Technology

US Charges American Citizen for Wiping Phone With Duress Password During Border Search

Martin HollowayPublished 5d ago5 min readBased on 6 sources
Reading level
US Charges American Citizen for Wiping Phone With Duress Password During Border Search

The US government is prosecuting American citizen Sam Tunick for allegedly giving authorities a duress password that erased his phone during a border search at Atlanta's Hartsfield-Jackson airport on January 24, 2025. The case, filed as United States v. Tunick (case number 1:25-cr-00499) in the U.S. District Court for the Northern of Georgia, Atlanta division, uses a statute that makes it illegal to destroy or damage property to stop authorities from seizing it (The Verge).

Tunick used the duress password feature of GrapheneOS, a privacy-focused operating system for phones. The feature works like a panic button: if someone forces you to unlock your device, you enter a specific alternative password instead of your real one, and the phone immediately erases all its data. It is designed for situations where a person is under coercion and would rather destroy sensitive information than hand it over.

According to a motion filed by Tunick's lawyers, federal agents refused him access to a lawyer, did not provide a warrant, and did not inform him of his legal rights during the detention. The motion argues the detention was a pretext for a fishing expedition into Tunick's connections to the Stop Cop City movement in Atlanta (The Verge). The government countered that no warrant was required because Tunick had not yet been granted permission to enter the US, pointing to the broad search authority that customs and border agents have at ports of entry.

The Guardian first brought the case to wide attention on July 23, 2026, characterizing Tunick as a "Cop City protester" in its headline (The Guardian). TechCrunch followed on July 24, 2026, and The Verge published its report on July 26, 2026, attributing its information to the motion filed by Tunick's defense team. The CourtListener docket for the case was last updated on July 17, 2026 (CourtListener).

404 Media had previously covered Tunick's initial indictment in December of the prior year, a detail surfaced by a later Gizmodo report published July 25, 2026 (Gizmodo). Marlon Kautz, a member of the Atlanta Solidarity Fund, was quoted in The Guardian's July 23 article commenting on the case.

The prosecution applies a property-destruction statute to the act of entering a credential that triggers a software-level data wipe. The duress password is a standard, built-in feature of GrapheneOS, not a custom-built tool for evading law enforcement. It functions as a deliberate, user-configured self-destruct mechanism for exactly the scenario Tunick faced. Charging its use as a crime effectively criminalizes a privacy-protective software feature operating exactly as designed.

The border search context matters here. The government's position, that no warrant was needed because Tunick had not yet been granted permission to enter the US, relies on the border search exception to the Fourth Amendment, a long-standing legal doctrine that gives customs agents wide latitude to search people and belongings at ports of entry without the usual warrant requirements. Whether a statutory destruction charge can survive when the underlying seizure lacked a warrant, and when the accused was denied counsel and Miranda warnings, is a novel legal question. The defense's motion frames the entire encounter as a pretextual detention targeting political association, which brings First Amendment concerns into what might otherwise be a straightforward property-destruction case.

This is not the first confrontation between privacy-focused technology and law enforcement's demand for access, but the specific mechanism here is unusual. A duress wipe triggered by a voluntarily provided password has not, to public knowledge, been the basis of a criminal charge before. The government is not compelling decryption or penalizing refusal to cooperate. It is charging the act of data destruction itself, using a feature whose explicit purpose is to prevent seizure of data by authorities.

In this author's view, the case turns the existence of a duress password from a security feature into potential legal liability. If entering a self-destruct credential at a border crossing is prosecuted as destruction of property, the practical effect is to neutralize the feature's utility for its intended audience: anyone who anticipates coercive search conditions. That reframing deserves close attention from the security community, not because the outcome is certain, but because it tests whether the right to privacy-protective software design holds when it directly frustrates a lawful seizure.