A phone wiped itself during an airport search. The US made it a federal case.
United States v. Tunick is the first known prosecution over a phone's built-in duress wipe: one count, up to five years, and a security feature on trial.
The US charged a man under 18 U.S.C. 2232 after agents typed his passcode and the Pixel erased itself.
On January 24, 2025, at Hartsfield-Jackson airport in Atlanta, Customs and Border Protection agents pulled Samuel Tunick into secondary inspection on his way home from the Dominican Republic and asked for his phone's passcode. He gave them one. An agent typed it in, the screen went blank, flashed several times, the phone restarted, and the data was gone. Ten months later, federal prosecutors charged him with destroying property to prevent its seizure, a single count under 18 U.S.C. 2232 that carries up to five years. As far as anyone can tell, it is the first US federal prosecution over a phone's built-in duress feature.
Why this is news now
The case, United States v. Tunick, No. 1:25-cr-00499 in the Northern District of Georgia, was filed on November 13, 2025, but surfaced publicly only on July 24, 2026, when The Guardian and TechCrunch reported on it following a July 20 evidentiary hearing before Magistrate Judge Christopher C. Bly. The Hacker News thread hit 1,263 points within days. Tunick has pleaded not guilty, and his motion to suppress the evidence is pending, with a ruling not expected before late October 2026.
What a duress PIN actually is
GrapheneOS, the hardened Android build Tunick's Pixel ran, offers an optional feature called a duress PIN: a second passcode that, entered into any credential prompt on the device, irreversibly wipes it. That is a different mechanism from the two features people usually mix it up with. Auto-reboot periodically returns a locked phone to its hardest encryption state without deleting anything, and a failed-attempts wipe only fires after repeated wrong guesses. Here, per the court filings as reported, the code was supplied once and the agents entered it themselves.
One precision that matters: calling it a duress PIN is the government's characterization of what happened. The wipe itself is not in dispute, but the defense has not conceded that the code was a configured duress code, so careful reporting says "allegedly" and so do we.
The two theories
The prosecution's theory is that knowingly handing over a wipe-triggering code is intentional destruction of property to defeat a lawful border seizure. The defense argues the search itself was unlawful: filings say Tunick asked for a lawyer four times and was refused, was never read his rights, and that agents had circulated his name and photo hours before his flight landed, which the defense ties to his protest activism and calls pretext. Prosecutors dispute that framing. If the suppression motion succeeds, the case may end before a jury ever hears it.
What GrapheneOS says
GrapheneOS responded on July 26 with a forum post laying out its security model: the duress PIN is one optional component, while the primary protections are hardware-backed encryption and auto-reboot, which destroy nothing. The post also says, pointedly, that users should weigh the legal consequences of a duress wipe before enabling one. That is the uncomfortable center of this story for anyone who builds security features: a control that worked exactly as designed is now the act a federal charge describes. This is one indictment, not a conviction, and it may yet collapse at suppression. But designers of anti-coercion features, and the users who enable them, now have a real docket number to think about instead of a hypothetical.
Next step: read TechCrunch's report, the court docket on CourtListener, and GrapheneOS's own explanation of its protections. If you are designing security features and want the failure modes thought through, write to hello@gattyworks.com.