Skip to content
Lex Machina Review logoLex Machina Review
Menu

Risk Digest

Samuel Tunick's Felony Charge Tests Duress Passcode Laws

The Samuel Tunick case marks the first criminal prosecution under 18 U.S.C. § 2232(a) for using a smartphone duress-password feature to delete data before a border search. This article examines the unprecedented legal theory, the suppression motion's implications, and what the case means for legal professionals who recommend or rely on such security tools.

REPORTED — UNVERIFIED
Jurisdiction
US - Eleventh Circuit
Court
U.S. District Court, Southern District of Florida
AI tool named
GrapheneOS
Ruling date
Jul 20, 2026
Source document
View primary court order ↗
Last verified
Jul 30, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

Risk Digest | Not legal advice | Last verified: July 30, 2026

The Samuel Tunick federal felony charge over GrapheneOS starts with a narrow but consequential allegation: prosecutors say Tunick violated 18 U.S.C. § 2232(a) by entering a duress passcode during a CBP border search, allegedly triggering deletion of phone data before agents could search or seize it. [1][2] Security researchers and reporters have described it as the first known prosecution using that statute against a smartphone duress-password feature. [3]

Primary record links for this analysis: indictment, 18 U.S.C. § 2232, CourtListener docket, motion to suppress, and our companion case overview, What the Samuel Tunick Case Means for Border Privacy Rights. The docket reflects an evidentiary hearing on July 20, 2026, and post-hearing briefing scheduled through October 23, 2026, so a suppression ruling should not be expected before late October on the present schedule. [4][5]

Smartphone keypad beside an open statute book and gavel, with digital particles dissolving between them

The statutory question is doing most of the work

Section 2232(a) is titled “Destruction or removal of property to prevent seizure.” In broad terms, it criminalizes knowingly destroying, damaging, wasting, disposing of, transferring, or otherwise taking action against property in order to prevent or impair the government’s lawful authority to take or keep custody or control of that property. [2] That language is not limited to crowbars, paper files, hard drives, or narcotics flushed before agents reach the bathroom. It is broader than that. But breadth is not the same thing as a settled fit.

The charge asks the statute to travel from a familiar physical-evidence setting into a passcode-triggered data deletion setting. That move raises several questions legal professionals should separate rather than collapse into one reaction.

  • What is the “property” allegedly destroyed: the phone, the data on the phone, or the government’s access to data?
  • Was CBP exercising “lawful authority” to search, seize, or secure the property at the time of the alleged wipe?
  • Does entering a duress passcode count as destroying or otherwise taking action against property, or is it closer to refusing or defeating access?
  • Can the government prove the required purpose: that the passcode was entered to prevent or impair lawful custody or control, rather than to avoid compelled disclosure, protect privileged material, or respond to coercive questioning?

Those questions matter because the indictment does not itself settle the meaning of § 2232(a). An indictment alleges a violation; it is not a judicial holding that the statute reaches duress-wipe passcodes. The difference is not academic for law firms, journalists, security trainers, or legal-tech buyers who must decide whether a feature belongs in a device policy. A filed charge changes the risk conversation. It does not rewrite the statute by itself.

The government’s strongest textual point is the statute’s functional language. Section 2232(a) is not drafted as a museum piece for paper documents. If data is property, if the border officers had lawful authority to search or secure it, and if the duress code intentionally made that evidence unavailable, prosecutors can argue the statutory verbs are satisfied. The words “otherwise takes any action” give the government room to argue that a button press or passcode entry can be as consequential as shredding a file. [2]

The weak point is also textual. Section 2232(a) is built around the government’s authority to take property into custody or control, and the defense is challenging whether the search and seizure posture was lawful at all. [5] If the border encounter is later found unconstitutional, the felony theory loses a major premise. Even if the search survives, the court still has to decide whether a security feature that deletes encrypted device data can be treated like destruction of seizable property rather than like a refusal to provide access to information.

