What the Samuel Tunick Case Means for Border Privacy Rights
This Risk Digest entry records the first known US prosecution under 18 U.S.C. § 2232(a) for using a duress-passcode feature during a CBP border search, a novel legal theory that, if upheld, could reshape legal advice on cross-border device security. The suppression motion remains pending as of July 2026, making this a live risk signal for litigators and traveling clients.
- Jurisdiction
- US Federal
- Court
- U.S. District Court
- AI tool named
- GrapheneOS
- Ruling date
- Nov 1, 2025
- Source document
- View primary court order ↗
- Last verified
- Jul 30, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
Risk Digest record
This entry tracks a pending federal prosecution, not a settled rule of border-search law. The docket materials now available show a one-count November 2025 indictment charging Samuel Tunick under 18 U.S.C. § 2232(a), a March 17, 2026 defense motion to suppress, and a statute that carries a maximum term of five years’ imprisonment for knowingly destroying or removing property to prevent seizure by an authorized government actor.[1][2][3]
As of July 30, 2026, the suppression motion remains pending. A suppression hearing occurred on July 20, 2026, and reporting on the case states that no ruling is expected before late October 2026.[4]
| Field | Current record |
|---|---|
| Category | risk-digest |
| Verification date | July 30, 2026 |
| Proceeding posture | Pending criminal case; suppression motion argued but not decided |
| Charged theory | Use of a GrapheneOS duress passcode allegedly destroyed property to prevent government seizure |
| Reader use | Risk monitoring only; not legal advice |
| Primary materials | Indictment, motion to suppress, 18 U.S.C. § 2232(a) |

For readers tracking the Samuel Tunick case as a border-privacy risk, the live issue is narrower and sharper than a general debate over phone searches at the border. The government is treating activation of a pre-installed duress-passcode feature as the charged felony act. If that theory survives, counsel advising travelers may need to account not only for what border agents can search, but for whether using a device-security feature during the encounter can itself be charged as destruction of property.
The statutory hinge: destruction to prevent seizure
Section 2232(a) is not a computer-crime statute. It applies when a person, before, during, or after a search or seizure by a person authorized to conduct it, knowingly destroys, damages, wastes, disposes of, transfers, or removes property for the purpose of preventing or impairing the government’s lawful authority to take it.[3] The Tunick indictment uses that statute in a device-security setting: it alleges that he knowingly destroyed property to prevent seizure after giving a border agent a duress passcode that allegedly caused the phone’s contents to become inaccessible.[1]
That is the prosecution theory that makes this case worth watching. The government does not need, at least from the face of the one-count indictment, to prove in the indictment itself that the wiped material was contraband or that the device contained evidence of another completed offense. The charged act is the alleged destruction to prevent seizure. The legal fight may therefore turn on whether the government can use § 2232(a) this way, and whether the evidence supporting the charge survives suppression.
The technical mechanism matters, but only to a point. GrapheneOS has described its duress-passcode feature as wiping encryption keys and has stated that data wiped through the feature cannot be recovered.[5] In practical terms for this prosecution, the government is not merely complaining that a traveler refused to unlock a phone. It is alleging that the traveler triggered a mechanism that made the phone’s contents unavailable for seizure.
Why the suppression motion is doing so much work
The defense has not limited itself to a narrow argument about the passcode. Its March 17, 2026 motion to suppress attacks the border encounter upstream. It argues that CBP unlawfully detained Tunick without a warrant, denied four requests for counsel, failed to Mirandize him, used child sexual abuse material allegations as a pretext for a political-activism investigation, and had placed him on a terrorism watchlist, with his name and photo circulated three hours before his arrival.[2]
Those allegations have not been adjudicated. They matter because the defense is trying to prevent the case from being treated as a clean test of a phone feature activated during a neutral inspection. If the stop, detention, questioning, or device search was unlawful, the defense argues that later evidence should be suppressed as tainted.[2]
The government’s account, as reported, describes the encounter as a routine secondary inspection.[4] The defense account is materially different: it frames the stop as targeted, politically charged, and built around a CSAM pretext.[2] A risk note should not choose between those accounts before the court does. It should notice that the § 2232(a) theory may be tested first through evidentiary admissibility rather than through a final appellate holding on the scope of border device searches.
