
GrapheneOS, a security-focused Android operating system, includes a feature known as a duress PIN that triggers an irreversible device wipe upon entry. Designed for extreme situations where an individual is forced to unlock a phone against their will, the tool is now at the center of a landmark legal case in the United States. A man named Samuel Tunick is being prosecuted after allegedly using a duress PIN to wipe his Google Pixel phone while border agents were attempting to search it. This case marks the first known instance where the use of this privacy feature has led to criminal charges, raising profound questions about the intersection of digital security technology and law enforcement authority.
Background on GrapheneOS and the Duress PIN
GrapheneOS is an open-source Android-based operating system that prioritizes privacy and security. It offers several advanced features, including the ability to configure multiple PINs or passwords that serve different purposes. A standard PIN unlocks the device normally, while a duress PIN triggers a factory reset, wiping all data as if the phone was restored to its original state. No visual or audio feedback differentiates the duress PIN from a regular one, making it indistinguishable to anyone observing the user. The feature is marketed as a safeguard against coercion, particularly in scenarios like border crossings, encounters with law enforcement, or even robbery attempts where the device holder is compelled to provide access under threat.
While the duress PIN has been praised by privacy advocates for giving individuals control over their data in hostile situations, legal experts have long warned that its use could be interpreted as destruction of evidence or obstruction of justice. The current case appears to validate those concerns. Unlike typical encryption or password refusal, which can lead to contempt or non-compliance charges, the deliberate destruction of data via a duress PIN is viewed more severely under federal law.
The Case Against Samuel Tunick
According to reports, Samuel Tunick, an Atlanta resident, was returning from the Dominican Republic through Atlanta’s Hartsfield-Jackson airport in January 2025 when Customs and Border Protection (CBP) agents stopped him. Agents demanded access to his Google Pixel phone, stating they did not need a warrant to search it at the border. Tunick’s attorneys claim that he repeatedly requested to speak with a lawyer but was denied. After entering a PIN, the phone’s screen went blank, flashed several times, and then appeared to restart. The agents later determined that the device had been wiped clean of all contents.
The Department of Justice indicted Tunick under 18 U.S. Code § 2232, which covers the destruction of property to prevent its seizure by the government. The indictment alleges that Tunick knowingly deleted digital contents to obstruct the government’s ability to take control of the phone. This statute is typically used in cases where physical evidence like documents or hard drives are destroyed, but its application to a duress PIN on a smartphone is unprecedented.
Legal Arguments and Defense Strategy
Tunick’s legal team has moved to have the evidence thrown out, arguing that his constitutional rights were violated. They contend that agents conducted the search without reading him his Miranda rights, that he was effectively in custody without being informed of his right to silence, and that the phone search constituted an unreasonable seizure under the Fourth Amendment. Furthermore, his lawyers allege that the agents used questions about child sexual abuse material as a pretext to investigate his alleged connections to activists opposing Atlanta’s police training center, known as Cop City. This raises the possibility that the search was politically motivated rather than based on probable cause related to border security.
The defense also points out that the duress PIN was a pre-installed security feature of GrapheneOS, not an action specifically designed to thwart the search. They argue that Tunick simply used the phone as intended during a stressful encounter, and that wiping the device was a privacy-protecting measure, not a deliberate attempt to obstruct justice. The prosecution, however, asserts that the act of entering the duress PIN amounts to intentional destruction of evidence, as it prevents the government from examining the contents of the phone.
Legal Precedents and Broader Implications
This case sits at a complex intersection of digital privacy law and border search exceptions. The U.S. Supreme Court has ruled that border searches do not require a warrant, but there is ongoing debate about whether this exception extends to searches of digital devices. In the 2021 case United States v. Touset, the Fifth Circuit held that forensic searches of electronic devices at the border require reasonable suspicion, but the law remains unsettled in other circuits. Additionally, the use of a duress PIN adds a new layer of complexity: while individuals have the right to refuse to decrypt their devices (subject to certain exceptions like compelled decryption under the All Writs Act), destroying the device or its contents is a criminal offense separate from refusing to cooperate.
Digital privacy experts are watching the case closely. If the court rules that using a duress PIN during a government search is automatically a crime, it could effectively neutralize the feature for anyone who might encounter law enforcement. This could have a chilling effect on the adoption of privacy-enhancing technologies, especially among journalists, activists, and whistleblowers who face heightened risks. Conversely, if the court finds that the duress PIN was a legitimate privacy tool and not an act of obstruction, it could set a precedent that protects users who take reasonable steps to secure their data.
Technical Considerations and Challenges
The GrapheneOS duress PIN works by triggering a factory reset that overwrites the device’s encryption keys, making the data unrecoverable even through forensic tools. This differs from simply turning off the phone or enabling airplane mode, which could leave data accessible after the device is unlocked. Because the wipe is irreversible, law enforcement may view it as hostile to their investigation. However, from the user’s perspective, the duress PIN is a defensive mechanism against coercion, similar to using a self-destruct mechanism on a burner phone. The law currently has no clear framework for distinguishing between legitimate privacy protection and obstruction in such scenarios.
Another issue is the mental state required for the destruction of property charge. The prosecution must prove that Tunick acted with the specific intent to prevent the government from seizing the phone’s contents. If Tunick can show that he entered the duress PIN out of fear or habit rather than with intent to obstruct, the charge may be harder to sustain. The defense may also argue that the government’s demand for the phone’s password was itself unreasonable, and that Tunick’s response was a reasonable exercise of his right to protect his data.
Reactions from Privacy Community and Legal Scholars
The case has generated significant discussion among digital rights organizations. The Electronic Frontier Foundation (EFF) has not yet commented specifically on this case, but they have previously warned that overreaching anti-obstruction laws could criminalize routine privacy practices like deleting files or encrypting data. Other experts note that the duress PIN is not a secret or hidden feature—GrapheneOS documents it on its website and community forums—so users are aware of its consequences. However, the legal environment around its use remains ambiguous, and this prosecution serves as a cautionary tale.
University law professors who specialize in cybercrime argue that while the government has a legitimate interest in investigating crime, the use of a duress PIN should not automatically be treated as evidence tampering. They draw parallels to the case of a person who uses a shredder to destroy personal documents when the police arrive without a warrant—a scenario where the legality of the destruction depends on whether the person had a reasonable expectation of privacy and whether the police had legal authority to seize the documents. In Tunick’s case, the border search exception grants broad authority, but the agents’ conduct (denying access to an attorney, failing to read Miranda rights) may undermine the legality of the entire encounter.
What’s Next in the Proceedings
A judge is not expected to rule on the motion to suppress evidence until at least the end of October 2026. The outcome could have immediate implications for Tunick’s defense, but also for the broader legal landscape around privacy technology. If the motion is granted, the evidence from the wiped phone would be excluded, potentially weakening the prosecution’s case. If denied, the case will proceed to trial, where the central issue will be whether using a duress PIN constitutes destruction of property with the intent to hinder a seizure.
Meanwhile, GrapheneOS continues to recommend the duress PIN feature as part of its security suite, though the developers have publicly acknowledged the legal risks. They emphasize that the feature is intended for use in extreme situations involving physical threats, not as a routine method to avoid law enforcement. However, the line between these scenarios is blurry when border agents use intimidation and legal power to compel access.
Potential Fallout for Users and Manufacturers
This case may prompt smartphone manufacturers and operating system developers to reconsider how they implement emergency features. For instance, Apple and Google offer Lost Mode or wipe-from-remote features that are legally distinct because they are typically initiated by the owner after theft, not during a law enforcement encounter. The duress PIN operates in a gray area because it is triggered on-device without remote intervention. Future legal decisions could influence whether such features remain available or are modified to include disclaimers or additional user confirmations.
Another practical concern is the possibility that law enforcement agencies will begin to target users of privacy-focused operating systems like GrapheneOS, assuming that any wipe of a device during a search is intentional obstruction. This could lead to increased surveillance or profiling of individuals who use such software, creating a chilling effect on privacy-conscious behavior. Privacy advocates argue that this would be an unacceptable outcome, as the right to protect one’s data should not be contingent on the absence of government suspicion.
Comparative Analysis with International Perspectives
In other countries, the use of duress PINs or similar security measures has not yet led to prosecution, but similar debates are emerging. The European Union’s General Data Protection Regulation (GDPR) gives individuals strong rights to control their data, but national laws on obstruction of justice may still apply. In the United Kingdom, the Regulation of Investigatory Powers Act requires individuals to decrypt devices upon lawful request, but destroying data preemptively may be treated as contempt. However, no case has tested the specific scenario of a duress PIN at a border. The Tunick case could therefore serve as a reference point for legal systems worldwide as they grapple with the tension between privacy technologies and state investigative powers.
Even within the U.S., border search policies differ across ports of entry. Some CBP officers have received training on handling encrypted devices, but no standardized protocol exists for dealing with a device that self-destructs upon entry of a specific PIN. The lack of clear guidelines increases the risk of arbitrary enforcement and legal inconsistency. The outcome of this case may pressure lawmakers to clarify the rules, possibly by requiring that devices be searched only upon reasonable suspicion and by limiting the ability to charge individuals for using security features that predate the encounter.
As the legal process unfolds, both sides are gathering expert testimony. The prosecution is likely to bring forensic analysts who can explain the difference between a normal wipe and a deliberate invocation of the duress PIN. The defense will likely call privacy experts to argue that the feature is a standard privacy tool and that its use was justified under the circumstances. The judge’s decision on the suppression motion will be a critical turning point, and an appeal is almost certain regardless of the outcome.
For now, Samuel Tunick remains free on bond while his case proceeds. His legal team continues to argue that the charges represent an overreach of government authority and that the duress PIN should not be a crime. Digital privacy advocates are rallying support, framing the case as a battle for the right to secure one’s digital life against coercive demands. The outcome will undoubtedly shape the future of privacy technology and its legal treatment in the United States.
Source:Android Authority News
