Sam Tunick, an Atlanta activist, is now charged under 18 U.S.C. § 2232(a) for allegedly destroying property to prevent lawful seizure. This is the first known US federal case built around a phone’s built-in self-wipe feature — and if you carry a surveillance app-era smartphone across a border, the outcome matters.
How the Duress PIN Actually Works
GrapheneOS doesn’t unlock when it receives a duress code — it destroys the keys instead.
Unlike a normal passcode, GrapheneOS’s duress PIN destroys the cryptographic key material protecting encrypted data. The physical phone stays in the agent’s hands. The data becomes unrecoverable noise. GrapheneOS’s Toronto-based Foundation describes this as a “minor option” within a broader security model that includes auto-reboot timers and profile isolation — features designed to resist forensic extraction without the nuclear option.
The Case So Far
Three facts, one quote, and one open question that no court has answered yet.
- The indictment was filed November 13, 2025, in the Northern District of Georgia (case 1:25-CR-499).
- Tunick has pleaded not guilty and moved to suppress evidence, alleging agents failed to provide Miranda warnings and denied his requests for counsel.
- The statute historically targets physical destruction — flushing drugs down a toilet, not erasing encrypted files — and legal analysts note § 2232(a) has never been applied to encrypted content inside a device that remained in government custody.
“Data cannot be recovered after the key derivation material is reliably wiped. It’s not possible and there’s nothing we can do to assist with it.” — GrapheneOS Foundation (via X)
The government kept the phone. Only the data vanished. Does data qualify as “property” under a statute written for tangible things? No final ruling has been issued, and written arguments are still being filed. Courts have no established map for this terrain.
What This Means If You Cross a Border With a Privacy Phone
The software is legal — but timing is everything.
GrapheneOS is not banned. Having a duress PIN configured is not a crime. The exposure, as this prosecution frames it, comes from triggering a wipe during an active border search. The Foundation’s own documentation warns that using the feature under actual duress “can carry physical or legal consequences.”
For travelers worried about legal risk, strong encryption combined with auto-reboot may be the configuration that keeps data locked without handing prosecutors a workable theory. The risk isn’t owning the tool. It’s when you use it — and concerns about secretly tracking users underscore why so many travelers rely on privacy-hardened devices in the first place.
How courts ultimately define “property” in this context will ripple far beyond one activist’s Pixel. Duress PINs, remote wipes, self-encrypting drives — every privacy tool that destroys keys instead of surrendering them is watching this case closely. The phone survived the encounter just fine. The precedent is the thing that might not.





























