Skip to content
AIBites
Security & Privacy

US Charges American Sam Tunick for Wiping Phone at Border

The US government is charging an American citizen for allegedly wiping his phone at the border — a case legal observers describe as an unusually novel

By AIBites Editorial Team13 min read

Researched and drafted with AI assistance, then screened by automated editorial checks before publishing. How we work.

A crowd gathers in Sacramento, California to protest for defending democracy with signs and American flags.

The US government is charging an American citizen for allegedly wiping his phone at the border — a case legal observers describe as an unusually novel federal prosecution. It turns on a privacy feature called a "duress password," built into the GrapheneOS mobile operating system, and it raises urgent questions about digital rights, border search powers, and whether protecting your own data can be treated as a federal crime. For anyone charging an American phone in Europe or preparing a travel device before an international trip, this case carries immediate practical implications that reach well beyond one activist's legal battle.

What Happened at Atlanta's Hartsfield-Jackson Airport

On January 24, 2025, Samuel Tunick, an Atlanta resident and American citizen, was pulled into secondary inspection at Hartsfield-Jackson Atlanta International Airport after returning from overseas, according to reporting by The Verge. Federal border agents detained him, and according to court filings described in that reporting, Tunick's defense says he was denied access to an attorney during the encounter.

Agents demanded access to his smartphone — a device running GrapheneOS, a privacy-hardened custom Android operating system built for Google Pixel phones. Tunick handed over what he said was the passcode. When agents entered it, the device restarted and its contents were wiped. That sequence of events is now the centerpiece of a federal criminal prosecution.

Agents let Tunick enter the country. Federal prosecutors later charged him under what The Verge describes as "a little-known and rarely-used statute that makes it illegal to destroy or damage property to stop authorities from seizing it." The specific section number has not been confirmed in the primary reporting we reviewed; some accounts characterize the charge simply as "destruction of evidence." We are not attributing a particular US Code citation here because the public reporting does not establish one with certainty.

Who Is Sam Tunick and Why Was He Stopped?

Tunick's lawyers argue the entire encounter was a pretext. He is publicly associated with Atlanta's "Stop Cop City" movement, which opposes the construction of a large law enforcement training facility on forested land near Atlanta. That movement — and the broader network of activists and the Atlanta Solidarity Fund connected to it — has drawn sustained federal and state attention in recent years, with activists facing a range of charges tied to protest and organizing activity.

According to court filings described in The Verge's reporting, agents said they were searching for child exploitation imagery on Tunick's phone — a justification his defense team calls a pretext for "a fishing expedition into Mr Tunick's connections" to the movement. His lawyers filed a motion to suppress the evidence gathered during the encounter, arguing the detention and device seizure were unlawful from the start.

The government's counter-argument is procedurally significant: agents maintain they needed no warrant because the search occurred at the border, before Tunick was formally admitted to the United States. Under long-standing legal doctrine, the border and its functional equivalents — including international arrival areas at airports — sit outside the full protection of the Fourth Amendment, giving agents broad authority to search travelers and their belongings without a warrant or even probable cause.

As of publication, no ruling on the motion to suppress has been publicly reported, and no precise hearing date has been confirmed.

What Is a Duress Password — and How Does GrapheneOS Enable It?

At the technical heart of this case is a feature most smartphone users have never heard of: the duress password. GrapheneOS, a custom Android distribution engineered for maximum privacy and security, lets users configure a secondary PIN or passphrase that is entirely separate from their normal unlock credential.

When someone enters this duress credential instead of the real one, the device does not unlock. Instead, per GrapheneOS's own documentation, it triggers an irreversible wipe of the device's encryption keys and data (and deletes eSIMs) before rebooting — rendering the stored data unrecoverable. The design intent is to give people in coercive situations — activists, journalists, dissidents, survivors of domestic abuse — a way to protect sensitive information when forced to hand over a passcode under threat, hence the name.

Tunick's phone was running GrapheneOS. The prosecution's theory, as described in the reporting, is that Tunick knowingly gave agents the duress password rather than the real unlock code, intending to trigger the wipe and destroy potential evidence. From a purely observational standpoint, an agent watching the sequence — a passcode entered, then a restart — could not readily distinguish a failed legitimate unlock attempt from a deliberate duress wipe without forensic access to the now-wiped hardware.

Hands wiping a smartphone with a cloth in an organized workspace. Emphasizes hygiene and device care.

The case drew immediate attention from privacy and security communities online, where many commenters framed the outcome as the tool working exactly as intended — a reaction that captures the tension between a feature functioning precisely as designed and the legal jeopardy that working-as-designed appears to have created for its user.

The Verge's reporting characterizes the statute being used against Tunick as little-known and rarely used — a characterization that underscores how novel this prosecution is. Federal law has long made it a crime to destroy property to obstruct a lawful seizure, but applying that idea to the act of triggering a built-in security feature on a personal computing device is an almost entirely untested legal theory.

