Samuel Tunick Charged with Felony for Border Phone Wipe Using Duress PIN
The Samuel Tunick indictment tests whether the government can charge a felony under 18 U.S.C. § 2232(a) for using a GrapheneOS duress PIN to wipe a phone during a border search. This article examines the novel legal theory, the court's pending decision, and the broader risk for anyone relying on data-wipe, auto-reboot, or remote-erase features.
- Jurisdiction
- US Federal (N.D. Ga.)
- Court
- N.D. Ga.
- AI tool named
- GrapheneOS
- Ruling date
- Dec 3, 2025
- Source document
- View primary court order ↗
- Last verified
- Jul 30, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
Risk record: United States v. Tunick
Last verified July 30, 2026. The Samuel Tunick border phone wipe federal felony charge is not a conviction, not appellate law, and not yet a suppression ruling. It is a pending federal criminal case: United States v. Tunick, No. 1:25-cr-00499, in the Northern District of Georgia. The indictment was filed November 13, 2025, Tunick entered a not-guilty plea on December 3, 2025, bond was set at $10,000, his motion to suppress was filed March 17, 2026, an evidentiary hearing was held July 20, 2026, and the current briefing schedule runs through October 23, 2026.[1][2][3]
| Item | Current status |
|---|---|
| Case | United States v. Tunick, No. 1:25-cr-00499, N.D. Ga.[1] |
| Charged theory | Felony destruction or action against property to prevent seizure under 18 U.S.C. § 2232(a).[2] |
| Device conduct alleged | Use of a GrapheneOS duress PIN during a border phone search.[2] |
| Defense posture | Motion to suppress pending; lawful authority, pretext, property, and Fifth Amendment issues contested.[3] |
| Next practical update point | No ruling should be expected before the late-October 2026 briefing endpoint.[1] |
The live risk is narrower and more operational than the public argument around border searches. The government is testing whether 18 U.S.C. § 2232(a), a statute long associated in the briefing with physical evidence destruction and concealment, can reach a user-triggered wipe of cryptographic access material on a seized phone.[2][3] That is the point where routine travel-security advice becomes criminal-procedure advice.

Where the charge turns
The indictment matters because of the statutory vocabulary it invokes. Section 2232(a) punishes certain conduct involving property when a person acts to prevent or impair a lawful seizure; the pleaded theory depends on phrases such as “property,” “lawful authority,” and “otherwise take action against.”[2] Those words are doing more work than the word “wipe” in the technology coverage.
A physical-evidence version is easy to visualize. If a person throws contraband into the sea while federal agents are moving to seize it, the object has been put beyond the government’s reach. Tunick’s phone did not vanish. On the defense account, the government had the handset; what allegedly disappeared was the access-enabling cryptographic material needed to make encrypted contents usable.[3]
That distinction is not cosmetic. If the “property” is the phone, the government had it. If the “property” is data on the phone, the court has to decide whether this statute reaches that form of property in this posture. If the “property” is key-derivation material, the question gets still tighter: was destroying the material that unlocks data the same legal act as destroying the evidence itself?
The government’s best textual move is the breadth of the verbs. “Dispose of” and “otherwise take action against” are not limited to smashing or burning. A deliberate command that makes evidence practically unrecoverable looks like an action against the thing the agents were trying to seize, even if the casing stays on the table. The defense’s best structural answer is that Congress wrote a destruction-of-property statute, not a general anti-encryption or compelled-access statute, and the border agents retained physical custody of the device.[2][3]
The technical fact that makes this different from a locked phone
The GrapheneOS duress PIN is not just another way to refuse access. PCMag reported GrapheneOS’s explanation that the feature wipes key-derivation material, and quoted the project’s position that erased data “cannot be recovered after the key derivation material is reliably wiped” and that “there’s nothing we can do to assist with it.”[4] In practical custody terms, the device can remain in an evidence bag while the path to decrypting its contents has been destroyed.

That is why the comparison to GrapheneOS’s auto-reboot feature should be handled carefully. Auto-reboot can return a device to a more secure locked state after inactivity; the duress PIN, as described in the GrapheneOS reporting, destroys the material needed to derive access keys.[4] From a security-engineering perspective, both reduce exposure. From a § 2232(a) perspective, only one is alleged to have made the government’s desired access path irretrievable.
GrapheneOS has publicly defended the legality of the feature. PCMag and Android Authority report the Foundation’s position that the duress feature is “completely legal” and that laws requiring weakened security or making such features illegal would be unconstitutional.[4][5] That may be an important product and constitutional position. It does not resolve an indictment. A software project can be right that a feature is lawful in general and still leave a user exposed if the feature is triggered after federal agents have asserted seizure authority over a device.
The suppression motion may decide the case without deciding the whole digital-property issue
The defense has not treated the case as a clean academic dispute over whether data is property. The motion to suppress attacks the government’s authority to search and seize in the first place, including a pretext argument tied to the asserted basis for the border encounter.[3] That matters because § 2232(a) does not punish interference with just any attempted access; the charged theory needs lawful authority.
