When Samuel Tunick handed border agents a passcode at Atlanta's Hartsfield-Jackson airport in January 2025, the screen went blank and the phone wiped itself. The government's response has produced what appears to be the first prosecution of its kind in the country, and a case that sits on top of several unsettled areas of law.

What happened

Tunick, an Atlanta resident and U.S. citizen, was returning from the Dominican Republic on January 24, 2025, when Customs and Border Protection pulled him into secondary inspection. Agents questioned him about child exploitation images and asked for the passcode to his Google Pixel, which was running GrapheneOS, a privacy-hardened Android fork. According to prosecutors, the code he provided was a "duress password" — a built-in GrapheneOS feature that irreversibly wipes the device, and any installed eSIMs, when entered instead of the normal credential. By most accounts, it was the agents themselves who typed the code that triggered the wipe.

Months later, the Justice Department charged him under 18 U.S.C. § 2232(a), which carries up to five years in prison. He has pleaded not guilty and is seeking to suppress the government's evidence on the grounds that the search and seizure were unlawful. A ruling wasn't expected before the end of October.

Why this is novel

The novelty here is not one thing but a stack of them.

It appears to be the first prosecution of its kind. Multiple outlets and security experts describe this as the first known U.S. case in which federal prosecutors charged someone for triggering a software-based duress password. Bill Budington of the Electronic Frontier Foundation and Runa Sandvik, founder of the security firm Granitt, both told TechCrunch they had not seen charges brought this way before. Sandvik said she had discussed the hypothetical with journalists and activists over the years but had never seen it actually charged — her practical takeaway being that the safer move is simply not to carry sensitive data across certain borders in the first place.

The statute is being stretched into an unfamiliar shape. Section 2232(a) makes it a crime to destroy, damage, or dispose of property "for the purpose of preventing or impairing the Government's lawful authority to take such property into its custody or control." That language was written with a very different picture in mind — someone flushing drugs, torching records, dumping contraband overboard. Applying it to a phone that erased its own data while the physical device sat in an agent's hand is, as one write-up put it, little-known and rarely used in this context. That framing invites a threshold question the statute has rarely had to answer: is the "property" here the phone (which was never destroyed) or the data (which was)? Commenters have seized on exactly this — arguing that the government had the phone the whole time and lost only the data, and that personal data may not be "property" of the kind the statute contemplates. That is an untested reading, but it is not a frivolous one.

A privacy feature is now Exhibit A. The GrapheneOS duress password is a deliberate design choice aimed at journalists, activists, and at-risk users — not a hack or a loophole. A conviction would effectively criminalize the use of a security tool that is marketed, and widely understood, as legitimate. That is why the case has drawn the concern it has: as Newsweek framed it, a successful prosecution could chill the use of tools built to protect ordinary citizens.

The legal issues, and why none of them are decided

This is the part worth dwelling on, because the case is a knot of open questions rather than a single clean dispute.

1. "Lawful authority" is written into the statute itself

Section 2232(a) doesn't just punish destroying property — it punishes destroying property to impair the government's lawful authority to seize it. As commentary at American Partisan and ZeroHedge has pointed out, that makes lawfulness an element of the offense, not merely a side issue for a suppression motion. If the seizure was unlawful, the conduct arguably falls outside the statute altogether, and there's no crime to convict on in the first place. That is a meaningfully different posture from the usual suppression fight, and it raises the stakes of the Fourth Amendment question below.

2. The border search exception is itself in flux

Courts have long recognized a "border search exception" giving officials broader search authority at ports of entry than police have in the interior. But how that doctrine applies to phones is one of the more actively contested questions in Fourth Amendment law right now.

The Supreme Court's 2014 decision in Riley v. California recognized the extraordinary privacy interests in a modern smartphone, but it was expressly limited to searches incident to arrest and did not address the border. Lower courts have been sorting out the implications ever since, and they've split:

  • The Ninth Circuit (Cotterman, 2013) and the Fourth Circuit (Kolsuz, 2018) held that forensic device searches at the border are "nonroutine" and require at least reasonable suspicion — the Ninth Circuit famously calling a forensic search "essentially a computer strip search."
  • The Eleventh Circuit — the circuit that governs Tunick's case — went the opposite way in United States v. Touset (2018), holding that no suspicion is required for device searches at the border, forensic or otherwise.

So on the raw Fourth Amendment question, Tunick is in arguably the least favorable circuit in the country: manual searches require no suspicion anywhere, and the Eleventh Circuit uniquely extends that to forensic searches too. The government has reportedly leaned further still, arguing that no warrant was needed because Tunick hadn't yet been formally admitted into the country during screening.

There's an additional complication even if a defendant wins on the Fourth Amendment. Courts generally hold that a new crime committed in reaction to an illegal search — as opposed to evidence found during one — is not suppressible. Because the alleged wiping happened in the agents' presence and in response to the demand, a suppression win might not dispose of the charge the way it normally would. This "new crime" wrinkle is why the Fourth Amendment victory the defense is chasing may be necessary but not sufficient.

3. The Fifth Amendment may be the stronger ground — and it's unsettled too

Several observers have suggested the Fifth Amendment is actually the more promising route, precisely because the act constituting the alleged offense is speaking a passcode. If that utterance was compelled while Tunick was in custody without warnings or counsel — his lawyers say agents refused him access to an attorney and never advised him of his rights — the statement itself might be suppressible.

And here's the genuinely interesting twist: the same Eleventh Circuit that is least protective on border searches is comparatively protective on compelled decryption. In its 2012 decision In re Grand Jury Subpoena Duces Tecum (the Doe case), the court held that compelling a suspect to decrypt hard drives can be testimonial and thus protected by the Fifth Amendment, and that the government's "foregone conclusion" workaround applies only when it can show with "reasonable particularity" that it already knows what it's looking for. Whether and how that reasoning maps onto a spoken passcode at a border stop — rather than a subpoena backed by a contempt order — is not something any court has squarely resolved. The compelled-decryption case law is itself fractured across federal and state courts, with different jurisdictions applying the foregone conclusion doctrine in incompatible ways.

4. The unusual fact that agents entered the code

Because the agents themselves reportedly typed the duress code, the case raises a causation-flavored question the statute has never really confronted: can you "knowingly destroy" property by handing someone else a string of characters they choose to enter? The statute requires that the defendant act "for the purpose of" impairing the seizure, so intent will be contested — but the intervening act of a government agent pressing the keys is an odd fit for a destruction statute, and there's no obvious precedent directly on point.

What to watch

The immediate milestone is the suppression ruling, which functions as a rough proxy for the whole case: if the court finds the seizure unlawful, the statute's "lawful authority" element may collapse the prosecution; if it upholds the search under the Eleventh Circuit's permissive border-search rule, the fight shifts to the Fifth Amendment and to the harder statutory questions about what counts as "property" and what counts as "destroying" it.

None of this is settled, and that's the point. The case gathers together an untested application of a niche statute, a live circuit split over phone searches at the border, an unresolved body of compelled-decryption law, and a novel factual wrinkle about who actually triggered the wipe. However it comes out, it's likely to be an early data point in an area of law that courts are only beginning to work through — and one worth watching for anyone who thinks about digital privacy, security tooling, or what happens to your rights at the border.


This post summarizes reporting and commentary from The Verge, TechCrunch, The Guardian, Newsweek, the Electronic Frontier Foundation, and legal analyses at Lawfare and elsewhere, along with the text of 18 U.S.C. § 2232(a) and the cited case law. It is general commentary, not legal advice.