That distinction is exactly where careful advice should slow down. The case is not simply about whether duress passcodes are “legal” in the abstract. Many lawful tools can be used in ways that create obstruction, evidence-destruction, contempt, sanctions, employment, or discovery problems. Nor is the case proof that using GrapheneOS, or any duress-wipe feature, is now a federal crime. The live issue is whether this particular statute can carry this particular fact pattern at the border.

What the GrapheneOS feature adds — and what it does not answer

GrapheneOS’s official documentation describes a duress PIN/password feature that can wipe user data when the duress credential is entered. [6] That is enough product detail for the legal question. The case does not turn on whether GrapheneOS is well engineered, fashionable among activists, or unusually protective compared with a stock mobile operating system. It turns on what legal significance attaches to entering a credential that causes data deletion during a government encounter.

The GrapheneOS Foundation has publicly said it “cannot do anything to help US law enforcement recover data” from the phone and has defended the feature as “completely legal.” [7] The first statement is operationally important: if no recoverable data exists, the prosecution may have to prove the case through the act of passcode entry and surrounding intent evidence rather than through a forensic reconstruction of the deleted contents. The second statement is not a legal ruling. Vendors can describe their products and defend their designs; courts decide statutory reach.

For policy writers, the operational point is more useful than the rhetoric. If a feature is designed to destroy or render inaccessible device contents under coercive conditions, the advisory record should not stop at “privacy enhancing.” It should identify when the feature may be triggered, who is authorized to enable it, how privileged and client data are minimized before travel, and what a user is instructed to do during a border search or law-enforcement encounter. That is not because the feature is contraband. It is because the government has now shown a willingness to charge its use as property destruction.

Novelty is established by the reaction, not by the indictment alone

The novelty claim is not just defense framing. Bill Budington of the Electronic Frontier Foundation told Ars Technica he had “never seen this before” in connection with § 2232(a) being applied to a duress code. [3] Runa Sandvik of Granitt told 404 Media that people had discussed this kind of scenario as a hypothetical for years, but had not seen it charged this way. [8] Christophe Boutry likewise confirmed the apparent novelty in TechCrunch’s reporting. [9]

That expert reaction does not decide the case. It does, however, tell lawyers how to classify the risk. This is not a mature doctrine with a known compliance playbook. It is an attempted extension of an existing criminal statute into a device-security behavior that security professionals had treated as foreseeable but apparently untested in federal court.

That posture affects advice in both directions. A lawyer should not tell a traveler, employee, journalist, or client that duress-wipe use is clearly criminal merely because Tunick was indicted. A lawyer also should not keep recommending duress-wipe configurations without discussing that prosecutors may characterize the act of entry as evidence destruction if it occurs during an attempted government search.

The suppression motion may decide more than admissibility

Tunick’s March 17, 2026 motion to suppress attacks the border encounter on Fourth, Fifth, and Sixth Amendment grounds. [5] The motion argues that agents lacked a warrant or probable cause, that Tunick was denied Miranda protections multiple times, and that the government’s stated rationales included pretextual references to CSAM and terrorism-watchlist placement tied to Cop City activism. [5] Those are defense allegations at this stage, not findings.

Suppression is not a side issue here. If the court suppresses the phone evidence, related statements, or the circumstances of the passcode entry, the government may lose the factual platform on which the § 2232(a) theory rests. The charge depends on the lawfulness of the attempted search or seizure and on proof that Tunick acted with the purpose required by the statute. A successful suppression motion could therefore narrow or disable the prosecution’s proof, not merely exclude a peripheral exhibit. [2][5]

The timing also matters. The docket reflects an evidentiary hearing on July 20, 2026, and a briefing schedule running through October 23, 2026. [4] Until the court rules, any confident claim that the government’s theory has been blessed — or that it has already failed — is premature.