The implications of the government's position are potentially sweeping. If entering a passcode — even a secondary one — that results in a data wipe can constitute criminal destruction of property, then a wide range of ordinary privacy practices could theoretically be exposed to similar arguments at the border:

  • Using a device configured to wipe after a set number of failed passcode attempts (a built-in option on iOS)
  • Running any operating system with a factory-reset-on-failure feature enabled
  • Refusing to provide a passcode at all (already a contested area of Fifth Amendment law)
  • Enabling remote-wipe features such as Apple's Find My or Google's Find My Device before a border crossing, where activation could later be characterized as premeditated destruction
  • Using full-disk encryption that renders a device irreversibly inaccessible after repeated wrong entries

Legal scholars and civil liberties advocates have long warned that the border exception to Fourth Amendment protections — originally designed for physical customs inspections of luggage and cargo — has been stretched far beyond its original scope in the digital era. A modern smartphone carries not just personal communications but financial records, medical histories, source code repositories, journalistic notes, attorney-client privileged material, API credentials, and access tokens for production infrastructure. Courts have been slowly grappling with this reality, and the Tunick case could sharpen that reckoning.

Expert Guidance: Better Not to Carry the Data at All

Security professionals who work with journalists and activists on operational security have long anticipated a scenario like this one, even before a documented prosecution existed. The consistent guidance from that community is that authorities may argue a traveler knowingly destroyed data — so the most defensible posture is not to have sensitive data on you when you cross certain borders in the first place.

The safest approach the security community broadly recommends is not to rely on any duress mechanism at all, but to travel with a clean device and download whatever data you need only after you arrive at your destination.

That advice points to what the security community now broadly recommends as the safest approach: travel with a clean device. Rather than relying on any duress mechanism, the most legally defensible strategy is simply not to carry sensitive data across the border at all. That applies equally to developers carrying SSH keys and API tokens, journalists holding source communications, lawyers transporting privileged documents, and activists maintaining organizer contact lists. The phone you bring to the border is the phone the government can demand access to — and, as this case now shows, the phone whose security features can become the basis of a criminal charge.

What This Means for Developers, Journalists, and Privacy-Conscious Travelers

For the technically sophisticated reader, the Tunick case is a notable moment regardless of how the court ultimately rules. It illustrates that using privacy-hardening tools — long considered a personal choice well within legal bounds — could itself become the basis for a federal criminal charge if prosecutors decide the outcome of those tools constitutes intentional evidence destruction.

Practical Threat Model: What Has Changed

Under the current federal administration, border scrutiny of returning travelers — including American citizens — has drawn increasing scrutiny and reporting, including accounts of lengthy secondary inspections, demands to review social media accounts, and device seizures. Against that backdrop, the Tunick prosecution signals that federal prosecutors may be willing to test aggressive new legal theories around digital privacy at the border. The table below maps the risk landscape as it currently stands:

Approach Privacy Protection Legal Risk at US Border Recommended?
Standard smartphone, data intact Low Low — data is immediately accessible to agents Risky for anyone carrying sensitive data
GrapheneOS with duress password High Elevated — now the subject of a federal prosecution per the Tunick case Legally contested; use with full awareness of risk
Travel with a wiped or purpose-built travel device High Very low — nothing to seize or destroy Yes — currently the expert consensus recommendation
Remote wipe triggered before border crossing High Lower than triggering at the border, but factual circumstances matter Better than duress password; coordinate with legal counsel
Full-disk encryption, refuse to provide passcode High Medium — Fifth Amendment compelled-decryption law remains unsettled in circuit courts Legally complex; outcome varies by jurisdiction

Note: A "remote wipe triggered after crossing" option is omitted here because a device already in agents' physical possession at the time of a remote wipe command would likely carry similar or greater legal risk than the duress password scenario — and in practice, agents can place devices in Faraday bags to block remote wipe signals entirely.

For Developers Specifically

Developers crossing borders often carry credentials, SSH keys, proprietary source code, environment configuration files, and live access tokens for production environments. An agent who gains access to a development device could potentially pivot to cloud infrastructure, internal code repositories, or client systems — a data breach scenario that most corporate security policies don't contemplate under the heading of "border search." The Tunick case is a forcing function for security and engineering teams to build explicit travel policies around device hygiene, pre-travel credential rotation, and the use of loaner or travel-specific hardware that is provisioned clean for each trip and re-imaged on return.

Bronze equestrian statue against the sky in Chinon, France.

This concern is part of a broader and accelerating wave of digital security challenges the industry is still adapting to — from unexpected account access vulnerabilities to questions about biometric data and identity verification at sensitive touchpoints.

A Brief Note on Charging American Devices Internationally

Travelers who cross borders with US-purchased smartphones and laptops face a second, lower-stakes but practical concern: charging American phones and iPhones in Europe and other regions. The US uses Type A/B plugs and 120V power, while most of Europe runs on Type C/E/F plugs and 220–240V. Modern smartphones and laptops are almost universally dual-voltage (100–240V), so a plug adapter — not a voltage converter — is typically all you need. Universal travel adapters are inexpensive and widely available. It's worth handling this as part of any device-preparation workflow before international travel, alongside the more consequential security precautions described above: wipe sensitive data, rotate credentials, and carry only what you actually need.

