US Prosecutes Citizen for Using Duress Password to Wipe Phone at Border

The US government is prosecuting American citizen Sam Tunick for allegedly providing authorities with a duress password that wiped his phone during a border search at Atlanta's Hartsfield-Jackson airport on January 24, 2025. The case, docketed as United States v. Tunick (case number 1:25-cr-00499) in the U.S. District Court for the Northern District of Georgia, Atlanta division, relies on a statute that makes it illegal to destroy or damage property to stop authorities from seizing it (The Verge).
Tunick used the duress password feature of GrapheneOS, a privacy-focused operating system, to trigger the wipe. The feature is designed to immediately erase device data when a specific credential is entered, providing users under coercion a mechanism to destroy sensitive information rather than surrender it.
According to a motion filed by Tunick's lawyers, federal agents refused him access to a lawyer, did not provide a warrant, and did not inform him of his legal rights during the detention. The motion argues the detention was a pretext for a fishing expedition into Tunick's connections to the Stop Cop City movement in Atlanta (The Verge). The government countered that no warrant was required because Tunick had not yet been granted permission to enter the US, invoking the broad search authority customs and border agents exercise at ports of entry.
The Guardian first brought the case to wide attention on July 23, 2026, characterizing Tunick as a "Cop City protester" in its headline (The Guardian). TechCrunch followed on July 24, 2026, and The Verge published its report on July 26, 2026, attributing its information to the motion filed by Tunick's defense team. The CourtListener docket for the case was last updated on July 17, 2026 (CourtListener).
404 Media had previously covered Tunick's initial indictment in December of the prior year, a detail surfaced by a later Gizmodo report published July 25, 2026 (Gizmodo). Marlon Kautz, a member of the Atlanta Solidarity Fund, was quoted in The Guardian's July 23 article commenting on the case.
The prosecution applies a property-destruction statute to the act of entering a credential that triggers a software-level data wipe. The duress password is a standard feature within GrapheneOS, not a bespoke evasion tool; it functions as a deliberate, user-configured self-destruct mechanism for exactly the scenario Tunick faced. Charging its use as a crime effectively criminalizes a privacy-protective software feature operating as designed.
The border search context is significant. The government's position, that no warrant was needed because Tunick had not yet been granted permission to enter the US, leans on the border search exception to the Fourth Amendment. Whether a statutory destruction charge can survive when the underlying seizure lacked a warrant, and when the accused was denied counsel and Miranda warnings, is a novel legal question. The defense's motion frames the entire encounter as a pretextual detention targeting political association, which introduces First Amendment concerns into what might otherwise be a straightforward property-destruction case.
This is not the first confrontation between privacy-focused technology and law enforcement's demand for access, but the specific mechanism here, a duress wipe triggered by a voluntarily provided password, is unusual. The government is not compelling decryption or penalizing refusal to cooperate. It is charging the act of data destruction itself, using a feature whose explicit purpose is to prevent seizure of data by authorities.
In this author's view, the case turns the existence of a duress password from a security feature into potential legal liability. If entering a self-destruct credential at a border crossing is prosecuted as destruction of property, the practical effect is to neutralize the feature's utility for its intended audience, anyone who anticipates coercive search conditions. That reframing deserves close attention from the security community, not because the outcome is certain, but because it tests whether the right to privacy-protective software design holds when it directly frustrates a lawful seizure.


