NewsSecurity

GrapheneOS Duress PIN Prosecution: First US Federal Case

Federal prosecutors this week charged Atlanta resident Samuel Tunick under a rarely-invoked obstruction statute after border agents say his GrapheneOS phone wiped itself during an airport search in January 2025 — the first known US prosecution for using a built-in phone security feature to destroy data at a border crossing. Tunick, who pleaded not guilty, faces up to five years in federal prison. The case has drawn immediate attention from the Electronic Frontier Foundation and the broader security community, both of which say nothing like it has been prosecuted before.

What a GrapheneOS Duress PIN Does

GrapheneOS is a hardened, privacy-focused Android operating system that runs on Google Pixel devices. It is widely used by security researchers, journalists, and developers who need a verifiable, tamper-resistant mobile OS. One of its features is the duress PIN: a dummy unlock credential that looks identical to a normal passcode but, when entered, triggers an immediate and irreversible device wipe — including any installed eSIMs. According to the official documentation, “the wipe does not require a reboot and cannot be interrupted.” No confirmation prompt. No visible indicator. From an outside observer’s view, the screen goes blank and the device appears to restart.

That design is intentional. The feature exists for situations where you are coerced into handing over your unlock code. The person demanding your passcode cannot tell whether you entered the unlock credential, the wrong PIN, or the duress PIN. Federal agents at Hartsfield-Jackson Atlanta International Airport discovered that distinction the hard way on January 24, 2025, when Tunick provided a passcode and the screen went blank.

The Charge: A Security Feature Reframed as Obstruction

Prosecutors charged Tunick under 18 U.S.C. § 2232(a), which makes it a federal crime to “knowingly destroy, damage, waste, dispose of” property “for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody.” The penalty: up to five years in prison and fines up to $250,000. Both Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, founder of security consultancy Granitt, told TechCrunch they had never seen a similar case.

The prosecution’s theory is that Tunick knowingly deleted his phone’s digital contents to prevent government access. That argument is novel — and dangerous in scope. If a court accepts it, any auto-wipe behavior triggered during a live government search could fall under the same reasoning. iOS wipes after ten failed unlock attempts. Standard Android does the same. None of those outcomes are meaningfully different from what the DOJ is now calling obstruction. Privacy advocate Christophe Boutry put it bluntly: the prosecution “sends the message that [GrapheneOS] is criminal by default.”

Related: AI Kill Switch Act: What the $20M Fine Means for Devs

The Defense: Encryption Keys Are Not Property

Tunick’s federal public defenders filed a motion to suppress on multiple grounds. First, the search was constitutionally tainted: agents conducted custodial interrogation without Miranda warnings, denied Tunick access to an attorney after he requested one, and used the pretextual claim of a child sexual abuse material investigation to probe his alleged ties to the anti-Cop City movement. Second, and more technically interesting: the defense argues that erasing encryption keys is not destroying property. The physical hardware is intact. What was overwritten were the cryptographic keys that made data readable — a legally novel distinction courts have never ruled on.

Tunick officially denies deliberately triggering the duress PIN. A judge is expected to rule on the motion to suppress by October 2026. If the motion succeeds, the case likely collapses before trial. If it fails, the prosecution moves forward on entirely uncharted legal ground.

What Developers Should Do at Borders Now

This case underlines something security experts have recommended for years, and that the Tunick prosecution now makes urgent: do not rely on technical countermeasures during a live government search. Runa Sandvik’s advice is direct: “With a little planning ahead of time, you can always download the data you need once you get to where you’re going.” The EFF’s border search guide makes the same point — carry a clean travel device or factory-reset before crossing and restore from encrypted backup on arrival. Minimize what you carry, not how aggressively you can wipe it mid-search.

After the Tunick case, activating a duress PIN during an active government search carries legal exposure regardless of how that interaction started. The feature is not illegal to have. Using it while a federal agent is present is now a prosecutorial theory that someone will have to fight in court — and Tunick is already doing that at considerable personal cost.

Key Takeaways

  • The Tunick prosecution is the first known US case where a person faces federal charges for using a phone’s built-in security feature to wipe data during a border search — under 18 U.S.C. § 2232(a), with a five-year prison maximum.
  • The GrapheneOS duress PIN is indistinguishable from a normal PIN entry by design: immediate, irreversible, and silent. That same design is what the prosecution frames as deliberate obstruction.
  • The defense’s encryption key argument — that overwriting cryptographic material is not “destroying property” — is legally untested and could be decisive. A ruling is expected October 2026.
  • The practical takeaway for developers: travel hygiene beats technical countermeasures. Carry a clean device across borders, not a defense strategy.
ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News