INDEX 134 / NEWS · 12 MIN

His Duress PIN Wiped the Phone at the Border. It's a Felony.

A GrapheneOS duress PIN wiped a phone during a CBP search. The feds called it obstruction. What it means for your rights.

CL

ComputeLeap Team

Share

His Duress PIN Wiped the Phone at the Border. It's a Felony.

On January 24, 2025, Samuel Tunick landed at Atlanta's Hartsfield-Jackson International Airport after a trip to the Dominican Republic. Customs and Border Protection agents pulled him into secondary inspection — a stop that would become the first known federal prosecution for using a phone's built-in privacy feature. When agents demanded his passcode, Tunick entered a code. The screen went blank, flashed several times, and the phone appeared to restart. The data was gone. The phone was running GrapheneOS, and the code Tunick entered was a duress PIN — a secondary passcode that, instead of unlocking the device, instantly and irreversibly wipes its encryption keys. Federal prosecutors now say that amounts to a felony.

@Pirat_Nation summarizing the GrapheneOS duress password border search case on X

View original post on X →

The Department of Justice charged Tunick under 18 U.S.C. Section 2232, a statute that criminalizes destroying property to prevent its seizure. He has pleaded not guilty to a one-count indictment alleging he destroyed the "digital contents" of his phone to prevent federal personnel from searching them. If convicted, he faces up to five years in prison. The case has drawn over 21,000 upvotes on Reddit's r/technology and 1,268 points with 1,019 comments on Hacker News — making it one of the most-discussed non-AI stories this week across both platforms.

Our take: This prosecution is not about one man's phone. It is the federal government testing whether using a privacy feature designed for coercion scenarios constitutes evidence destruction when triggered during a border search. If this charge sticks, every duress mechanism — from GrapheneOS's wipe PIN to remote-erase commands — becomes a potential felony at the border. The implications reach far beyond one activist's Pixel phone.

What Actually Happened at the Airport

According to court filings reported by TechCrunch, the story has layers that the headline does not capture. Tunick was not flagged randomly. Federal agents had previously circulated his name and photo internally, identifying him as under investigation for "suspected terrorism activities" — linked to his alleged association with the Defend the Atlanta Forest movement, which opposes a law enforcement training facility known locally as "Cop City."

A motion filed by Tunick's defense argues that the stated justification for the search — looking for child sexual abuse material — was pretext for investigating his connections to the protest movement. His attorneys say he was denied access to a lawyer, was not read his Miranda rights, and was repeatedly pressed for his passcode during what amounted to a warrantless interrogation.

INFO

The border search exception: U.S. courts have long held that CBP officers can conduct warrantless searches of travelers and their belongings at ports of entry. But whether that authority extends to the full contents of a smartphone — and whether compelling a passcode is testimonial — remains unsettled law across the federal circuits.

TechCrunch article reporting on the GrapheneOS duress password border search prosecution

View original article on TechCrunch →

The timing is not coincidental. Just weeks before this case made headlines, the Fourth Circuit ruled in U.S. v. Belmonte Cardozo that CBP officers may manually scroll through any traveler's phone at the border without any suspicion at all. The EFF called the ruling a significant erosion of digital privacy at borders, noting it conflicts with the spirit of Riley v. California (2014), which established that searching a phone requires a warrant in non-border contexts.

What Is a GrapheneOS Duress PIN?

For readers unfamiliar with the technology at the center of this case: GrapheneOS is a privacy- and security-focused Android operating system that runs on Google Pixel phones. It is maintained by an independent open-source project and is widely used by journalists, activists, security researchers, and privacy-conscious individuals.

In June 2024, GrapheneOS shipped a feature it had been developing for months — the duress PIN/password. Here is how it works:

  1. You set your normal unlock PIN (say, 1234)
  2. You separately configure a duress PIN (say, 5678)
  3. If you enter 1234, the phone unlocks normally
  4. If you enter 5678, the phone instantly deletes its encryption keys and wipes all data, then shuts down
  5. The wipe is irreversible — even GrapheneOS cannot recover the data

The feature was explicitly designed for scenarios where someone is physically coerced into unlocking their device. GrapheneOS's own documentation lists the intended use cases: journalists protecting sources, activists in repressive environments, and travelers facing device searches at border crossings.

GrapheneOS official account discussing data extraction defenses and Motorola partnership

View original post on X →

The GrapheneOS project itself responded to the case, emphasizing the OS's broader data-extraction defenses and its upcoming partnership with Motorola Mobility to expand beyond Pixel devices. The project notably did not comment on Tunick's specific legal situation but reinforced that its security features are designed to protect all users.

The Legal Fault Line

The prosecution under 18 U.S.C. Section 2232 is unusual. Bill Budington, a senior technologist at the Electronic Frontier Foundation, told TechCrunch he had never seen charges brought in connection with duress password use. Runa Sandvik, a digital security expert and founder of Granitt, confirmed she had not encountered a similar case either.

The government's argument is straightforward: Tunick knowingly gave agents a code that would destroy data during an active search. That, prosecutors say, is the textbook definition of destroying property to prevent seizure.

The defense fires back on multiple fronts:

  • Fourth Amendment: The search was warrantless and lacked probable cause. Tunick's lawyers cite decisions from the First, Fourth, and Ninth Circuits holding that warrantless border device searches cannot be used to fish for evidence of domestic crimes.
  • Fifth Amendment: Surrendering a passcode is a testimonial act. The defense relies on a 2012 Eleventh Circuit decision (In re Grand Jury Subpoena Duces Tecum) holding that decrypting and producing hard-drive contents triggers Fifth Amendment protection.
  • Pretext: The stated CSAM justification was a cover for investigating Tunick's activism. If the search itself was unlawful, the destruction-of-evidence charge built on top of it cannot stand.

