Security

GrapheneOS Duress PIN Wipe Leads to Federal Prosecution

Sam Tunick entered a GrapheneOS duress code during an airport border search and his phone wiped itself. The DOJ now prosecutes him for destroying property to prevent seizure.

GrapheneOS Duress PIN Wipe Leads to Federal Prosecution — article cover

On January 24, 2025, Sam Tunick returned to Atlanta from a vacation in the Dominican Republic and was pulled into a secondary inspection room at Hartsfield-Jackson airport. He entered his phone passcode as customs agents demanded — and the screen went blank as the device began erasing itself. A year and a half later, the US Department of Justice is prosecuting him on grounds that stunned the security community: not espionage, but destruction of property to prevent its seizure — and experts say this may be the first time the federal statute has effectively put an operating system feature on trial.

The Timeline: An Email Three Hours Before Landing

The timeline the Guardian obtained is specific. Three hours before Tunick landed, a homeland security agent emailed a CBP tactical terrorism response team and an FBI joint terrorism task force, flagging him for “suspected terrorism activities” tied to his alleged connection with the movement against Cop City, Atlanta’s $109 million police training center; federal authorities had placed him on a terrorism watchlist over that association. In secondary inspection, agents pressed him with questions about child sexual abuse images, repeatedly demanded he unlock his phone, and threatened seizure; his lawyers say he asked four times for an attorney, was refused, was never read his rights, and no warrant was produced. When he entered the passcode, his defense motion describes it: “the screen went blank, flashed several times and the phone appeared to restart” — its contents gone. One CBP officer testified the team was “looking for anything that’s prohibited.”

The Duress PIN: Designed for “Hand It Over” Moments

Tunick’s Pixel ran GrapheneOS, an open-source, privacy-focused Android operating system built for Google Pixel phones. At the center of the case is its duress PIN: a backup code that looks like an ordinary passcode but, instead of unlocking the phone, triggers an irreversible data wipe — with no confirmation prompt or any other clue to reveal what it does. It is designed for exactly the scenarios where you are physically forced to hand over your device: a mugging, a coerced border search. The question the case now poses: in the eyes of the law, is that feature a self-protection tool or a way to destroy evidence?

The charge rests on a little-known federal statute, 18 U.S.C. § 2232, which criminalizes destroying property to prevent its seizure. EFF’s Bill Budington and cybersecurity expert Christophe Boutry both told reporters they had never seen a similar case. Prosecutors argue Tunick knowingly deleted the phone’s contents to keep the government from taking control of the property. His suppression motion argues the search was unconstitutional, that the child-abuse-image questions were a pretext for a fishing expedition into his Cop City ties, and it raises the more fundamental issue of which rights apply at the border. Boutry’s warning is the bluntest: the prosecution “sends the message that [GrapheneOS] is criminal by default,” when the system’s main goal is privacy protection. He pointed to French and Spanish authorities’ frustration with the OS, including Catalan police profiling Pixel owners as suspected criminals, and Marlon Kautz of the Atlanta Solidarity Fund defended the right to secure one’s private data. A ruling on the motion is expected no earlier than late October — and it will set the first reference point.

What It Means for Users and Teams

Crossing a border with a work phone is no longer a low-risk assumption. Three practical suggestions. First, reduce what a single device carries before international travel: a travel device, minimal installs, sensitive data left in the cloud and synced again after return. Second, organizations need a border-search playbook — when a journalist, researcher, or developer is told to hand over a device passcode, who decides and what procedure to follow should be written policy, not an improvisation. Third, security features are not legally neutral: knowing what your tools do in extreme situations is basic literacy for building and using products in 2026. Android Authority’s own framing captures the tension: a duress PIN is reassuring if you are getting mugged, but using it against law enforcement raises questions the industry has not answered — would wiping data under compulsion be treated as destruction of evidence even when no charge ever sticks? Until a court answers that, the safer assumption is that a wipe is permanent, discoverable, and scrutinized. GrapheneOS is not on trial for being insecure; it is being scrutinized for working exactly as documented, and that distinction is what makes this case worth watching.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL