
US accuses American of allegedly wiping his phone using a ‘duress’ password during border search
Quick Answer
Samuel Tunick faces federal charges for allegedly using a 'duress' password on his GrapheneOS phone to wipe its data during a U.S.
Quick Take
border search. This unprecedented case raises significant questions about constitutional rights at the border and the legality of device searches without warrants.
Key Points
- Tunick's phone ran GrapheneOS, allowing a passcode to wipe its data.
- Federal prosecutors claim he knowingly destroyed evidence to avoid seizure.
- The case challenges U.S. border search policies and constitutional rights.
- Tunick's attorneys argue the phone seizure was unlawful and evidence should be suppressed.
- Security experts note this is the first known case involving duress passwords.
DeepSignal Analysis
What happened
Samuel Tunick is facing federal charges for allegedly using a 'duress' password on his GrapheneOS phone to wipe its data during a U.S. border search. This case is notable as it may be the first instance in the U.S. where someone is charged for data destruction using such a password. Tunick's legal team argues that the seizure of his phone was unlawful and that the evidence should be dismissed.
Key evidence
- The U.S. Justice Department is prosecuting Samuel Tunick for allegedly providing a passcode that wiped his phone's contents during a border search.
- Tunick's attorneys claim that U.S. Customs and Border Protection unlawfully seized his phone and that evidence from the seizure should be suppressed.
- The case involves a feature of GrapheneOS that allows users to set a passcode that wipes the device's data if entered instead of the unlock passcode.
Why it matters
This case raises important questions regarding constitutional rights at U.S. borders, particularly concerning the legality of device searches without warrants. The outcome may influence how border authorities handle digital privacy and the rights of individuals crossing into the U.S. It also highlights the potential risks associated with using security features like duress passwords, which could be interpreted as data destruction by authorities.
📖 Reader Mode
~4 min readThe U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports.
This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data using a so-called “duress” password built into a phone’s software.
According to The Guardian, which covered the story earlier this week following the court’s first hearing on Monday, Atlanta resident Samuel Tunick is fighting the charges. Tunick’s attorneys said that it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year, and that any evidence — including the alleged wiping of his phone — should be thrown out.
The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone.
The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode.
Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.
The government’s indictment, which contains a typo (“Untied States Code”), accuses Tunick of allegedly providing a passcode to border agents that caused the phone to “delete the digital contents,” prior to the device being seized.
Tunick’s attorneys filed a motion to suppress the evidence, claiming that the detention and seizure were unlawful. The motion said U.S. border authorities took Tunick into a secondary inspection at Atlanta’s Hartsfield-Jackson airport as he returned from overseas on January 24, 2025, but that he was repeatedly denied access to an attorney and was not informed of his legal rights.
Tunick’s attorneys accused the government of demanding access to his phone under the pretext of searching for child exploitation imagery, but without providing evidence to justify its suspicion. His motion to suppress argued that the government was instead investigating him over his association with a long-running environmental movement called Defend the Atlanta Forest, which opposes the development of a sprawling training campus for law enforcement in Atlanta dubbed “Cop City.”
The motion said that the border agents claimed they did not need a warrant to search Tunick’s phone because he had not yet crossed the U.S. border. The U.S. government has long claimed it can search and seize people’s devices without a search warrant or court order until they are permitted entry to the United States.
When Tunick provided his passcode and the authorities entered it, “the screen went blank, flashed several times and the phone appeared to restart.” The authorities seized his phone anyway, before telling him that he was free to go and could enter the United States.
Prosecutors later charged Tunick under a federal statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it. Tunick has pleaded not guilty.
Matthew Dodge, an assistant federal public defender on Tunick’s legal team, told TechCrunch that it was incredibly rare to see the federal statute used in an indictment.
Security experts also said they had not seen charges brought in this way before.
Bill Buddington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who works to protect at-risk people as the founder of security consultancy firm Granitt, told TechCrunch that they had not seen similar cases involving the use of duress passwords.
“I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years,” said Sandvik. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.”
“With a little planning ahead of time, you can always download the data you need once you get to where you’re going,” said Sandvik.
The Electronic Frontier Foundation has guides on how to protect your data and security at the U.S. border, and explaining what rights you have.
The Atlanta federal court overseeing the case is expected to rule on Tunick’s motion to suppress later this year. A Justice Department spokesperson did not respond to TechCrunch’s request for comment.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.
— Originally published at techcrunch.com
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from TechCrunch
See more →
AI chip startup Etched defies skeptics, hits $10.3B valuation from big-name investors
AI chip startup Etched has achieved a $10.3 billion valuation after a $300 million Series C funding round, led by Sequoia and supported by notable investors like Andreessen Horowitz. The company claims to have developed innovative low-voltage chips for AI inference, significantly enhancing performance and reducing costs, with $1 billion in orders already booked.

