GrapheneOS’s Duress Password Was Meant to Protect You at the Border. In Atlanta, It’s Now a Federal Charge

Illustration of a smartphone glowing purple in a dark airport corridor, representing the GrapheneOS duress password border search case
Grapheneos duress password: dangerous 2026 warning 1

Date Published: 28 July 2026 Author: Baizaar Lee Last Updated: 28 July 2026

TL;DR:

The GrapheneOS duress password is meant to protect you at the border, not put you in front of a judge. For Samuel Tunick, it did both. His phone wiped itself during a Customs and Border Protection search at Atlanta’s Hartsfield-Jackson airport in January 2025, and the wipe was his duress password doing exactly what it’s built to do. Federal prosecutors see it differently. He’s now charged under 18 U.S.C. § 2232(a), destruction of property to prevent seizure, not obstruction of justice, and he’s pleaded not guilty. It’s believed to be the first US prosecution built around a phone’s duress feature, and however it ends, the ruling will shape how border agents treat privacy tools for years.

BAIZAAR may earn a commission if you buy through links on this page, at no extra cost to you.


What Actually Happened at Hartsfield-Jackson

Tunick landed back in the US on 24 January 2025, home from a trip to the Dominican Republic. CBP pulled him into secondary inspection at Hartsfield-Jackson, the room you get sent to when an officer wants a longer look at you before you’re waved through.

They asked for his phone. He gave them a passcode. Agents typed it in themselves, according to court filings reported by TechCrunch, and the screen went dark, flickered a couple of times, then came back up at the setup screen. Wiped. They kept the phone anyway, then told him he was free to enter the country.

That warrant detail matters more than it looks like it should. CBP’s position was that Tunick hadn’t technically “entered” the US yet when they searched his phone, so no warrant was needed. That’s the border search exception, and the government has leaned on it for years at ports of entry.

Then nothing happened publicly for a year and a half. The week of 20 July 2026, the case had its first hearing, and the theory prosecutors were building became public: Tunick had knowingly destroyed evidence to keep the government from taking it. He’s pleaded not guilty. His lawyers have filed a motion to suppress, arguing the stop itself was unlawful.

How the GrapheneOS Duress Password Actually Works

GrapheneOS is a hardened Android build, Pixel-only, no Google Play Services unless you choose to sandbox it back in. It’s the kind of operating system built for people who assume the worst about what’s watching them. One of its more startling features is the GrapheneOS duress password, documented plainly on the project’s own site. Not a back-alley trick. A published feature.

Here’s the mechanism behind the GrapheneOS duress password. You set a real unlock code, then a second one, distinct from the first. Enter the real one, the phone behaves like any other phone. Enter the second one instead, and it wipes its own encryption keys and any installed eSIMs, instantly, with no confirmation screen and nothing beforehand that would tip off whoever is watching you type it.

The threat model is blunt, and honestly reasonable: someone with physical access to you and your phone, demanding you open it. A border officer. A partner who shouldn’t be reading your messages. A thief who has worked out that coercion beats guesswork. Hand over the duress code, the phone dies, the demand fails.

Here’s the bit that makes the Tunick case genuinely odd, though. Agents typed the GrapheneOS duress password in themselves; Tunick simply handed it over. He didn’t secretly trigger a hidden wipe mid-conversation while pretending to comply. The government’s own hands did the unlocking, or the wiping, whichever you want to call it. That’s a stranger fact pattern than a standard obstruction case, and it’s arguably the whole argument here.

Why the Cop City Connection Matters

Per Tunick’s motion to suppress, agents said they were searching for child exploitation imagery. No supporting evidence has surfaced in the public filings so far. His lawyers argue the real target was his association with Defend the Atlanta Forest, the movement opposing the city’s planned police and fire training complex, widely known as “Cop City.”

TechSpot’s reporting adds something uglier: agents had reportedly circulated Tunick’s name and photo internally beforehand, flagging suspected involvement in the anti-Cop City movement rather than anything to do with child exploitation material.

None of this is proven. It’s an allegation in a motion, not a finding of fact. But it’s the backdrop the destruction-of-property charge sits against, and it explains why privacy and civil liberties groups are watching this one more closely than an ordinary phone search gone sideways.

Tunick isn’t charged under the statute most people assume applies here. That would be 18 U.S.C. § 1519, the Sarbanes-Oxley obstruction law, maximum 20 years, the one that tends to get cited whenever “evidence destruction” makes headlines. He’s actually charged under 18 U.S.C. § 2232(a), a narrower statute covering the destruction of property to prevent a lawful government seizure. Maximum penalty: a fine, up to five years in prison, or both.

It’s rare. Matthew Dodge, an assistant federal public defender on Tunick’s team, told TechCrunch it was unusual to see this particular statute in an indictment at all.