That distinction is not academic. If suppression is granted on facts specific to this encounter, the case may tell practitioners less about the outer reach of § 2232(a) and more about border-stop limits, pretext evidence, and custodial questioning. If suppression is denied, the charging theory remains in a posture where the government can press the claim that activating a duress feature during a search is felony destruction.
The novelty claim should be read carefully
Several digital-security observers have treated the Tunick prosecution as the first known U.S. case centered on a duress-passcode feature. Bill Budington of the Electronic Frontier Foundation was quoted in Ars Technica describing it as the first known prosecution of this kind.[4] Christophe Boutry told The Guardian that the prosecution “sends the message that [GrapheneOS] is criminal by default.”[6] Runa Sandvik, quoted by TechCrunch, warned that authorities may argue a traveler knowingly destroyed data, making it safer not to carry that data across certain borders.[7]
Those reactions are useful because they show how the case is being read by people who work closely with secure-device practices. They are not the same thing as a comprehensive national survey of every § 2232(a) charge ever filed. The stronger formulation is the bounded one: no known U.S. prosecution has previously centered on use of a duress-passcode feature, based on the expert statements now in the public record.
GrapheneOS has taken the additional position that the duress-passcode feature is “completely legal.”[5] That statement is unsurprising from the project and not dispositive of the criminal case. Still, it identifies the practical anxiety created by the indictment: a security feature installed before travel, and designed for protective use, can become the factual basis for a felony destruction charge if used in front of border officials.
What changes for traveler counseling if the theory survives
Most border-device advice has historically centered on exposure: what data is on the device, whether the device can be searched, whether the traveler can be compelled to unlock it, and what remedies exist if agents exceed their authority. The Tunick case adds a different advisory problem. It asks whether a protective action taken during the encounter can be characterized as obstruction-like destruction even when the feature was installed before travel.
That does not mean every traveler using encryption is at criminal risk. It also does not mean GrapheneOS, duress passcodes, or data minimization are unlawful. The live issue is narrower: when a traveler activates a mechanism that makes data unrecoverable during a government search, prosecutors may argue that the act impaired seizure within the meaning of § 2232(a). The indictment shows that DOJ has made that argument at least once.[1]
For litigators, the immediate file note is to preserve the difference between three questions that can otherwise blur together: whether the border search was lawful, whether evidence from the encounter is admissible, and whether activating a duress feature can satisfy § 2232(a). The suppression motion attacks the first two. The charging theory raises the third. The court may resolve the case at one level without giving clean answers at the others.
For in-house teams and privacy-tool buyers, the practical conversation is more operational. If staff travel internationally with sensitive data, the least legally dramatic control remains not carrying unnecessary data across the border in the first place. Once a device is in an inspection setting, a tool designed to protect data may also create a recordable event that agents and prosecutors can characterize as intentional destruction. That is the risk signal, not a final statement of law.
The next checkpoint is the suppression ruling
The July 20, 2026 suppression hearing is now the procedural marker to watch, with a ruling reported as unlikely before late October 2026.[4] Until that ruling arrives, the case should be treated as a live first-known risk signal, not as a settled doctrine about border privacy rights.
If the suppression motion fails or the § 2232(a) theory is sustained, legal advice about cross-border device security may need to account for more than search exposure. It may need to address the possibility that using an already-installed duress feature during a border inspection can be charged as felony destruction of property.
References
- Samuel Tunick Indictment — DocumentCloud, November 2025.
- Tunick’s Motion to Suppress — DocumentCloud, March 17, 2026.
- 18 U.S. Code § 2232 - Destruction or removal of property to prevent seizure — Cornell Legal Information Institute.
- Activist charged with felony after giving border agent duress code that wiped his phone — Ars Technica, July 2026.
- GrapheneOS statement on duress passcode feature — GrapheneOS Foundation, July 26, 2026.
- Cop City protester phone report — The Guardian, July 23, 2026.
- Runa Sandvik statement on the Samuel Tunick case — TechCrunch, July 24, 2026.
Related records
Tool profile
Browse tool evaluations →Governing regulation
Browse the obligations tracker →Preventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →