The U.S. government has filed charges against Sam Tunick, an American citizen, for allegedly using a “duress password” that wiped his phone when federal agents attempted to seize it at Hartsfield-Jackson Atlanta International Airport on January 24, 2025. The case marks a rare application of an obscure statute criminalizing the destruction of property to prevent law enforcement from accessing it. Tunick’s defense contends that the detention and search were unlawful, arguing that agents lacked a warrant, denied him access to a lawyer, and failed to inform him of his legal rights.
According to court filings, Tunick was stopped by Homeland Security Investigations (HSI) agents at the airport. They claimed they were investigating him for possessing child exploitation images. However, Tunick’s attorneys have called this allegation a pretext—a cover for what they describe as a “fishing expedition” into Tunick’s connections to the Stop Cop City movement, a protest against the construction of a police training facility in Atlanta. The government has countered that because Tunick had not yet been cleared to enter the United States after returning from abroad, border search authority applies, which does not require a warrant or probable cause.
How the Duress Password Worked
The technology at the center of the case is GrapheneOS, a privacy-focused operating system for smartphones. GrapheneOS allows users to set both a standard unlock password and a separate “duress” password. When the duress password is entered—either under coercion or intentionally as a fallback—the device immediately wipes all user data and resets to factory settings. This feature is designed for individuals who may be forced to unlock their phone at a border, by police, or in other high-pressure situations. Tunick allegedly gave agents the duress password, causing the phone to erase its contents before they could search it.
Prosecutors are relying on a little-known statute, 18 U.S.C. § 2232, which makes it a crime to “destroy, damage, or dispose of any property” to prevent its seizure by federal authorities. The law was originally intended to stop suspects from destroying evidence during a raid, but its use in a digital context is unprecedented. Legal scholars note that the statute does not explicitly address the act of wiping a device using a pre-programmed security feature. The government argues that by deliberately providing the duress password, Tunick intended to frustrate the seizure and therefore violated the statute.
Border Search Authority and Privacy Rights
The case has ignited debate over the scope of border search powers. Under U.S. law, officers at ports of entry have broad authority to search travelers and their belongings without a warrant. This doctrine, known as the “border search exception,” is rooted in the government’s interest in protecting national security and preventing contraband from entering the country. Courts have historically given wide latitude to these searches, even extending them to laptops and cell phones. However, the Supreme Court has not yet ruled definitively on whether the government can force a traveler to reveal a password or face penalties for refusing.
Tunick’s defense team argues that the agents exceeded their authority. They point out that Tunick is a U.S. citizen returning from abroad, not a foreign national seeking entry. The Fourth Amendment protects citizens against unreasonable searches and seizures, even at the border. While the border search exception permits routine searches, it does not authorize indefinite detention or the use of deception. According to Tunick’s lawyers, the agents told him they had a warrant, but no warrant was ever produced. They also refused his requests to speak with an attorney, which the defense characterizes as a violation of his Sixth Amendment rights.
The government counters that the border search exception is broad enough to cover the detention and search. They also note that because Tunick was technically not yet “admitted” into the United States, the usual constitutional safeguards did not apply. This argument, if accepted, could significantly expand government power at airports, allowing agents to detain returning citizens without probable cause for as long as they deem necessary.
The Pretext Allegation and Stop Cop City
The pretext argument centers on Tunick’s alleged involvement with the Stop Cop City movement. This grassroots campaign opposes the construction of a $90 million police training facility in a forested area of Atlanta. Activists have held protests, some of which turned violent, leading to arrests and allegations of police surveillance. Tunick’s attorneys claim that the child exploitation investigation is a ruse—that the real target is his political activism. They have filed a motion to suppress all evidence obtained during the seizure, arguing that the entire stop was unlawful.
In support of their motion, Tunick’s lawyers presented evidence that agents asked him questions about his participation in Stop Cop City activities before they mentioned any child exploitation allegations. The defense also notes that no child pornography was ever found—because the phone was wiped. The government has not commented on the pretext claim but has stated that the investigation into child exploitation images was ongoing and supported by information from other sources.
Implications for Digital Privacy
Civil liberties organizations have condemned the charges, warning that they set a dangerous precedent for digital privacy in the United States. Marlon Kautz of the Atlanta Solidarity Fund told reporters that “we all have a right to secure our private data against unconstitutional searches.” The case underscores the vulnerability of travelers, especially at a time when the Trump administration has intensified scrutiny at borders and airports. Returning citizens have reported being detained for hours, having their social media accounts examined, and being asked to unlock their phones—often without any suspicion of wrongdoing.
GrapheneOS developers have also weighed in, stressing that the duress password feature is a legitimate privacy tool, not a weapon to obstruct justice. They argue that users should not be punished for taking proactive steps to protect their data from overreaching authorities. The company’s co-founder has noted that the duress password is designed to be used when a person is under threat, and that forcing someone to provide a password under duress is itself a violation of the principle against self-incrimination.
Legal experts are divided. Some argue that the government has a legitimate interest in preventing suspects from destroying evidence, especially in cases involving serious crimes like child exploitation. Others counter that the government must first establish probable cause and obtain a warrant before it can demand that a device be unlocked. The Supreme Court has long held that digital data is entitled to strong Fourth Amendment protections, but the border context has historically been an exception.
The Road Ahead
Tunick’s case is now pending in federal court. A hearing on the motion to suppress evidence is expected in the coming months. The outcome could have far-reaching consequences for how the justice system balances privacy rights against law enforcement needs at the border. If the motion is granted, the charges against Tunick would likely be dismissed, as the wiped phone would be the only evidence. If the motion is denied, the case will proceed to trial, where the government will have to prove that Tunick intentionally destroyed property to prevent seizure.
Observers note that the case may also test the limits of the duress password feature. Technology companies have been reluctant to include such features due to legal risks, but GrapheneOS has championed them as essential for human rights defenders and journalists. As more people adopt privacy-enhancing tools, the legal system will be forced to confront questions that were unimaginable a decade ago. The Tunick case is just the beginning of what promises to be a long and contentious debate about the boundaries of digital autonomy and state authority.
Meanwhile, border travelers are left wondering how to protect their data. The only safe approach, many experts agree, is to not carry sensitive information when crossing the border. But for individuals like activists, reporters, and whistleblowers, that may not be an option. The law is still catching up with technology, and the outcome of this case could help shape the rules for years to come.
Source: The Verge News