A Man Gave Border Agents His Phone Passcode. It Wiped Everything. Now He's Facing Federal Charges
An Atlanta activist faces federal charges after a GrapheneOS "duress password" wiped his phone during a warrantless border search at Hartsfield-Jackson airport in January 2025.
Intelligence analysis by Llama

Samuel Tunick is reportedly the first American charged under 18 U.S.C. § 2232 for using GrapheneOS's duress-passcode feature, which irreversibly wipes a Pixel phone when entered under coercion.
Imagine a secret knock on a door that, when used, makes everything inside the house vanish. Samuel gave border agents a similar secret code on his phone, and it wiped everything. Now the government says that was a crime, even though he was just trying to protect his stuff.
Analysis
A Border Search Meets a Wipe Command
According to the report, Samuel Tunick, an Atlanta-based activist, was entering the country through Hartsfield-Jackson Atlanta International Airport in January 2025 when border agents requested his phone passcode. The phone was running GrapheneOS, a hardened Android distribution available for Google Pixel devices that includes a dedicated "duress password" setting. When that alternate code is entered, the operating system destroys all encryption keys and wipes user data instantly and irreversibly, leaving the device functionally blank. Agents, expecting access, instead got an empty handset, and the encounter escalated into a federal prosecution rather than a routine secondary inspection.
The Statute Few Have Heard Of
The government has charged Tunick under 18 U.S.C. § 2232, a rarely invoked federal statute that the article frames as the legal basis for the case. The charge marks what the report calls the first known instance of an American being prosecuted federally for using a duress-passcode feature during a warrantless border search. The case sits at the intersection of two long-running legal tensions: the so-called "border search exception," which lets agents inspect devices without a warrant, and the Fourth Amendment protections users normally expect over the contents of their phones. By targeting the act of self-wiping rather than the act of refusing to unlock, prosecutors are testing a novel theory of liability that, if sustained, could recast ordinary privacy tools as obstruction.
Why the Crypto World Is Watching
For crypto holders, journalists, and developers, the practical stakes are unusually direct. Self-custody begins with private keys, and many users store seed phrases, wallet files, or exchange credentials on mobile devices. A duress feature is one of the few tools that lets a user neutralize that attack surface in seconds, without waiting for remote wipes that depend on network access or cooperation from a phone manufacturer. A conviction under § 2232 would not ban GrapheneOS, but it would functionally criminalize one of its marquee privacy guarantees for anyone crossing a U.S. border. That could push serious users toward hardware wallets, multi-device separation, or simply avoiding travel with sensitive devices, reshaping how the crypto community thinks about portable security.
The Road to October
Tunick's defense has filed a motion to suppress, and the report says a federal judge is expected to rule no earlier than the end of October. The outcome will determine whether the duress-passcode evidence survives and, by extension, whether the underlying § 2232 charge can proceed. Whatever the ruling, an appeal seems likely, and the case is positioned to become a cited reference point in future litigation over border-device searches, anti-forensics tools, and the legal line between privacy hygiene and obstruction. For now, GrapheneOS users in the United States are operating in a gray zone where a feature marketed as protection could, under the right circumstances, become the basis for federal charges.
Key points
- Samuel Tunick, an Atlanta activist, is reportedly the first American charged federally for using a GrapheneOS "duress password" during a border search.
- The incident occurred at Hartsfield-Jackson Atlanta International Airport in January 2025 during a warrantless search.
- GrapheneOS's duress feature instantly and irreversibly deletes encryption keys and user data when the alternate code is entered.
- Prosecutors are using 18 U.S.C. § 2232, a rarely cited federal statute, as the legal basis for the charge.
- A federal judge is expected to rule on the motion to suppress no earlier than the end of October.
If the judge grants the motion to suppress, the case could establish that using a duress passcode during a border search is protected self-help rather than obstruction, reinforcing the legitimacy of GrapheneOS and similar privacy tools for law-abiding users.
A conviction under § 2232 would set a precedent that privacy-preserving device features can be treated as obstruction, chilling adoption of GrapheneOS and other anti-forensics tools among U.S. travelers and pushing crypto users toward more cumbersome workarounds.



