US federal prosecutors are pursuing an American traveler over a GrapheneOS duress PIN that allegedly wiped his Google Pixel while border agents were demanding access to it. Security researchers believe it is the first time anyone in the United States has been charged over a duress password built into a phone’s software, and the case has turned a privacy feature that has sat quietly in hardened Android builds for years into a live legal question.

What happened at the airport
Atlanta resident Sam Tunick was stopped for secondary inspection at Atlanta’s Hartsfield-Jackson airport on January 24, 2025, returning from a vacation in the Dominican Republic. According to court filings and testimony reported by The Guardian, a homeland security agent had circulated an email three hours before his flight landed, carrying his name and photo and stating he was under investigation for suspected terrorism activities — over his alleged association with the movement opposing the Atlanta police training center known as “Cop City.”
Agents questioned him about child sexual abuse imagery, which his federal public defenders’ motion to suppress describes as a pretext for a fishing expedition into his Cop City connections. Testimony cited by The Guardian says he asked four times to speak to a lawyer and was refused each time, that no warrant was produced, and that he was never read his rights. Agents repeatedly told him they would seize the phone if he did not unlock it. When he finally gave a passcode, the motion says, the screen went blank, flashed several times and the phone appeared to restart. They seized it anyway and let him into the country.
He was later charged under a rarely used federal statute making it a crime to destroy property to stop it being seized, and has pleaded not guilty. Nothing has been proven; the judge’s decision on the suppression motion is not expected before the end of October. Tunick’s attorneys have confirmed his phone ran GrapheneOS, the privacy-hardened Android build most commonly installed on Pixel hardware.
What a duress PIN does, and the tradeoff nobody advertises
A duress PIN is a second unlock code set alongside your real one. Enter the real code and the phone unlocks. Enter the duress code and, instead of unlocking, the device wipes itself. It exists for coercive situations — where you are being physically threatened, or pressured into handing over access you cannot practically refuse — and its value is that the person watching you type cannot tell which code you entered.
That last part is where the design runs out. A duress PIN is not a stealth feature. It leaves a very visible signal: a phone that restarts in front of the person who just asked for the code and comes back empty. That visible event is exactly what this indictment is built on. The cryptography did its job; the legal exposure is the part that does not appear in any privacy-tool feature list.
Why this matters beyond one court case
The more uncomfortable thread here is that the operating system itself is being treated as the signal. Cybersecurity and surveillance researcher Christophe Boutry, speaking to The Guardian, put it plainly:
It’s concerning – and sends the message that [GrapheneOS] is criminal by default.
— Christophe Boutry, cybersecurity and surveillance researcher
Boutry also told The Guardian that in Catalonia, Spain, police have profiled people carrying Google Pixel phones on the assumption that they are running GrapheneOS and are involved in drug or gang activity. That is a genuinely bad direction for Android: a mainstream Google phone plus a well-regarded open-source ROM read as probable cause rather than as a normal privacy choice.
Runa Sandvik, founder of the security consultancy Granitt, gave TechCrunch the practical version of the lesson:
I have not seen this before, though I’ve discussed the potential scenario with activists and journalists over the years. I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.
— Runa Sandvik, founder of Granitt, speaking to TechCrunch
That is the advice with the fewest downsides. If the data is not on the device when it is inspected, there is nothing to destroy and nothing to argue about — travel with a clean or minimally provisioned phone and restore what you need after you land. The US government has long asserted it can search and seize devices at the border without a warrant, and the Tunick case will now test how far that reaches. Until it is settled, an Android privacy feature working exactly as designed can still put its owner in front of a judge.
Sources: The Guardian, TechCrunch






