July 27, 2026 ChainGPT

GrapheneOS Duress PIN Sparks First U.S. Indictment After Atlanta Airport Border Search

GrapheneOS Duress PIN Sparks First U.S. Indictment After Atlanta Airport Border Search
Headline: Man Charged After Using GrapheneOS “Duress” PIN at Atlanta Airport — A Test Case for Privacy Tools at the Border A Georgia man is facing federal prison time after using a privacy feature that deliberately wipes a phone when a second, “duress” passcode is entered. According to federal prosecutors, Atlanta resident Samuel Tunick triggered that wipe during a warrantless border search at Hartsfield-Jackson airport on January 24, 2025, and has since been indicted under the rarely used federal statute 18 U.S.C. § 2232 — which criminalizes knowingly destroying property to keep it from being seized by authorities. How the duress PIN works The duress passcode is a built-in safety mechanism in GrapheneOS, a hardened privacy-focused version of Android developed for Google Pixel phones and widely adopted by journalists, activists, security researchers — and privacy-conscious members of the crypto community. With two codes set up, entering the usual PIN unlocks the phone normally. Entering the duress PIN performs an immediate, irreversible wipe by deleting the device’s encryption keys, leaving the phone in a factory-reset state and rendering the data unreadable. GrapheneOS added the duress PIN in June 2024 to protect people who might be compelled at gunpoint or under duress to unlock devices. The OS has previously complicated court-ordered monitoring efforts; in 2023, privacy-focused ROMs including GrapheneOS frustrated attempts to install surveillance tools even when a judge had authorized them. What happened at the airport Tunick’s lawyers say U.S. Customs and Border Protection (CBP) pulled him into secondary inspection after he returned from the Dominican Republic and demanded access to his phone without a warrant, invoking the “border search exception” that allows device inspections at the border. They also say he was denied a lawyer and not read Miranda rights. Court filings state that when Tunick supplied a code, “the screen went blank, flashed several times, and the phone appeared to restart.” Agents seized the device and released him shortly after. The indictment alleges Tunick provided “a passcode to border agents that caused the phone to delete the digital contents,” before the device was seized. Tunick has pleaded not guilty and has moved to suppress evidence; a federal judge is expected to rule on that motion no earlier than the end of October. Why it matters to the crypto and privacy communities This appears to be the first known U.S. criminal prosecution tied specifically to the use of a duress passcode. If prosecutions under 18 U.S.C. § 2232 become a roadmap for charging people who use privacy tools to protect data at the border, it could have a chilling effect on the adoption of encryption and anti-coercion features — tools many in crypto and digital-rights circles view as essential protections. Civil-liberties groups are watching. The Electronic Frontier Foundation provides public guidance on travelers’ device rights at the U.S. border as part of broader efforts to defend privacy-first tools. The case will likely be read as a test of how far government power extends when device-extraction and anti-forensics measures collide at the border. Tunick’s case will be closely followed by privacy advocates, security researchers, and anyone who relies on encryption and device-hardening tools to protect sensitive data. Read more AI-generated news on: undefined/news