GrapheneOS's duress password is getting its first legal test
A US prosecution involving a GrapheneOS duress password reached its first court hearing on July 20, bringing fresh attention to a case that began more than a year ago. As TechCrunch reported on July 24, federal prosecutors have charged Atlanta resident Samuel Tunick with destroying data to prevent the government from taking it into custody.
The underlying airport encounter occurred on January 24, 2025. Tunick was indicted in November 2025, pleaded not guilty, and filed a motion to suppress the evidence in March 2026. His attorneys argue that Customs and Border Protection unlawfully detained him and seized his phone as he returned to the United States. The government says he supplied a passcode that caused the contents of his Google Pixel to be deleted before agents seized it.
Tunick's attorneys confirmed that the phone ran GrapheneOS, a security-focused Android operating system. Bill Budington of the Electronic Frontier Foundation and security consultant Runa Sandvik told TechCrunch that they had not seen a similar case involving a duress password.
A duress password does not unlock the phone
GrapheneOS lets an owner configure a second PIN and password alongside the real device credentials. Entering either duress credential anywhere the operating system requests authentication triggers an irreversible wipe, including installed eSIMs. According to the GrapheneOS documentation, the process does not require a reboot and cannot be interrupted.
This is not a decoy screen or another user profile. The credential is meant for a situation where someone is being forced to unlock the device. GrapheneOS describes the resulting wipe as irreversible; the practical result is that the information is no longer accessible.
According to the defense motion described by TechCrunch, Tunick did not type the passcode himself. He provided it to CBP officers, who entered it. The phone's screen then went blank, flashed several times, and appeared to restart.
That detail does not settle the case, but it makes the issue more complicated than someone simply pressing a delete button while agents approached.
The prosecution depends on whether the seizure was lawful
Prosecutors charged Tunick under 18 U.S.C. Section 2232(a). The statute covers knowingly destroying, damaging, disposing of, transferring, or otherwise taking action against property to prevent or impair the government's lawful authority to take it into custody. A conviction can carry up to five years in prison.
The word "lawful" is doing important work here.
The defense's argument is not only that agents lacked a warrant. According to court testimony reported by TechSpot, federal agents had circulated Tunick's name and photograph internally, flagging him for "suspected terrorism activities" because of his alleged association with Defend the Atlanta Forest, the movement opposing Atlanta's "Cop City" police training facility. His attorneys allege that CBP presented the detention as a search for child exploitation imagery without providing evidence for that suspicion, while actually using it to investigate his association with the protest movement.
Tunick's attorneys also say he was taken into secondary inspection, repeatedly denied access to an attorney, and told that agents did not need a warrant because he had not yet been admitted across the border. They have asked the court to suppress evidence and statements from the encounter. At the hearing, government attorneys characterized it as a routine airport inspection and maintained that agents had lawful authority to search and seize the device. Tunick has pleaded not guilty, and the court has not resolved those competing claims.
The case therefore concerns more than whether a particular Android feature erased data. It asks whether using, or supplying, a duress credential can become a criminal act when authorities are attempting to take a device, and how that depends on the legality of the search itself.
Security features can acquire consequences outside their threat model
The response on Hacker News and in Reddit's technology community has largely focused on warrantless phone searches and the right to erase one's own data. A more practical concern is what the case means for security tools built for coercive situations.
A duress password is technically simple from the user's perspective. Its legal context is not. The same feature may be used during a robbery, domestic abuse, an unlawful seizure, or a search a court later finds valid. Software cannot determine which situation the owner is in when the credential is entered.
That does not make the feature inherently unlawful, and prosecutors have charged the user rather than GrapheneOS. It does show the limit of treating device security as a purely technical problem. Encryption can make data unrecoverable. It cannot decide whether a court will view that outcome as protection, obstruction, or something in between.
The next important development will be the court's ruling on the motion to suppress, which TechSpot reports is not expected before late October. Until then, the case remains an allegation, not a legal verdict on GrapheneOS or duress passwords generally.
Member discussion