If the court finds the seizure or search lacked lawful authority, the felony theory could fail without a broad holding about cryptographic key material. That would be a narrower outcome, but for risk managers it would still be an important one: the same wipe event could look very different depending on whether agents were acting within enforceable border-search authority at the moment the command was entered.
The motion also raises the Fifth Amendment act-of-production problem.[3] Entering a duress PIN is an act, and acts can communicate facts: possession, control, knowledge, and sometimes the existence or location of information. The unresolved question here is not simply whether the government may ask for a passcode. It is whether criminal liability can attach to the act of entering a code that performs destruction while also responding to government pressure at the border.
This is why the procedural date matters. Until the suppression ruling, the case remains a live prosecution theory with several exits. A ruling for Tunick on pretext or lawful authority would not necessarily bless duress-wipe features nationwide. A ruling for the government would not automatically establish appellate law. Either way, the first meaningful update for institutional device policies is tied to the post-briefing ruling window after October 23, 2026.[1]
Border-search law makes Georgia a hard forum for this defense
Tunick is in the Northern District of Georgia, so Eleventh Circuit doctrine is not a side issue. The controlling border-search environment is unusually favorable to the government: United States v. Touset, 890 F.3d 1227, held that forensic device searches at the border do not require individualized suspicion, a rule the defense has to litigate against rather than around.[3]
The national landscape is not uniform. On July 13, 2026, the Fourth Circuit held in United States v. Belmonte Cardozo that manual phone searches at the border are routine and require no warrant or individualized suspicion, a fresh decision that widens the government-friendly side of the split.[6] The Ninth Circuit remains more restrictive, so advice that treats “border phone search law” as a single national rule will misstate the exposure.
That distinction is easy to lose in product-centered discussions. The same device feature can sit inside different legal environments depending on the port of entry, the circuit, whether the search is manual or forensic, whether the traveler is a citizen or noncitizen, whether agents have already asserted custody, and whether there is a developed record of pretext. Tunick’s case does not erase those variables. It gives prosecutors a new theory to test inside them.
The risk is not confined to GrapheneOS
The indictment should not be read as a general felony warning label on every privacy feature. A traveler who configures a device before a trip, minimizes stored data, uses a clean travel phone, or relies on ordinary lock-state protections is not in the same posture as someone who triggers irreversible erasure after agents have taken or demanded access to a device. Timing is doing much of the work.
Still, the government’s logic is not product-specific. If § 2232(a) can cover deliberate destruction of digital access material or contents during a federal encounter, the same argument could be aimed at other tools when they are triggered at the wrong moment. Signal disappearing messages, enterprise mobile-device-management remote wipe, and iCloud Find My erase are risk analogues, not established felony triggers. Their legal profile would depend on who initiated the deletion, when, with what knowledge of government authority, and what property or evidence the government says was impaired.
For law firms and security teams, the practical line should be drawn before travel, not at secondary inspection. Data minimization, client-matter segregation, temporary travel devices, cloud-access controls, and written escalation rules all reduce the chance that a person at the border has to improvise under pressure. The risky instruction is the one that turns an access-control decision into a real-time destruction decision while a federal officer is asserting authority over the device.
Enterprise remote wipe deserves special attention because it separates the person holding the phone from the person pressing the button. A help desk that wipes a lost laptop is in a different factual posture from a security administrator who receives a messaged request from an employee standing in front of federal agents. The case law has not yet drawn those lines under § 2232(a), but the Tunick theory gives prosecutors a vocabulary for arguing that a remote command can be an action against seizable property.
Disappearing-message tools pose a different problem. Many deletion timers run automatically and are configured long before any government encounter. That is not the same as pressing a panic-wipe control while agents are seeking a device. But if a user changes settings or manually deletes threads after learning that federal officers intend to seize or search a phone, the facts begin to look less like passive retention policy and more like a contested destruction event.
What can be said now
The safest current reading is procedural: the DOJ has brought a novel § 2232(a) charge based on a duress-PIN wipe during a border phone search; the defense has challenged the search and the application of the statute; the court has not yet ruled; and no appellate court has approved this digital-data application. Treating the indictment as settled law overstates it. Treating the feature’s asserted legality as a complete answer understates the risk.
The case lives at the mechanical boundary between custody and usability. Federal agents allegedly had the physical phone. The usable access path allegedly disappeared. Whether that is destruction of property to prevent seizure, unconstitutional punishment for an act of production, or a prosecution defeated by unlawful authority remains unresolved until the district court acts after the October 2026 briefing cycle.
References
- United States v. Tunick, 1:25-cr-00499 — CourtListener
- Indictment — DocumentCloud
- Motion to Suppress — DocumentCloud
- GrapheneOS Defends Data-Wiping Function That Blocked US Border Search — PCMag
- GrapheneOS duress PIN could land a man in prison — Android Authority
- The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required — Electronic Frontier Foundation, July 2026
Related records
Tool profile
Browse tool evaluations →Governing regulation
Browse the obligations tracker →Preventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →