Samuel Tunick, an Atlanta resident, is facing federal prison exposure after allegedly triggering a duress passcode on his phone during a warrantless border search at Hartsfield-Jackson airport on January 24, 2025.

Prosecutors charged him under 18 U.S.C. § 2232, a rarely used federal statute that makes it illegal to knowingly destroy property in order to prevent authorities from seizing it. According to The Guardian, this is the first known criminal prosecution in the United States tied to the use of the feature through a password.
How the duress passcode works
A duress passcode is a second unlock code set up alongside a standard one. Enter the regular PIN and the phone opens as usual. Enter the duress code and the device immediately performs an irreversible wipe.
As described in the report, the wipe works by deleting the encryption keys—the mathematical locks that scramble data and keep it unreadable without the right code. Once those keys are gone, the phone is left in a blank, factory-reset state.
GrapheneOS is at the center of the case
The feature is part of GrapheneOS, a privacy-hardened version of Android built exclusively for Google Pixel phones. The operating system is commonly used by journalists, activists, and security researchers, according to the report.
Edward Snowden publicly praised the software after posting on November 4, 2022 that he used GrapheneOS every day. The ROM, the article noted, has been around for years.
GrapheneOS added the duress PIN in June 2024, with exactly this kind of situation in mind: a person being physically forced to hand over access to a device.
The operating system has surfaced in legal disputes before. Decrypt said courts in 2023 ran into the limits of smartphone monitoring when devices running privacy-focused systems, including GrapheneOS, resisted surveillance software installed under a judge’s order.
What happened at the border
Tunick’s lawyers say that is what happened here. After returning from the Dominican Republic, he was pulled into a secondary inspection room by Customs and Border Protection officers, who demanded access to his phone without a warrant.
CBP relies on the so-called border search exception to the Fourth Amendment and claims the authority to inspect devices before a traveler formally enters the country. Tunick’s attorneys also say he was denied a lawyer and was never read his Miranda rights.
According to court filings, when Tunick provided a code, “the screen went blank, flashed several times, and the phone appeared to restart.” Agents seized the device anyway and released him into the country shortly afterward.
The indictment says Tunick gave border agents “a passcode to border agents that caused the phone to delete the digital contents” before the device was seized.
What comes next
The Electronic Frontier Foundation has published a public guide on device rights at the U.S. border, part of a broader push toward privacy-first tools that, the report said, has been building for years.
Tunick has pleaded not guilty. A federal judge is expected to rule on his motion to suppress no earlier than the end of October.