Security researchers agree the underlying theory itself is new. Runa Sandvik, founder of the security consultancy Granitt, told TechCrunch she’d never seen a case built this way, and added that it’s “better to not have that data on you when you cross certain borders.” Bill Budington at the Electronic Frontier Foundation said much the same.

Prosecutors don’t have to prove Tunick meant to trigger the wipe rather than fumble his real PIN under pressure. They only have to show he knowingly took an action that destroyed property the government had a right to seize. Whether a pre-configured, openly documented privacy feature counts as “knowing destruction” in that sense, particularly one the government’s own agents activated, is now a question for a judge. Don’t expect an answer before autumn 2026 at the earliest.

What This Means If You Rely on the GrapheneOS Duress Password

Nothing about this case makes duress passwords illegal to install or use. What it tests is narrower: whether triggering one during an active federal search can be charged as destruction of property, deliberate or not.

It’s also not quite the Fifth Amendment fight you might expect. Tunick wasn’t refusing to hand over a passcode, so the familiar argument about compelling someone to reveal a PIN doesn’t really apply here. The stranger question is whether a code that destroys data, instead of revealing it, becomes a crime once you’ve handed it over voluntarily.

Border device searches have been climbing for years, a trend TechCrunch has tracked separately, and CBP’s warrantless search authority applies to citizens returning home, not only to visitors. Sandvik’s advice was plain enough: travel with less sensitive data on the device to begin with, and pull down what you actually need once you’ve landed.

Which is really where the limits of any wipe start to show. The GrapheneOS duress password only touches what’s stored on the handset itself. Your carrier’s call logs, SMS metadata and cell-tower records live somewhere else entirely and don’t care what happens to the phone. Cloud backups are the same story. Anything already synced to Google Photos or a general cloud drive survives the wipe untouched.

If the plan is to keep sensitive material off the device and pull it down only when it’s needed, that’s really a cloud storage decision more than a phone-settings one. We’ve covered running Proton Drive from the command line before, which is one way to keep files encrypted before they ever reach a server. Worth a look if a wiped phone is meant to be a clean slate rather than a starting point for recovery. For the wider picture on where zero-knowledge storage fits against bulkier options, our Proton Drive vs pCloud comparison lays out the trade-offs properly.

Limitations Worth Knowing

The GrapheneOS duress password only wipes what’s local. Cloud backups, carrier records, anything synced through a non-FOSS app you’ve sandboxed in, none of it goes anywhere.

It also asks a lot of you under pressure: remembering two codes correctly while someone is standing over you wanting one of them. Get it wrong during ordinary use, through habit or tiredness or whatever, and there’s no undo. That’s the design, not a flaw in it. Still worth saying plainly that “irreversible” cuts both ways.

Device support shifts too. As of 2026, official GrapheneOS support runs roughly from the Pixel 6 series through the newly added Pixel 10 line, because the security model depends on a relockable bootloader that, right now, only Pixels offer. Check GrapheneOS’s install page before assuming an older or newer model qualifies. That list moves.

GrapheneOS Duress Password (FAQ)

What Is the GrapheneOS Duress Password, and How Does It Relate to the Tunick Case?

The GrapheneOS duress password is a secondary PIN that wipes the device’s encryption keys the moment it’s entered instead of the real unlock code. Tunick was running GrapheneOS on his Pixel when the feature triggered during a CBP search at Hartsfield-Jackson in January 2025, and prosecutors are now treating that wipe as a federal offence.

Can you be charged for using a duress PIN during a border search?

Federal prosecutors are currently arguing yes, at least in this case. Tunick has been charged under 18 U.S.C. § 2232(a), destruction of property to prevent seizure. It’s believed to be the first US prosecution of its kind. He’s pleaded not guilty, and no court has ruled yet on whether the charge holds up.

What statute is Tunick actually charged under, and what’s the maximum penalty?

18 U.S.C. § 2232(a), not the obstruction-of-justice statute some early coverage implied. The maximum penalty is a fine, up to five years in prison, or both, well short of the 20-year exposure under Sarbanes-Oxley obstruction charges.

Does the duress password wipe cloud backups or carrier metadata too?

No. It only erases what’s stored locally on the device. Cloud-synced photos and messages, along with your carrier’s call logs and location records, are untouched and can still reach investigators through other channels.

Which phones currently support GrapheneOS?

Official support currently runs from the Pixel 6 series through the newly supported Pixel 10 line. GrapheneOS’s security model depends on hardware only Pixels currently offer, so check their install documentation before assuming your model qualifies.

Has Samuel Tunick been convicted?

No. He’s pleaded not guilty, his lawyers have a suppression motion pending, and a ruling isn’t expected before autumn 2026 at the earliest.


Hi 👋 welcome to BAIZAAR!!

Sign up to receive awesome content in your inbox, every month.

We don’t spam! Read our privacy policy for more info.

Hi 👋 welcome to BAIZAAR!!

Sign up to receive awesome content in your inbox, every month.

We don’t spam! Read our privacy policy for more info.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top