Cop City belongs in the analysis only as alleged pretext

The Cop City context is legally relevant because the suppression motion uses it to argue pretext and unconstitutional targeting. It is not necessary to resolve whether Tunick’s activism was protected, wise, disruptive, or politically sympathetic in order to see the procedural point: if border authorities used watchlist placement or investigative labels as a pretext to obtain device access, that allegation bears on the lawfulness of the search. [5]

Defense attorney Matthew Dodge told El País that “none of” the Cop City-related charges brought against dozens of people “has resulted in a conviction.” [10] That quote is useful as defense context for the pretext argument. It is not proof that the border search in Tunick’s case was unconstitutional, and it does not answer the § 2232(a) question.

Border-device-search law is unsettled enough to make the suppression fight serious

The constitutional backdrop is moving. On July 13, 2026, the Fourth Circuit’s Belmonte Cardozo decision allowed suspicionless manual phone searches at the border, and EFF described the ruling as deepening the circuit split over border device searches. [11] That ruling is not binding in Tunick’s case, which is in the Eleventh Circuit. It does, however, show why a border-phone-search dispute cannot be treated as if the governing law were administratively settled.

For risk officers, the circuit split matters less as a prediction tool than as a documentation problem. A travel-security policy that says “use a privacy phone” or “enable duress mode” without explaining jurisdictional uncertainty, border-search procedures, privilege handling, and user conduct during inspection is now incomplete. For attorney-client confidentiality risks at international borders, see also State Department Worldwide Caution Raises Legal Stakes for Law Firms.

The immediate change is not to ban GrapheneOS or duress passcodes across the board. The immediate change is to stop treating them as purely technical controls. They are now controls with a criminal-procedure fact pattern attached.

A defensible policy should distinguish at least three situations: routine device hardening before travel, compelled or requested unlocking at a border, and deletion or wipe events after a government officer has asserted authority to search or seize. The first may be ordinary security hygiene. The second may involve constitutional and privilege questions. The third is where Tunick creates the new advisory risk.

  • For law-firm travel devices: minimize client data before travel rather than relying on emergency deletion at inspection.
  • For journalists, investigators, and lawyers crossing borders: document the threat model and the legal advice given about searches, passwords, privilege, and possible obstruction allegations.
  • For procurement teams: ask vendors what duress, wipe, remote-lock, and failed-login features do, and whether logs can show when and how they were triggered.
  • For incident response: treat a wipe during a law-enforcement encounter as a legal event, not merely as a device-management event.
  • For lawyers advising clients: avoid categorical statements that the feature is either a guaranteed shield or inherently criminal.

This case also belongs in legal-technology risk review even though it is not an AI hallucination or sanctions case. The bridge is narrower: legal professionals increasingly recommend security configurations, mobile operating systems, password managers, and device-management settings as part of legal work. When one of those recommendations can later be characterized as obstruction or destruction, the advice needs a record.

On the present record, the government’s § 2232(a) theory is untested and may fail, especially if suppression succeeds. But the filing itself has already changed the risk surface. Anyone recommending duress-wipe functionality now needs to document not only why the feature protects sensitive information, but what the user is told about border searches, asserted lawful authority, and the possibility that a prosecutor may treat passcode entry as destruction of property.

References

  1. Samuel Tunick indictment — DocumentCloud
  2. 18 U.S. Code § 2232 - Destruction or removal of property to prevent seizure — Cornell LII
  3. Activist charged with felony after giving border agent 'duress code' that wiped his phone — Ars Technica
  4. United States v. Tunick, 1:25-cr-00499 — CourtListener
  5. Tunick's Motion to Suppress Evidence and Statements — CourtListener Doc 21, March 17, 2026
  6. GrapheneOS Features: Duress PIN/Password — GrapheneOS Official Documentation
  7. GrapheneOS Defends Data-Wiping Function That Blocked US Border Search — PCMag
  8. 'The Government Hopes To Set a Precedent': An Interview With the Man Charged for Allegedly Wiping His GrapheneOS Phone — 404 Media
  9. US accuses American of allegedly wiping his phone using a 'duress' password during border search — TechCrunch, July 24, 2026
  10. Atlanta activist charged after using phone-wiping software during federal questioning — El País English, July 28, 2026
  11. The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required — EFF

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →
Blogarama - Blog Directory