Technology

Man Charged for Wiping His Phone at the Airport With a Secret Password

Martin HollowayPublished 7d ago4 min readBased on 5 sources
Reading level
Man Charged for Wiping His Phone at the Airport With a Secret Password

The U.S. Justice Department is prosecuting Samuel Tunick, an Atlanta resident, for allegedly giving border agents a password that erased everything on his phone during a search at Hartsfield-Jackson airport. The case, reported by TechCrunch on July 24, 2026, is believed to be the first in the United States where federal prosecutors have charged someone for erasing data using a duress password built into a phone's operating system.

A duress password is a special code you can set up on some phones. If someone forces you to hand over your password, you give them the duress one instead. The phone then deletes all its data rather than unlocking.

Tunick was returning from overseas on January 24, 2025, when Customs and Border Protection pulled him into a secondary inspection. His phone was running GrapheneOS, a privacy-focused version of Android that includes a duress password feature. When border agents entered the passcode Tunick provided, the screen went blank, flashed several times, and the phone appeared to restart.

The indictment, which contains a typo reading "Untied States Code" instead of "United States Code," charges Tunick under 18 U.S.C. § 2232, a law that makes it illegal to knowingly destroy property to prevent authorities from seizing it. The indictment accuses Tunick of providing a passcode that caused the phone to "delete the digital contents" before the device could be seized. Tunick has pleaded not guilty.

Border agents said they did not need a warrant to search the phone because Tunick had not yet crossed the U.S. border. At ports of entry, CBP has broader search authority than police have during a regular domestic search. This is known as the border search exception to the Fourth Amendment, and it puts the Tunick case within a long-running tension between border search authority and digital privacy.

Tunick's defense attorney, Matthew Dodge, an assistant federal public defender, has filed a motion to suppress the evidence, arguing the detention and seizure were unlawful. The motion alleges that Tunick was repeatedly denied access to an attorney and was not informed of his legal rights during secondary inspection. It further accuses the government of demanding access to his phone under the pretext of searching for child exploitation imagery without evidence to justify its suspicion. The motion argues the government was instead investigating Tunick over his association with the Defend the Atlanta Forest movement, which opposes the "Cop City" law enforcement training campus.

The first court hearing in the case was held on Monday, July 20, 2026. The Guardian had covered the case earlier in the same week, and the Associated Press also published a wire story on July 24.

GrapheneOS's duress feature is not unique in concept. Several privacy-focused mobile platforms and applications have offered similar functionality, though implementation details vary. The feature is designed for situations where a user is compelled under threat to surrender a passcode. Entering the duress PIN or password triggers irreversible data deletion rather than unlocking the device. The technology sits at the intersection of legitimate privacy protection and legal obligations to comply with law enforcement, and the Tunick case is the first known U.S. prosecution to test that intersection in federal court.

The broader context here is that the law used in this case, 18 U.S.C. § 2232, was written to address physical destruction of property, not the automated, software-triggered erasure of data on a device the user owns. Whether courts will treat a duress-password wipe the same as, say, burning documents to prevent their seizure is an open legal question. The outcome will shape how both privacy software developers and law enforcement approach device searches at the border going forward.

The motion to suppress raises a separate set of concerns that go beyond the duress-password charge. If the court finds that CBP denied Tunick counsel and conducted a pretextual search, the suppression of evidence could follow regardless of the wipe. The government's justification for the search, and whether it can establish individualized suspicion, will likely be contested.

For the privacy and security community, the case arrives during heightened attention to both mobile device security and government surveillance practices. GrapheneOS has gained visibility as a hardened Android alternative, and a prosecution targeting its duress feature will draw scrutiny from developers, civil liberties groups, and anyone who configures devices for high-risk users. The legal precedent set here, if the case proceeds to trial, could influence how duress features are designed, documented, and deployed.

In my view, the core tension is not going away. Devices will continue to offer stronger self-protective capabilities, and border authorities will continue to assert broad search powers. What the Tunick case determines is whether using a built-in security feature to protect data from seizure counts as a federal crime. That is a consequential question, and one worth watching closely.