A federal judge in Atlanta is expected to rule on the motion to suppress no earlier than late October 2026. However the court rules, this case will almost certainly be appealed — making it a potential circuit-level precedent on whether privacy features can be criminalized at the border.

WARNING

The contrarian view: There is a genuine argument on the other side. Tunick gave agents a passcode he knew would destroy data during an active search. If you handed a customs officer a briefcase rigged to burn its contents when opened, nobody would call that a privacy right. The duress PIN was designed for exactly the scenario Tunick used it in — the question is whether designing a tool for coercion resistance makes using it during a federal search legal. The prosecution may be novel, but the underlying act — deliberately destroying evidence during a search — is not.

What the Community Is Saying

The case has ignited one of the most active privacy debates online this year.

Hacker News thread discussing the GrapheneOS duress PIN border search case with 1268 points and 1019 comments

View discussion on Hacker News →

On Hacker News (1,268 points, 1,019 comments), the discussion split into several camps:

The compliance pragmatists argued that antagonizing border agents — who hold enormous discretionary power — is tactically foolish regardless of your legal rights. As one commenter noted, "You may have to think both about protecting your data by technical means, and about not angering the agents."

The rights maximalists pushed back hard, arguing that "if you have nothing to hide" logic is precisely what the Fourth Amendment exists to prevent. Multiple commenters drew uncomfortable parallels to authoritarian border practices in other countries, with several noting that the U.S. system is becoming harder to distinguish from the regimes it criticizes.

The technical middle ground focused on practical alternatives: travel with a clean device, restore from encrypted cloud backup after clearing customs, use hidden encrypted volumes rather than wipe mechanisms. The consensus among technical commenters was that the safest approach is making destruction unnecessary — rather than carrying a weapon (the duress PIN) you might be forced to deploy.

Chase Oliver commenting on the first known US case charging data destruction via a hidden phone wipe feature

View original post on X →

Political figures weighed in as well. Chase Oliver, the 2024 Libertarian presidential candidate, called it "the first known U.S. case charging data destruction via a hidden phone wipe feature" and framed it as a civil liberties flashpoint.

The Bigger Picture: Privacy Tools Under Legal Fire

This case does not exist in a vacuum. It arrives alongside a broader tightening of government authority over digital devices at borders:

  • Fourth Circuit ruling (July 2026): In U.S. v. Belmonte Cardozo, the court held that manual phone scrolling at the border requires zero suspicion — only forensic extractions need justification
  • Legislative stalemate: The Protecting Data at the Border Act (Wyden/Paul) would require warrants for all border device searches, but has never received a floor vote in either chamber
  • GrapheneOS + Motorola expansion: GrapheneOS is expanding beyond Pixel to Motorola devices in 2027, potentially putting duress PINs in far more hands

The collision course is clear. Privacy tools are becoming more accessible. Government search authority at borders is expanding. And the Tunick case is where these two vectors meet.

What This Means for You

If you are a developer, journalist, security researcher, or anyone who crosses borders with sensitive data on your phone, the Tunick case creates concrete legal exposure you need to account for.

TIP

Practical recommendations for border crossings:

  1. Travel with a clean device. Wipe or factory-reset your phone before travel. Restore from an encrypted cloud backup after clearing customs. This is the single most effective protection because there is nothing to find and nothing to destroy.

  2. Understand that duress features are now a prosecution vector. GrapheneOS's duress PIN is still valuable for genuine coercion scenarios (mugging, kidnapping, authoritarian regimes). But using it during an active U.S. federal search now has documented legal consequences.

  3. Know your rights — and their limits. U.S. citizens cannot be denied entry, but they can be detained, their devices seized, and (now) charged for destroying data. The ACLU and EFF both publish border-crossing digital security guides.

  4. Separate devices from data. Consider a dedicated travel phone with only essential apps. Keep sensitive data in encrypted cloud storage accessible only from your primary device at home.

  5. Consult legal counsel before your trip if you work with sensitive sources or data that could trigger government interest.

What Comes Next

The federal court in Atlanta will rule on Tunick's suppression motion no earlier than late October 2026. The possible outcomes fork sharply:

If the motion succeeds and the search is deemed unconstitutional, the case collapses — and the government gets a clear signal that border search authority has limits when it comes to phones.

If the motion fails and the case proceeds to trial, we get the first jury verdict on whether using a built-in phone feature constitutes evidence destruction. An appeal to the Eleventh Circuit is virtually guaranteed either way.

The wildcard: GrapheneOS could modify the duress PIN feature in response — perhaps adding a delay, a confirmation step, or a "travel mode" that disables the wipe function. But doing so would undermine the feature's core purpose: protecting users who are being coerced and cannot safely refuse.

This is one of those cases where the legal system is being asked a question technology has already answered. GrapheneOS built the duress PIN because coercion at borders is real. The government is now arguing that defending against that coercion is a crime. A federal court will decide which framing wins — and the answer will shape how every privacy-focused OS, app, and feature is designed going forward.

The case is United States v. Tunick, Northern District of Georgia. We will update this article when the court rules.

Related reading:

AUTHOR
CL

ComputeLeap Team

The ComputeLeap editorial team covers AI tools, agents, and products — helping readers discover and use artificial intelligence to work smarter.

DISCUSSION

Join the discussion

Have thoughts on this article? Discuss it on your favorite platform:

NEWSLETTER

The ComputeLeap Weekly

Get a weekly digest of the best AI infra writing — Claude Code, agent frameworks, deployment patterns. No fluff.

WEEKLY. UNSUBSCRIBE ANYTIME.