Border Agents Demand Access. He Gave Them a Code That Wiped Everything. Now the Government Wants Him in Prison.

Samuel Tunick faces felony charges for using a GrapheneOS duress password that wiped his phone when border agents demanded access at Atlanta airport. His lawyers call the search a pretext to probe Cop City activism. The rare prosecution tests digital privacy rights at U.S. borders. It could reshape how travelers protect data when federal officers insist on entry to their devices.
Border Agents Demand Access. He Gave Them a Code That Wiped Everything. Now the Government Wants Him in Prison.
Written by Juan Vasquez

Samuel Tunick returned from vacation in the Dominican Republic on January 24, 2025. He stepped off the plane at Atlanta’s Hartsfield-Jackson airport expecting the usual customs routine. Federal agents had other plans.

They pulled him into secondary inspection. They asked for the passcode to his Google Pixel smartphone. Tunick gave them one. The screen went blank. The device restarted. All data was gone. The agents seized the phone anyway.

Months later the Justice Department charged him with a felony. Prosecutors say he deliberately destroyed evidence to prevent its lawful seizure. The statute they cite, 18 U.S.C. § 2232(a), is little-known and rarely used in this context. TechCrunch first reported the indictment.

This marks the first known U.S. case in which federal authorities have prosecuted someone for triggering a duress password built into phone software. The feature comes from GrapheneOS, a privacy-focused Android operating system. Tunick’s lawyers confirmed the phone ran that OS.

GrapheneOS describes the capability plainly. “GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested.” The wipe happens instantly. It cannot be interrupted. No reboot is required. The project requires users to set both a duress PIN and a duress password to avoid accidental triggers. It warns that the real unlock method always takes precedence if the codes match.

Tunick has pleaded not guilty. His federal public defenders filed a motion to suppress all evidence, including the fact of the wipe itself. They argue the entire encounter violated his constitutional rights. Agents, they say, denied him a lawyer. They gave no Miranda warnings. They offered no warrant. And the stated reason for the search, suspected child exploitation material, was a pretext.

The real target, according to the motion, was Tunick’s activism. He has ties to the movement against Atlanta’s planned public safety training center, widely known as Cop City. The facility has sparked years of protests over environmental concerns and police militarization. A hearing on the suppression motion took place in recent weeks, with more arguments expected later this year. CourtListener hosts the docket for United States v. Tunick, 1:25-cr-00499.

The government offers a different account. Tunick had not yet cleared immigration. Border agents, they contend, needed no warrant. Device searches at ports of entry carry broad latitude. Customs and Border Protection data shows these inspections have reached record highs in recent quarters, as TechCrunch detailed last year.

Yet the facts alleged in court filings raise sharp questions. Agents from the Customs and Border Protection Tactical Terrorism Response Team questioned Tunick. They focused on his connections to environmental activists. The indictment itself, obtained via DocumentCloud, accuses him of destroying property “before and during the search for and seizure of property by Customs and Border Patrol.” It does not specify what evidence the agents hoped to find.

Privacy advocates see danger. “This is a reminder that authorities may argue you knowingly destroyed data,” said Runa Sandvik, a security engineer, in comments to TechCrunch. The Electronic Frontier Foundation’s Cooper Quintin echoed the rarity of the charge. No previous federal case appears to have targeted the use of a software duress mechanism this way.

Tunick’s attorney Matthew Dodge called the statute’s application unusual. Defense filings emphasize that the phone wipe occurred only after agents demanded the code under circumstances the lawyers deem coercive. The device was seized post-wipe. Forensic examination would reveal nothing of its prior contents.

The case lands amid ongoing fights over digital privacy at the border. Federal courts have split on warrant requirements for device searches. A 2024 ruling in another matter required warrants in certain circumstances, as TechCrunch covered at the time. Citizens cannot be denied entry for refusing to unlock a phone, but devices can be held for weeks or months. Non-citizens risk visa problems.

Under the current administration, border scrutiny has intensified. Travelers report longer detentions. Social media reviews have become routine. Even U.S. citizens face pressure. Hours-long holds are not uncommon. Many security experts advise deleting sensitive data before crossing. Others recommend traveling with clean devices entirely.

But Tunick didn’t delete data in advance. He relied on a technical safeguard designed exactly for coercion. GrapheneOS built the feature for users who might face compelled disclosure. Enter the wrong code. Everything vanishes. The OS treats it as a deliberate security choice.

Critics of the prosecution worry this sets a precedent. If providing a duress code equals evidence tampering, then the feature’s utility collapses. Users might hesitate to enable it. Developers could face pressure to remove such tools. Yet supporters counter that the government cannot force citizens to hand over encryption keys or passwords without proper process, especially when the search itself lacks justification.

Marlon Kautz, with the Atlanta Solidarity Fund, spoke to The Guardian. “We all have a right to secure our private data against unconstitutional searches. And we should, especially in a time of rising authoritarianism.” His comments, published days ago, captured the activist community’s alarm. The Guardian’s story, which first tied the case explicitly to Cop City, added fresh context on Tunick’s background as a musician and organizer.

Legal observers predict a lengthy battle. The suppression motion could succeed if the judge finds the initial detention flawed. If it fails, Tunick faces trial on the destruction charge. Conviction carries prison time, though analysts on X suggest a plea to lesser penalties remains possible. One security researcher posted that precedent in the 11th Circuit favors border agents’ broad authority. Another noted the novelty gives defense counsel leverage.

Either outcome will shape policy. A win for Tunick could reinforce limits on warrantless device demands. A loss might chill the adoption of privacy tools like GrapheneOS at the border. Law enforcement already complains that encryption hinders investigations. This case hands them a new argument: some users actively destroy data rather than comply.

The phone itself sits in evidence. Its memory wiped clean. What it once held, if anything incriminating, is lost. Prosecutors must prove Tunick acted with intent to obstruct. His lawyers say he simply exercised a built-in privacy control. They insist the agents manufactured suspicion to justify a political probe.

So far the court has released Tunick on $10,000 bond. He awaits further hearings. The indictment remains sealed in parts, though key documents have leaked to public repositories. Interest on X has surged since the TechCrunch and Verge stories broke within the past week. Posts debate everything from border rights to the ethics of duress codes.

This isn’t just one man’s legal fight. It tests where physical borders end and digital ones begin. Agents stand at airports demanding entry to pocketsized vaults of personal history. Citizens push back with code. The government responds with prosecution. The rest of us watch to see which side the law ultimately favors.

And the implications stretch further. If courts bless this charge, expect more. Future travelers might disable such features before flying. Or they might refuse to provide any code at all. Both choices carry risks. Neither solves the underlying tension between security theater and personal sovereignty.

Tunick’s case, obscure today, could become precedent tomorrow. The wipe happened in seconds. The legal fallout will last years.

Subscribe for Updates

InfoSecPro Newsletter

News and updates in information security.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us