The Broader Context: Border Powers in the Digital Age

The legal doctrine underpinning border searches was not written with the smartphone in mind. Courts have held for decades that the government's interest in controlling who and what enters the country justifies a relaxed standard at the border — no warrant required, no probable cause needed, minimal suspicion sufficient. That made reasonable sense when "border search" meant inspecting a suitcase for contraband or undeclared currency.

Digital devices are categorically different in scale and intimacy. The Supreme Court acknowledged as much in Riley v. California (2014), ruling unanimously that police must generally obtain a warrant before searching a cell phone seized incident to arrest. Writing for the Court, Chief Justice Roberts observed that modern phones hold "the privacies of life" and are "not just another technological convenience" — a far cry from a pocketful of cigarettes or a hidden compartment in a car door. But Riley applies to domestic law enforcement encounters, not to border agents operating under the border exception doctrine. That gap — between Riley's logic and the border exception's permissiveness — has never been definitively resolved, and the Tunick case may push courts to engage with it more directly.

Meanwhile, the government's position here — that the search occurred at the border, before full admission to the country — has real judicial precedent behind it. International arrivals areas have consistently been upheld as legitimate territory for expansive government search authority. That doctrine is now being applied not to a bag of undeclared cash or a piece of agricultural contraband, but to the act of entering a passcode that triggered a device's own designed-in security response.

Civil liberties organizations including the Electronic Frontier Foundation (EFF) and the American Civil Liberties Union (ACLU) have both published guidance on border device searches in recent years. It would be reasonable to expect groups like these to monitor cases of this kind, though no formal involvement in the Tunick proceedings has been publicly confirmed as of this writing.


Key Takeaways

  • Sam Tunick, an American citizen and activist associated with Atlanta's "Stop Cop City" movement, faces federal criminal charges for allegedly triggering a GrapheneOS duress password to wipe his phone when border agents demanded access at Hartsfield-Jackson airport on January 24, 2025.
  • The charge is brought under what The Verge describes as a little-known, rarely-used federal statute that makes it illegal to destroy or damage property to prevent its seizure; the exact US Code section has not been confirmed in the public reporting we reviewed.
  • Tunick's defense argues the search was unlawful from the start: conducted without a warrant and premised on a pretext (child exploitation imagery) that his lawyers describe as a "fishing expedition" into his political associations.
  • A duress password is a GrapheneOS feature that irreversibly wipes a device's data when a specific secondary passcode is deliberately entered — an intentional design for users facing coercion.
  • The security community's consistent guidance is unambiguous: do not carry sensitive data across the border at all. Travel with a clean device; retrieve what you need after arrival.
  • The remote-wipe-after-seizure approach is less viable than commonly assumed — agents routinely use Faraday bags to block wireless signals the moment a device is confiscated.
  • The case raises unresolved constitutional questions about the scope of Fourth Amendment protections at the border in the smartphone era, and the gap between Riley v. California (2014) and existing border-exception doctrine.
  • The Atlanta federal court has yet to publicly rule on the motion to suppress evidence; the outcome will shape both this prosecution and the broader legal landscape for border device searches.
  • Developers, journalists, lawyers, and activists should audit their device and credential travel policies — including adopting travel-specific hardware, pre-trip credential rotation, and explicit data-minimization practices before any international crossing.

What Comes Next

The immediate legal battleground is the motion to suppress filed by Tunick's defense team. If the court finds that the initial detention was unlawful — whether for lack of articulable suspicion, denial of counsel, or another procedural defect — the evidence underpinning the charge could be excluded, potentially collapsing the prosecution before trial. If the motion fails, the case moves to the question of whether triggering a built-in device security feature meets the legal threshold for "knowingly destroying property" under federal law.

Either outcome will reverberate well beyond this single defendant. A conviction would place a legal cloud over any traveler who uses privacy-hardening operating systems or enables automatic data-destruction features — potentially chilling legitimate security practices relied upon by human rights workers, investigative journalists, corporate security teams, and software developers worldwide. An acquittal, a dismissal on suppression grounds, or an appellate ruling that narrows the government's border-search authority in the digital context would push back on what critics describe as an expansion of federal power at the expense of the very people those powers nominally protect.

Organizations like the EFF and ACLU, which have long litigated the outer edges of border search authority, could be potential participants in any appeal. If the case reaches a federal circuit court — or ultimately the Supreme Court — it could sharpen the question Riley v. California left open: does the border exception still make sense when the "luggage" being searched contains the entirety of a person's digital life?

For anyone who crosses international borders with a device carrying sensitive information, the message from this prosecution is already clear, regardless of the verdict: the assumption that privacy tools sit in a legal vacuum at the border no longer holds. The government has now demonstrated both the willingness and a legal theory to treat a security feature as a crime. Plan accordingly — and watch this case closely.

Topics

Sources

Comments(0)

No comments yet. Be the first to share your thoughts.

Join the conversation

Your email stays private and comments are reviewed before appearing.

Comments are moderated before appearing.

0/2000
View all