A US citizen is being prosecuted for entering a duress password on his own phone during a border search, in what lawyers and privacy researchers believe is the first case of its kind. Samuel Tunick handed border agents a passcode at Atlanta's Hartsfield-Jackson airport, the screen went dark, and the device wiped itself. The federal government has now charged him under a statute written for people who destroy property to stop it being seized. He has pleaded not guilty.
What happened at Hartsfield-Jackson
On 24 January 2025 Tunick landed in Atlanta returning from a trip abroad and was pulled aside for secondary inspection. Agents from Customs and Border Protection asked for access to his phone, saying they were looking for child exploitation imagery. According to his defence, no evidence was ever offered to justify that suspicion.
Tunick gave them a passcode. In the account filed with the court, the screen went blank, flashed several times and the phone appeared to restart. It was not restarting. The code he entered was a duress password, and the device had just erased itself. Agents seized the handset anyway and let him into the country. Eighteen months later the case became a federal indictment.
How a duress password works
Tunick's phone ran GrapheneOS, a privacy-focused Android alternative that installs on Google Pixel hardware. Among its features is a second passcode that looks exactly like the normal one but triggers an immediate wipe instead of unlocking. There is no warning dialogue, no confirmation prompt and no visible difference at the lock screen.
The wipe is not a slow file deletion that forensic tools can partially recover. The system destroys the encryption keys that make the stored data readable and powers the device down. Without those keys the remaining bytes are noise. That design is deliberate: the feature exists for journalists, activists and domestic abuse survivors who may be physically compelled to unlock a device, and a wipe that could be interrupted halfway would be useless to them.
The charge: a property statute pointed at encryption keys
Prosecutors reached for 18 U.S.C. section 2232(a), which covers anyone who, before, during or after a search or seizure by an authorised official, knowingly destroys, damages, wastes, disposes of or transfers property to prevent it being seized. The maximum sentence is five years.
The statute was written with physical evidence in mind: flushing drugs, burning documents, throwing a weapon off a bridge. Applying it here requires treating the data on a personal device, or the encryption keys protecting it, as the property being destroyed. The phone itself was not damaged at all. Agents took it away in working order.
- The act charged: typing a code into a device the defendant owned, when asked for a code by an officer.
- The property allegedly destroyed: data, not hardware. The handset survived and was seized intact.
- The precedent at stake: whether a documented, shipped operating system feature becomes a crime the moment it is used in front of an official.
Bill Budington of the Electronic Frontier Foundation and security researcher Runa Sandvik both said they had never seen the provision used this way before.
What the defence argues
Tunick is represented by assistant federal public defender Matthew Dodge. The defence is running two lines at once. The first is procedural: the stop was pretextual, Tunick was repeatedly denied access to a lawyer, and he was never informed of his rights. The second goes to the charge itself, arguing that entering your own passcode into your own phone is not the destruction of property, and that no lawful seizure was under way at the moment he typed it.
That second point is the one with consequences beyond this defendant. If a passcode entry counts as destruction whenever an officer is watching, then any security feature that fails closed becomes legally hazardous. An Atlanta federal court is expected to rule on the motion to suppress later this year.
The border is a low-rights zone by design
This case only exists because of how thin constitutional protection is at a port of entry. CBP asserts authority to conduct basic searches of electronic devices without a warrant and without any particular suspicion, and courts have largely allowed the border exception to stand while circuits continue to disagree about advanced forensic searches.
The volume is rising. In fiscal year 2025 CBP searched 55,318 electronic devices, up 17.6 percent on the year before and up from 41,767 in 2023. Basic searches accounted for 50,922 of those, with 4,396 advanced searches involving analysis or copying of contents. Of the total, 13,590 involved US citizens. Set against roughly 419 million travellers, the odds for any individual remain under 0.01 percent, but the trend line has pointed one way for three years.
This is the category of exposure a VPN does not address, and it is worth being precise about why. Encrypting traffic protects data while it moves across a network; a border search takes the endpoint itself, where the data sits decrypted behind a lock screen. The same distinction we covered when looking at device-level identifiers that survive any tunnel applies here in physical form. Network privacy and device privacy are separate problems, and travellers who conflate them tend to protect the wrong one. For anyone tracking how far US entry screening may go, we also looked at the proposal to require ten years of social media, email and phone history for entry.
Conclusion
• US accuses American of wiping his phone using a duress password during border search - TechCrunch
• An Atlanta man used a duress password. Now the government is prosecuting him - Closed Network
• GrapheneOS duress PIN could land a man in prison - Android Authority
• 18 U.S. Code section 2232 - Cornell Law School LII
• Border search of electronic devices - U.S. Customs and Border Protection
• US customs searched a record number of electronic devices last year - CBC News