Federal prosecutors in Atlanta have charged a traveler with destroying evidence after he allegedly supplied a code that erased his phone’s contents during a secondary inspection at Hartsfield-Jackson airport. The indictment, handed down against Atlanta resident Samuel Tunick, is believed by digital-security experts to be the first U.S. prosecution built around a “duress password”—a feature in the privacy-focused GrapheneOS that lets an owner wipe a device by entering a special unlock code. The case tests whether a security tool designed to protect data from coercive unlock demands can become a criminal act when the demand comes from federal agents at the border.
Tunick pleaded not guilty to one count of destroying the “digital contents” of his phone to prevent federal personnel from searching and seizing them, a charge that invokes 18 U.S.C. § 2232(a). The alleged wipe occurred on January 24, 2025, after Tunick returned to the United States from the Dominican Republic. While the outcome will depend on detailed factual and constitutional disputes, the prosecution already delivers a stark warning: security features that users treat as prudent last-resort protections can be interpreted as deliberate obstruction when activated during a government encounter.
The Encounter That Led to a Landmark Indictment
According to a defense motion to suppress, Customs and Border Protection officers placed Tunick in secondary inspection and pressed him repeatedly for his device passcode. The filing asserts that he was physically searched, questioned without Mirandizing him, and denied access to an attorney—conditions the defense argues amounted to a custodial interrogation that violated his constitutional rights. The government has not yet formally responded to those claims.
When Tunick eventually provided a passcode, the phone’s screen went blank, flashed multiple times, and appeared to restart. The filing describes this as the device’s “wipe process,” triggered by the GrapheneOS duress password. The agents did not receive a non-working or incorrect code; they received one that the operating system accepted and that then initiated irreversible data destruction. That distinction is central to the legal divide. A forgotten PIN or a refusal to unlock raises one set of questions; a code that deletes all local data and encryption material raises another: is it an exercise of privacy self-help, or the destruction of evidence?
The government’s theory is that Tunick knowingly used the wipe function to prevent officers from lawfully seizing and searching the phone’s contents. The defense counters that the interrogation was unlawful, that any statements and the wipe itself should be suppressed, and that the underlying investigation was pretextual. Tunick’s lawyers argue that agents were actually interested in his alleged ties to Defend the Atlanta Forest—a movement opposing the “Cop City” public safety training center—and that the border stop was a fishing expedition disguised as a child-exploitation-material check. A judge’s eventual ruling on the motion to suppress will shape the admissibility of evidence and could narrow or collapse the prosecution’s case entirely.
What GrapheneOS’s Duress Feature Actually Does
The feature at the heart of the case is not a Hollywood “self-destruct” button. GrapheneOS, a hardened Android-based operating system for Google Pixel devices, allows users to define a secondary PIN or password for duress situations. When that credential is entered at any Android unlock prompt, the device immediately begins an irreversible wipe: user data, downloaded apps, and even eSIMs are deleted, according to the project’s documentation. The process does not require a reboot and cannot be interrupted. The idea is to thwart an adversary who tries to force a unlock by threat or coercion.
Crucially, the duress password must differ from the real unlock credential; if they match, the real unlock takes priority. GrapheneOS warns that the feature is designed only for genuine emergencies, not as a routine privacy tool. Once activated, the device doesn’t present a sanitized dummy profile or hidden data; it simply erases everything. That design choice makes the feature powerful for its intended purpose, but also makes its use during a border inspection immediately conspicuous and legally aggressive.
The threat model that duress passwords address is straightforward: an attacker doesn’t need to break encryption if they can compel the owner to decrypt. Security practitioners have long recognized that physical coercion, whether by criminals or by state agents, can bypass technical defenses. GrapheneOS’s answer is to give the user a way to comply with an unlock demand while simultaneously destroying local data. But the Tunick case illustrates a dangerous flip side: the same act that protects data from an attacker can be construed as obstructing a lawful government seizure.
Why the Airport Is a Legal Minefield for Your Devices
International airports are among the most legally fraught places in the United States for electronic devices. The border-search doctrine grants Customs and Border Protection broader authority to search travelers’ belongings, including phones and laptops, without a warrant or even individualized suspicion in some circumstances. However, that authority is not limitless, and federal appellate courts have drawn different lines.
In Alasaad v. Wolf, the First Circuit held that basic manual device searches need no suspicion, while advanced forensic searches require only reasonable suspicion, not a warrant. The Ninth Circuit, in United States v. Cano, drew a sharper distinction: manual searches require no suspicion, but forensic or invasive searches demand reasonable suspicion that the device contains digital contraband, and a “generalized search for evidence” is forbidden. That rift means a traveler’s protections can vary profoundly depending on the airport and the jurisdiction.
Tunick’s case arises in the Eleventh Circuit, where precedent has been more permissive of warrantless device searches at the border. Even so, his defense argues that the facts of his detention—prolonged questioning, denial of counsel, and the alleged password demand—exceeded what constitutional boundaries allow. The legal terrain underscores a practical reality for travelers: a quick manual inspection, a device seizure, a forensic extraction, and an extended interrogation can all be treated differently, and the rules are not uniform across the country.
What the Charge Means for Your Security Habits
The Tunick prosecution doesn’t make GrapheneOS or its duress feature illegal. Nothing in the case suggests that installing a privacy-focused OS or configuring a secondary wipe password is, by itself, criminal. But the practical message is unmistakable: using that feature during a border encounter can expose you to a felony charge. That sets up a security paradox. Users who configure no last-resort wipe may fear compelled access; those who do configure one may fear that activating it will be treated as obstruction.
This risk directly affects anyone whose phone holds sensitive material belonging to others: journalists with confidential sources, lawyers with client communications, corporate employees with trade secrets, healthcare workers with regulated data, domestic-violence survivors with safety-plan information, and activists with organizational contacts. For these groups, a duress wipe can seem like a logical safeguard. The indictment signals that such a safeguard, if triggered in response to a government demand, can be reinterpreted as evidence of intent to destroy property.
The case also highlights a distinction that users often blur: there is a difference between data-minimizing before travel and destructive action after a law-enforcement demand has begun. A duress password is a one-way trip with no undo. The law around 18 U.S.C. § 2232(a) turns on whether the destruction was done “for the purpose of preventing or impairing” the government’s lawful control of the property. If agents have already asserted authority to search the device, activating a wipe becomes legally perilous in a way that pre-travel data trimming does not.
Before Your Next Flight: A Practical Travel-Data Checklist
The safest approach, security professionals say, is not to carry sensitive data across a border if you don’t need to. Duress passwords have a legitimate role, but they aren’t a comprehensive travel plan. For Windows laptop users and Android phone owners alike, preparation should begin well before departure.
- Travel with less data. Use a separate travel profile, a freshly provisioned handset, or a clean laptop install when feasible. Remove locally stored documents, archives, and media that aren’t essential for the trip. Cloud access can be useful, but only if accounts are properly secured and two-factor authentication doesn’t depend solely on a device you might lose.
- Know your platform’s wipe mechanics. Windows BitLocker encryption protects data at rest, but it doesn’t self-destruct on demand. Android factory-reset protection works differently from Apple’s remote erase, and third-party “panic” buttons may only lock the device or send a distress alert, not delete data. Understand whether your chosen tool locks, deletes, revokes keys, removes eSIMs, or needs connectivity to function.
- Plan for recovery. If your device is lost, seized, or wiped, you’ll need backup codes, hardware security keys, and a way to restore accounts without relying on the missing device. Store recovery materials somewhere accessible but off-device.
- Don’t equate technical capability with legal immunity. A feature may work exactly as documented and still create criminal exposure depending on timing, intent, jurisdiction, and the specific sequence of events at an inspection point.
- Think beyond the panic wipe. Long before any border encounter, consider a personal data audit: what’s on your phone, why it’s there, and whether a warrant-proof encrypted cloud backup could let you travel with a leaner local footprint. Encrypting work files and keeping them in a dedicated secure container can also limit what a casual inspection reveals.
GrapheneOS offers other hardening features—USB data controls, improved sandboxing, hardened memory allocation—that can reduce a device’s attack surface without triggering a wipe. The duress password is one tool among many, not a substitute for disciplined data management.
Where the Law Goes from Here
The Tunick case won’t deliver a sweeping verdict on the legality of security software overnight. If the defense succeeds in suppressing evidence, the government’s case could collapse before the broader questions are ever litigated. A ruling for prosecutors wouldn’t ban duress passwords, but it would provide a roadmap for charging someone who uses one during a border inspection—especially if officials can show advance knowledge or deliberate activation.
The most lasting impact may be on user confidence. For years, factory resets, remote wipes, and encryption-key destruction have been viewed as sensible hygiene. This case shows how quickly those features can be cast as evidence of criminal intent when the state demands access. Travelers who value strong data protection now face an uncomfortable reality: the tools that guard against unlawful coercion are the very ones that can place you in legal jeopardy. That tension won’t be resolved by a single district court ruling, but the Atlanta prosecution ensures that every device owner crossing a U.S. border will carry the new calculus forward.
Watch for developments in the suppression motion and for any guidance from the Eleventh Circuit on the intersection of border-search authority and digital evidence destruction. For now, the practical takeaway is clear: a duress password is an emergency feature, not a border-crossing strategy. Prepare before you travel, and don’t count on a last-second wipe to keep your data—and your freedom—intact.