurred? These questions may decide the case more directly than broad arguments about whether privacy technology is socially desirable.

Why the border changes the legal landscape​

International airports are among the most legally complicated places to carry a device. The government has broader search authority at the border than it ordinarily has inside the country, but that authority is not limitless, and courts have reached different conclusions about how it applies to modern electronics.
In Alasaad v. Wolf, the U.S. Court of Appeals for the First Circuit held that basic electronic-device searches at the border could occur without reasonable suspicion, while advanced searches could be conducted with reasonable suspicion rather than a warrant or probable cause. The First Circuit decision summary illustrates the expansive view of border-search authority adopted by that court.
Other appellate rulings have imposed different limits. In United States v. Cano, the Ninth Circuit held that manual phone searches could be conducted without reasonable suspicion, but forensic searches required reasonable suspicion that the phone contained digital contraband; it also ruled that a border search could not extend into a generalized hunt for evidence of any crime. The Ninth Circuit’s Cano opinion demonstrates the unsettled and jurisdiction-specific nature of digital border-search doctrine.
Tunick’s case is in the Eleventh Circuit, where his defense filing acknowledges precedent more favorable to the government’s ability to conduct warrantless electronic-device searches at the border. The motion to suppress nevertheless argues that the facts of his detention and interrogation exceeded what constitutional protections permit.
That uneven legal map is important for ordinary travelers. “The border” is not a single, perfectly settled exception that produces the same answer in every court, every level of search, or every set of circumstances. A quick manual inspection, a device seizure, a password demand, a forensic extraction, and an extended interrogation can be treated differently.

The risk to privacy tools: criminalization by outcome​

The most troubling potential consequence of this prosecution is not that GrapheneOS will suddenly become illegal. There is no indication that simply installing a privacy-focused operating system or configuring a wipe feature is itself criminal. GrapheneOS offers the duress function publicly as part of a broader suite of security options. Its official feature page presents it as a user-configurable protection, not as concealed or illicit functionality.
The concern is subtler. If activating a duress feature during a border encounter becomes a successful basis for criminal liability, users may conclude that a security feature built for coercive situations becomes legally dangerous at precisely the moment it was designed to operate.
That can create a security paradox. A phone owner who uses no wipe feature may fear compelled access. A phone owner who configures one may fear that using it creates an allegation of destruction to impede the government. The technology offers a technical defense against coercion, while the legal system may treat its activation as evidence of intent.
This concern is especially relevant to people whose phones carry material belonging to others:
  • Journalists with confidential sources or unpublished reporting.
  • Lawyers with client communications and litigation files.
  • Corporate employees with trade secrets, customer information, and privileged documents.
  • Health-care workers and researchers handling regulated information.
  • Domestic-violence survivors whose devices contain location, contact, or safety-planning data.
  • Activists, religious communities, and political organizers whose contact networks may be sensitive even without being unlawful.
The case should not be read as a blanket endorsement of device wiping. It should instead force a clearer distinction between responsible data minimization before travel and destructive action after a law-enforcement demand has begun.

A better travel-security strategy than relying on a panic wipe​

The practical advice from security professionals is often less dramatic and more effective: do not carry sensitive data across a border if you do not need to carry it. A duress password may have a legitimate security purpose, but it is not a comprehensive travel plan, and the Tunick case shows why treating it as one can be fraught.
For Windows users who travel with a laptop, Android handset, or both, sensible preparation starts before departure:
  1. Travel with less data. Use a clean travel profile, a separate travel laptop, or a freshly provisioned handset where appropriate. Remove local copies of documents, archives, and media that are unnecessary for the trip.
  2. Separate device storage from cloud availability. Keep essential information accessible through properly secured accounts where lawful and appropriate, rather than retaining every file offline. This approach has trade-offs, including account-security and connectivity concerns, but it reduces what exists locally.
  3. Use strong, unique device credentials. Encryption is only meaningful when the credential protecting it is robust. Avoid reusing a device passcode as an account password.
  4. Understand your specific platform. Windows BitLocker, Android encryption, Apple device protection, remote-wipe services, and third-party “panic” tools do not operate identically. Know whether a feature locks, deletes, revokes keys, removes an eSIM, or merely sends a remote request that requires connectivity.
  5. Plan for account recovery. If a device is lost, seized, or wiped, the user needs recovery codes, secure backups, hardware security keys, and a way to regain access without relying on the missing device.
  6. Do not confuse technical capability with legal immunity. A feature may work exactly as documented and still create legal exposure depending on timing, intent, jurisdiction, and the circumstances of an encounter.
GrapheneOS itself is a technically sophisticated operating system with meaningful hardening features beyond the duress password, including USB data controls, improved sandboxing, exploit mitigations, hardened memory allocation, and enhanced profile support. Its feature documentation shows that the duress mechanism is one component of a broader security model—not a substitute for disciplined data management.

What the court’s decision could—and could not—change​

A ruling in Tunick’s favor would not eliminate the government’s border-search authority or establish an unconditional right to erase a phone when agents seek access. It could, however, reinforce the importance of the circumstances in which officers demand credentials, question a traveler, and assert authority to inspect a device.
A ruling for prosecutors would not automatically ban GrapheneOS, privacy-focused Android operating systems, or device-wipe features. But it could provide a roadmap for treating an activated wipe mechanism as a prosecutable effort to impair a lawful seizure, particularly where officials can show advance knowledge, deliberate activation, and a valid underlying authority to take the device.
The most durable consequence may be cultural rather than doctrinal. For years, users have treated factory reset capabilities, remote erase functions, and encryption-key destruction as sensible security hygiene. This case exposes how quickly those same features can be placed in an adversarial legal frame.
That is why the Tunick prosecution deserves close attention from the Windows, Android, and broader security communities. It is not a narrow argument about one activist’s Pixel phone. It is a dispute over whether personal-device security tools remain tools of user autonomy when the state demands access—or become evidence of criminal intent the moment they are used.

References​

  1. Primary source: International Business Times UK
    Published: 2026-07-26T21:35:01+00:00
  2. Related coverage: discuss.grapheneos.org
  3. Related coverage: boingboing.net
  4. Related coverage: sovereignphone.au
  5. Related coverage: news.linxi.com.au