GrapheneOS Says Duress Password Is Legal Despite User Facing Federal Charges

Atlanta activist Sam Tunick faces federal destruction charges after his GrapheneOS phone erased itself at a border checkpoint in a legal first

Al Landes Avatar
Al Landes Avatar

By

Image: Cape

Key Takeaways

Key Takeaways

  • Sam Tunick faces federal charges for triggering GrapheneOS’s duress PIN at a border checkpoint.
  • Courts must decide whether encrypted data qualifies as “property” under 18 U.S.C. § 2232(a).
  • Activating a duress wipe during active border searches creates legal exposure, not merely owning privacy tools.

Sam Tunick, an Atlanta activist, is now charged under 18 U.S.C. § 2232(a) for allegedly destroying property to prevent lawful seizure. This is the first known US federal case built around a phone’s built-in self-wipe feature — and if you carry a surveillance app-era smartphone across a border, the outcome matters.

How the Duress PIN Actually Works

GrapheneOS doesn’t unlock when it receives a duress code — it destroys the keys instead.

Unlike a normal passcode, GrapheneOS’s duress PIN destroys the cryptographic key material protecting encrypted data. The physical phone stays in the agent’s hands. The data becomes unrecoverable noise. GrapheneOS’s Toronto-based Foundation describes this as a “minor option” within a broader security model that includes auto-reboot timers and profile isolation — features designed to resist forensic extraction without the nuclear option.

The Case So Far

Three facts, one quote, and one open question that no court has answered yet.

  • The indictment was filed November 13, 2025, in the Northern District of Georgia (case 1:25-CR-499).
  • Tunick has pleaded not guilty and moved to suppress evidence, alleging agents failed to provide Miranda warnings and denied his requests for counsel.
  • The statute historically targets physical destruction — flushing drugs down a toilet, not erasing encrypted files — and legal analysts note § 2232(a) has never been applied to encrypted content inside a device that remained in government custody.

“Data cannot be recovered after the key derivation material is reliably wiped. It’s not possible and there’s nothing we can do to assist with it.” — GrapheneOS Foundation (via X)

The government kept the phone. Only the data vanished. Does data qualify as “property” under a statute written for tangible things? No final ruling has been issued, and written arguments are still being filed. Courts have no established map for this terrain.

What This Means If You Cross a Border With a Privacy Phone

The software is legal — but timing is everything.

GrapheneOS is not banned. Having a duress PIN configured is not a crime. The exposure, as this prosecution frames it, comes from triggering a wipe during an active border search. The Foundation’s own documentation warns that using the feature under actual duress “can carry physical or legal consequences.”

For travelers worried about legal risk, strong encryption combined with auto-reboot may be the configuration that keeps data locked without handing prosecutors a workable theory. The risk isn’t owning the tool. It’s when you use it — and concerns about secretly tracking users underscore why so many travelers rely on privacy-hardened devices in the first place.

How courts ultimately define “property” in this context will ripple far beyond one activist’s Pixel. Duress PINs, remote wipes, self-encrypting drives — every privacy tool that destroys keys instead of surrendering them is watching this case closely. The phone survived the encounter just fine. The precedent is the thing that might not.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →