US Citizen Charged After GrapheneOS Phone Wipes During Airport Search

US Citizen Charged After GrapheneOS Phone Wipes During Airport Search

Federal prosecutors have charged Atlanta resident Sam Tunick with destroying evidence after his GrapheneOS phone wiped itself during a Customs and Border Protection search. While agents claim the device was intentionally erased to hide suspected terrorism links to the Cop City movement, the defense argues the search violated constitutional rights. This unprecedented case questions whether privacy-focused security features can be criminalized under federal law.

It's concerning – and sends the message that GrapheneOS is criminal by default.
  1. cameldrv

    I’ve seen a lot of people on the internet over the years say things like “the government can’t make x illegal, it’s just y.” For example, the government can’t make wiping your phone at the border illegal, it’s just punching four numbers into your phone, just like a pin, only a different four numbers, which could just have well been your pin.

    U.S. law though is highly non-autistic and what you were trying to do is just as important as what you superficially did. Hell there could have been a third set of four numbers that were the nuclear launch codes. It’s not the fact that it was four numbers, it’s what you were trying to make happen when you typed them. Now of course whether they can prove what your intent was when you typed them is another matter, but generally a duress pin should be for when robbers are breaking into your house, and the government will be on your side, and not when the government will be against you.

  2. sfRattan

    Ultimately, when you choose to enter a duress PIN that will wipe your device, you have to recognize that choice may have legal consequences. I don't like the amount of power our government has at the national border when it comes to detaining and pressuring citizens, but our Constitution explicitly grants it at least some of the power it now exercises in that context.

    If your threat model includes US state actors at the national border, then your security practices need to account for the confiscation of your device at that border without requiring you to willfully wipe the phone and (in the eyes of police and prosecutors) destroy evidence.

    That means:

    1. Don't travel with anything you can't afford to lose on device. This means setting up travel-specific password managers and hardware keys for a subset of your accounts that you absolutely need to access while abroad, and being prepared to reset those passwords and disable those hardware keys very quickly once home.

    2. Review past legal cases against travelers and identify what behaviors the government considers worthy of prosecution or harassment. Your secure setup must function without needing you to engage in those behaviors, even if it is less convenient as a result. This isn't perfect, as the government may decide some new behavior is prosecutable.

    3. Consult with a lawyer and review your security procedures from a legal standpoint. All of the above is technical and practical advice, not legal counsel and no substitute fo […]

  3. whats_a_quasar

    Here is the indictment:

    https://www.documentcloud.org/documents/28513012-samuel-tuni...

    Here is the statute Tunick is indicted under:

    https://www.law.cornell.edu/uscode/text/18/2232

    There is an immediate problem: the device was being searched, and this statute criminalizes destruction of property to prevent seizure, not searches. I don't think this statute applies this situation. Regardless of whether the border agents could lawfully search his phone at the border, they didn't have grounds to seize it. I suspect this prosecution will quietly be dismissed within a few months.

  4. Grimblewald

    VeraCrypt has a cool function which is a reserved space for a decoy OS.[1] Everything else registers as free space while decrypting to dummy volume. You make the dummy volume look lived in, and forget. provide dummy password, volume decrypts such that only dummy is accessible/readable. give proper password, real OS and FS decrypt and load.

    Something like this may need to become the standars over duress pins which should be treated as a fallback or more extreme alternative. Right now, A single choice to reasonably and rightfully protect your privacy reuslts in jail time over something which likely wouldnt have resulted in any issues if superficial compliance was observed.

    These goons, even if a branch of a facist regime, are ultimately burocrats with violent options to settle. They aren't doing forensics on your device etc. They have neither means nor knowledge to do so. They just need to tick their boxes. Did the phone unlock? tick. Did our spyware complain? no? tick. Overall appearance of compliance from person? yes? tick. free to go, next!

    You just have to find ways to stay safe without agitating their workflow and all is well.

    - [1] https://veracrypt.io/en/VeraCrypt%20Hidden%20Operating%20Sys...

  5. DanHulton

    If your threat model means you can’t afford for border security to view your device, wipe the damn thing yourself before crossing the border and restore it from an encrypted online backup on the other side.

    You’re just carrying a blank phone that you intend to set up and use later, and they can’t force you to install your backup onto a phone.

    Now, this is sus as hell, and you’ll probably draw all kinds of extra attention, but if border security wants access to your phone in the first place, you’re already in a weird place.

  6. northernsausage

    If this happened in an EU country you'd all be wetting yourselves, but for some reason the rooms different today. The professional advice we are given traveling to the US is back up you phone, wipe it, travel and restore once you are comfortable. Sad state of affairs guys

  7. daishi55

    > federal agents had already circulated his name and photo internally, saying he was under investigation for "suspected terrorism activities" because of his alleged association with the movement against Cop City

    Of course it’s about that huh. It’s quite scary how far the US will go against anyone who engages in this sort of activism.

  8. rock_artist

    For non-graphene users (eg. Boring iPhone people like me).

    So there’s a feature called Duress PIN which as explained through some comments means you put a different pin which intentionally wipes the phone.

    It’s not auto wipe or wipe after several failed attempts but intentional wipe of device.

    (Worth explanation as the current title nor the article doesn't easily explain this was made by the US citizen providing the alternative passcode)

    For more technical details:

    > GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).

    https://grapheneos.org/features#duress

  9. etienne89

    So in GrapheneOS you enter your regular passcode to unlock it and a secondary passcode will wipe everything? Maybe it needs a third option where it just shows predefined apps/data, so it could just show e.g. WhatsApp, a set off chosen photo albums and some irrelevant office documents. Could also be useful for handing it to children, so they can access some games or whatever but nothing critical

  10. amelius

    Why didn't the device shadow-ban the user instead of wiping the device upon entering the wrong PIN?

    Of course TSA agents become angry when they enter the PIN and see a message "wiping device".

More from this day

2026-07-27