The U.S. Justice Department has brought an unprecedented criminal charge against an American citizen for using a “duress” password that wiped his phone clean when border authorities entered it, marking the first known prosecution of its kind in the United States. The case, centered on a custom Android operating system that allows users to set a passcode that deliberately destroys all data, has ignited a fierce legal debate over the constitutional limits of border searches and the right to protect digital privacy against government overreach.
The First Prosecution for a “Duress Password” at the Border
Samuel Tunick, an Atlanta resident, was returning from overseas travel on January 24, 2025, when he arrived at Hartsfield-Jackson Atlanta International Airport and was pulled into a secondary inspection by U.S. Customs and Border Protection (CBP) agents. According to court documents, Tunick was questioned about his association with the environmental movement Defend the Atlanta Forest, which opposes the construction of a massive law enforcement training center known as “Cop City.” The government has not publicly disputed that its interest in Tunick’s phone was linked to this activism.
During the inspection, the agents demanded access to Tunick’s phone. Tunick provided a passcode, which the agents entered. The screen went blank, flashed several times, and the phone appeared to restart. The agents seized the device anyway, and after telling Tunick he was free to enter the country, they later charged him under a federal statute that makes it a crime to knowingly destroy or damage property to prevent authorities from seizing it. The charge is the first time federal prosecutors have used the statute in connection with a duress-password feature built into a phone’s software.
What Is a Duress Password and How Does GrapheneOS Implement It?
The phone in question was running GrapheneOS, a security-focused, open-source Android operating system designed for Google Pixel devices. GrapheneOS includes a duress feature that allows the device owner to set a secondary passcode. When this passcode is entered—whether by the user under coercion or by an unauthorized party—the phone immediately wipes all user data, including apps, contacts, messages, and files. The primary unlock passcode, by contrast, grants full access to the device.
This mechanism is distinct from a simple factory reset. It is a deliberate, software-driven destruction of data that occurs in real time, with no recovery option unless the user has a separate backup. The feature is widely used by journalists, activists, and human rights defenders who travel to high-risk locations where authorities may compel them to unlock their devices. Until now, no one in the United States had been charged for using it.
Legal Questions: What Rights Do Travelers Have at the U.S. Border?
The case raises fundamental questions about the Fourth Amendment at the border, where the U.S. government has long claimed broad search and seizure powers without a warrant. The legal fiction that the border is not “U.S. soil” until a person is formally admitted allows CBP agents to search electronic devices without probable cause, as long as the search is “routine.” However, the Supreme Court has never fully settled whether prolonged, non-routine searches—especially those that involve copying or seizing a device—require a warrant.
Tunick’s attorneys argue that the detention and seizure were unlawful from the start. They claim that CBP agents denied him access to an attorney and failed to inform him of his legal rights during the secondary inspection. The government, according to the defense, demanded access to the phone under the pretext of searching for child exploitation imagery, but provided no evidence to justify that suspicion. The true motive, the motion to suppress alleges, was to investigate Tunick’s involvement in the Defend the Atlanta Forest protests—a domestic political activity protected by the First Amendment.
“The screen went blank, flashed several times, and the phone appeared to restart,” the motion states, describing the moment the agents entered the duress passcode. Despite the wipe, the agents seized the phone and later charged Tunick for destroying data that could have been seized.
What Is the Federal Statute Used to Charge Tunick?
The indictment cites 18 U.S.C. § 2232, which makes it unlawful to “knowingly destroy, damage, or remove any property to prevent the seizure or securing of such property by a person authorized to make such seizure.” The law is typically used in contexts where a suspect destroys physical evidence—such as flushing drugs down a toilet or shredding documents—during a raid. Applying it to the use of a duress password on a phone is legally novel.
Matthew Dodge, an assistant federal public defender on Tunick’s legal team, told TechCrunch that it was “incredibly rare” to see the statute used in an indictment. Security experts agreed. Bill Budington, a senior staff technologist at the Electronic Frontier Foundation (EFF), and Runa Sandvik, a digital security expert and founder of Granitt, said they had not encountered a similar case. “I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” Sandvik said. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.”
Broader Implications for Digital Privacy and Border Security
The case is a watershed moment for the use of duress passwords and similar security features. If the prosecution succeeds, it could discourage travelers from using such protections, effectively compelling them to surrender their data under threat of criminal liability. Conversely, if the court grants Tunick’s motion to suppress—arguing that the seizure itself was unlawful—the government’s ability to search phones at the border based on thin pretext may be curtailed.
The EFF has long warned that travelers should not carry sensitive data across borders without preparation. Sandvik advises that “with a little planning ahead of time, you can always download the data you need once you get to where you’re going.” That practical guidance becomes even more critical in light of this prosecution: if you cannot protect your data with a duress password without facing charges, the safest option is to leave the data behind entirely.
The Technical and Legal Nuances of the GrapheneOS Duress Feature
GrapheneOS’s duress feature is not a hidden backdoor or a vulnerability. It is a documented, user-controlled security tool. The user sets the duress passcode in the phone’s settings. When entered, the phone triggers a secure wipe that cannot be undone. The operating system is designed with a focus on privacy and security, and its duress feature is explicitly intended for situations where a user is forced to unlock the device.
The core legal question is whether using such a feature constitutes “knowingly destroying” property to prevent seizure. The government argues yes: Tunick provided the duress passcode intentionally, knowing it would wipe the phone, and did so to prevent CBP from accessing the data. The defense counters that the property (the phone itself) was not destroyed—only the data was deleted—and that the seizure was illegal in the first place, so the destruction was not done to prevent a lawful seizure.
Notably, the indictment contains a typo, referring to “Untied States Code” instead of “United States Code.” While a minor error, it underscores the novelty of the case and the legal system’s lack of precedent for this scenario.
What Happens Next? The Motion to Suppress and the Court’s Ruling
The Atlanta federal court overseeing the case is expected to rule on Tunick’s motion to suppress later this year. The motion argues that the evidence gathered from the phone—including the fact that it was wiped—should be excluded because the detention and seizure were unlawful. If the court agrees, the prosecution may collapse. If it denies the motion, the case will proceed to trial on the § 2232 charge, setting a landmark precedent for how duress passwords are treated under U.S. law.
The Justice Department has not responded to requests for comment, but the case is being closely watched by civil liberties organizations, digital security advocates, and the tech industry. For travelers, the message is clear: the protections you thought you had at the border may come with legal risks you never anticipated.
As Sandvik noted, the best defense is preparation. The EFF provides guides on how to protect data at the U.S. border, including advice on using encrypted devices, traveling with minimal data, and understanding your legal rights. But this case adds a new layer of complexity: even the most well-intentioned security feature can be turned into evidence of a crime.