🌍 Your Global Travel News Source
AboutContactPrivacy Policy
Nomad Lawyer
travel news

US Customs and Border Protection Files First-Ever Charges Over GrapheneOS Duress Passcode Use in 2026

The DOJ is prosecuting a traveler for using a GrapheneOS duress passcode to wipe a Google Pixel phone during a CBP search at Hartsfield-Jackson Atlanta International Airport.

Kunal K Choudhary
By Kunal K Choudhary
4 min read
CBP officer conducting electronic device search at US border

Image generated by AI

The U.S. Department of Justice is pursuing a first-of-its-kind prosecution against an American citizen who allegedly used a security feature to erase his smartphone during a federal border inspection.

The case centers on Samuel Tunick, an Atlanta resident, whose device was seized in January 2025 at Hartsfield-Jackson Atlanta International Airport. This legal action signals a shift in how the U.S. government views the use of privacy-centric operating systems during routine Customs and Border Protection (CBP) screenings.

The Incident: Duress Passcodes and Data Destruction

During a routine inspection, CBP officers requested access to Tunick's smartphone. The device runs GrapheneOS, a hardened Android operating system commonly installed on Google Pixel hardware. GrapheneOS includes a "duress passcode" feature: if this specific code is entered instead of the primary unlock password, the device immediately wipes all user data.

According to court indictments, when Tunick provided the code, the phone screen flashed and restarted, effectively deleting the contents before officers could examine them.

Legal Strategy and Charges

The government is not charging Tunick under traditional digital evidence or obstruction laws. Instead, prosecutors are utilizing a federal statute under Title 18, United States Code, Section 2232(a). This law makes it illegal to knowingly destroy or damage property to prevent authorities from seizing it.

Key Case Details:

  • Defendant: Samuel Tunick (Atlanta resident).
  • Location: Hartsfield-Jackson Atlanta International Airport.
  • Device: Google Pixel running GrapheneOS.
  • Charge: Violation of Title 18, U.S. Code, Section 2232(a).
  • Incident Date: January 2025.

The Defense: Unlawful Search and Political Targeting

Tunick has pleaded not guilty. His legal team has filed a motion to suppress evidence, arguing that the CBP search was a pretext. While officers claimed they were searching for child exploitation material, the defense asserts the real target was Tunick’s involvement with "Defend the Atlanta Forest," a movement opposing the "Cop City" law enforcement training campus.

The defense further alleges:

  • CBP officers ignored repeated requests for a lawyer.
  • Miranda rights were not administered.
  • The search was conducted without a warrant.

The government maintains that no warrant was required because Tunick was returning from the Dominican Republic and had not yet been granted entry into the U.S.

Border Search Statistics and Privacy Trends

CBP's authority to search electronic devices is broad. Our analysis of current border trends indicates that CBP conducts these searches approximately 10 times more frequently than Canadian authorities. This includes the inspection of WhatsApp messages, emails, notes, and smartwatches.

Feature Standard Android/iOS GrapheneOS (Hardened)
Primary Passcode Unlocks device Unlocks device
Duress Passcode Not natively available Triggers immediate data wipe
Privacy Focus Consumer convenience High-level security/anti-surveillance

Why This Matters: Industry Implication

For the digital nomad and privacy-conscious traveler, this case is a watershed moment. Historically, the "battle" at the border was about whether an officer could compel a password. Now, the government is criminalizing the mechanism of data protection itself.

From a logistical and legal perspective, this means that using a "kill switch" or duress code is no longer viewed as a passive privacy choice, but as an active destruction of federal property (the data) during a legal seizure. If the court upholds the use of Section 2232(a), any traveler using advanced encryption or auto-wipe features could face felony charges if those features trigger during a search.

Forward Outlook

The Atlanta Federal Court is expected to rule on the motion to suppress later this year. A ruling in favor of the government would likely lead to an increase in the scrutiny of "hardened" devices at all U.S. ports of entry. Travelers should expect CBP to specifically query the presence of custom ROMs or privacy-focused operating systems during primary and secondary inspections.

The outcome of this case will define the boundary between personal digital privacy and the government's authority at the border.

Related Travel Guides

Disclaimer

This article is for informational and educational purposes only. It does not constitute legal, financial, or professional advice. While we strive to provide accurate and up-to-date information, travel policies, regulations, and conditions change rapidly. Always verify information with official sources before making travel decisions. Nomad Lawyer makes no representations about the accuracy, reliability, completeness, or suitability of the information provided. Readers should consult qualified professionals for advice specific to their circumstances. The views expressed in this article are those of the author and do not necessarily reflect the views of Nomad Lawyer.

Tags:US Customs and Border ProtectionGrapheneOSdigital privacytravel law 2026
Kunal K Choudhary

Kunal K Choudhary

Co-Founder & Contributor

A passionate traveller and tech enthusiast. Kunal contributes to the vision and growth of Nomad Lawyer, bringing fresh perspectives and driving the community forward.

Follow:
Learn more about our team →