US Citizen Charged After GrapheneOS Phone Wipes at Airport Search
Landmark Case Over GrapheneOS Duress Password at Airport
Federal prosecutors have charged Atlanta resident Sam Tunick after his GrapheneOS phone wiped itself during a search by Customs and Border Protection (CBP) agents at Hartsfield-Jackson Atlanta International Airport. The case, which had its first hearing on Monday, centers on a little-used federal statute that makes it a crime to destroy property to prevent seizure.
This is believed to be the first known prosecution in the United States targeting the use of a duress password feature built into privacy-focused mobile operating systems. The Justice Department alleges Tunick intentionally wiped his device by providing a special passcode that triggers data deletion, rather than his actual unlock code.
What Happened at the Airport
The incident occurred on January 24, 2025, when Tunick returned from a trip to the Dominican Republic. According to court testimony, federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" due to his alleged association with the movement against the Cop City police training facility.
Tunick was taken to a secondary screening room where multiple agents questioned him. His defense motion argues the interrogation focused on child sexual abuse material as a pretext for investigating his connections to the protest movement. The motion states Tunick asked four times to speak with a lawyer and was denied each time, with agents producing no warrant and not reading him his rights.
Government attorneys and agents described the encounter as a routine airport inspection. Larry Findley, a CBP officer, testified they were "looking for anything that's prohibited." During questioning, agents repeatedly asked Tunick to unlock his phone and warned they would seize it if he refused.
The Technical Details of the Wipe
When Tunick finally provided a passcode, the phone behaved unexpectedly. According to the defense motion, "the screen went blank, flashed several times, and the phone appeared to restart," resulting in data loss. The phone was running GrapheneOS, an open-source operating system designed for Google Pixel devices that prioritizes privacy and security.
GrapheneOS includes a feature allowing users to set a separate "duress password" that, when entered, wipes the device clean rather than unlocking it. This is intended to protect sensitive data in situations where a user is compelled to provide access under duress, such as at border crossings or during police encounters.
Prosecutors are treating the wipe as an intentional act to destroy evidence, charging Tunick under a federal statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it. The indictment contains a typo, referencing "Untied States Code," but the legal weight is clear.
Constitutional Rights at the Border
The case raises fundamental questions about which constitutional rights apply at US borders, including international airports. The US government has long asserted that border areas are not US soil until a person is authorized to enter, granting CBP broader search powers without warrants.
Tunick's attorneys argue the detention and seizure were unlawful, and that all evidence, including the alleged wiping of his phone, should be suppressed. They contend the search violated his Fourth Amendment rights against unreasonable searches and seizures, as well as his Fifth Amendment right to counsel.
A judge is not expected to rule on the defense motion until at least late October, leaving the legal landscape uncertain for privacy advocates and technology users alike.
Privacy Advocates Sound Alarm
Cybersecurity experts and digital rights groups have expressed concern about the prosecution's implications. "It's concerning – and sends the message that GrapheneOS is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, said he had not seen a similar case before.
Boutry noted that authorities in France and Spain have struggled to access secured devices and have treated GrapheneOS use as suspicious. In Catalonia, Spain, police have been profiling people carrying Pixel phones, assuming they have GrapheneOS installed and are drug dealers or gang members. "The main goal of the operating system is protection of privacy," Boutry said. "They're our phones and the state can't tell us how to use them."
The Cop City Connection
The case is tied to ongoing opposition to Cop City, a $109 million police training facility that opened last spring. The project has drawn activists concerned about police militarization and environmental impacts. Law enforcement officials have defended it as necessary for training and recruitment.
Previous attempts to prosecute protesters at the state level have foundered, while federal authorities have stepped in more recently, including a separate indictment announced last month. Marlon Kautz, a member of the Atlanta Solidarity Fund, said: "We all have a right to secure our private data against unconstitutional searches. And we should – especially in a time of rising authoritarianism."
What This Means for Privacy Technology
This case could set a precedent for how courts treat security features designed to protect user data under duress. If prosecutors succeed, it may chill the development and adoption of privacy-enhancing technologies, as users could face criminal liability for using tools that protect their data from government searches.
Supporters of GrapheneOS argue the tools are legitimate security protections, not evidence of criminal intent. The outcome of this case will likely influence how other jurisdictions approach similar technology, potentially reshaping the balance between privacy rights and law enforcement powers at borders and beyond.
Related News

Anthropic rewrites context engineering for Claude 5: Less rules, more judgment

Open-weight AI mirrors Kubernetes trajectory amid geopolitical tensions

UK and US AI Safety Institutes Find Kimi K3 Nears Frontier in Cyber Capabilities, But Lags in Exploit Execution

Tech Giants Warn Against Overregulation of Open-Weight AI Models

Startup Founders Urge US to Keep Chinese Open-Weight AI Accessible

