The Tech Docket Daily signal on tech & AI — what the world is searching, and why
Policy & Society

US Border Phone Searches: The GrapheneOS Wipe Case, Explained

A GrapheneOS phone wiped itself during a CBP airport search; its owner faces five years. What border officers can really do, and what Indian travelers should know.
A smartphone on an airport inspection desk, its screen going blank while a queue of travelers waits behind a barrier.
Note: This article discusses security topics for awareness and defense only. Follow official vendor advisories for remediation steps.

A US federal court is weighing a first-of-its-kind prosecution: an Atlanta man faces up to five years in prison because his phone — running the privacy-focused GrapheneOS — wiped itself when he entered a “duress” code during an airport inspection, as TechCrunch first reported. The case turns a niche Android feature into a live constitutional question about what border officers can demand from the devices we carry. Here is what happened, what border agents can do, and why the answer depends on the passport in your hand.

What happened at the Atlanta airport

On January 24, 2025, Samuel Tunick landed at Hartsfield-Jackson Atlanta International Airport from the Dominican Republic and was pulled into secondary inspection by US Customs and Border Protection (CBP), according to TechCrunch’s account of the court filings. Agents demanded access to his Google Pixel. Tunick entered a code — and, in language quoted from the filings, the screen “went blank, flashed several times and the phone appeared to restart.”

Prosecutors say that was no malfunction. The phone ran GrapheneOS, a hardened version of Android for Pixel phones, and the government alleges the code Tunick typed was its duress password — a second credential that, per the official GrapheneOS documentation, “will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested.” The wipe needs no reboot and cannot be interrupted. Agents seized the blank phone and let Tunick, a US citizen, enter the country.

Why he was stopped is disputed. Tunick has said agents told him they were looking for child sexual abuse material, he recounted to 404 Media; his defense calls that pretext, pointing to an internal Homeland Security email — described in reporting on the suppression motion — flagging him hours before landing over ties to Atlanta’s “Stop Cop City” protest movement. The Justice Department declined to comment to TechCrunch.

The charge: five years over a self-wiping phone

A federal grand jury indicted Tunick in November 2025 under 18 U.S.C. § 2232(a), which punishes anyone who “knowingly destroys” property or “takes any action” to prevent its lawful seizure by the government. The maximum penalty is five years in prison. He was arrested in December 2025, pleaded not guilty, and told 404 Media he believes “the government hopes to set a precedent that no one has the right to privacy.”

His federal public defender, Matthew Dodge, called this use of the statute “extraordinarily rare” in the same 404 Media report, saying he found only one prior case. Security researcher Runa Sandvik, who advises journalists on crossing borders, told TechCrunch she had “not seen this before” — and that “it’s better to not have that data on you when you cross certain borders.” The Electronic Frontier Foundation’s Bill Budington said the same: no one recalls a prosecution built on a duress wipe.

GrapheneOS pushed back publicly, noting the duress feature “is not required to protect user data from extraction” — the system’s hardware-backed encryption already prevents that — and calling it an optional layer “for users who determine it is appropriate for their own threat model.” A judge heard the defense’s suppression motion on July 21, 2026; a ruling is not expected before late October.

What US border officers can actually do

The border is the weakest point in American privacy law, and CBP’s own rules say so plainly. Under CBP’s published policy, set out in Directive 3340-049A and a January 2026 revision that extended coverage to smartwatches, SIM cards and drones, officers may conduct a “basic” search — manually scrolling through a device — with no warrant and no suspicion at all. An “advanced” search, connecting the device to forensic equipment that copies and analyzes its contents, requires reasonable suspicion or a national-security concern, plus a senior manager’s sign-off. No judge is involved in either tier. Officers are supposed to enable airplane mode first, because the authority covers what is stored on the device, not your cloud accounts — a distinction we unpack in our explainer on on-device versus cloud data.

These searches are rare but growing. CBP’s own figures show 47,047 device searches in fiscal 2024 — about 90% basic — out of hundreds of millions of crossings, roughly 0.01% of travelers. Fiscal 2025 data reported from CBP statistics puts the total at 55,318, up 17.6% year on year. A locked device does not stop the process: under the directive, CBP can detain a phone five days by default — longer with supervisor approval — and travelers are “obligated” to present devices in a condition that allows inspection.

What refusal costs you depends almost entirely on immigration status:

Status Can you be denied entry for refusing to unlock? Can the device be seized? Practical consequences
US citizen No Yes Hours of secondary questioning; device held five days or longer
Green-card holder Unsettled — no clear rule Yes Risk of delays; refusal may be scrutinized in later proceedings
Visa holder / visitor Yes Yes Denial of entry, visa revocation, expedited removal

The citizen row comes straight from CBP’s policy page; the visa-holder row reflects CBP’s statement that refusal can affect admissibility. Courts are actively fighting over whether any of this needs a warrant: on July 13, 2026, the Fourth Circuit appeals court held that manual border phone searches need no suspicion at all, joining several circuits, while a line of New York federal rulings has demanded warrants. That split is why cases like this one may eventually reach the Supreme Court.

How other countries handle locked devices

The US has no law directly compelling you to hand over a passcode — which is why prosecutors reached for a property-destruction statute. Other democracies legislated more bluntly:

Country Legal mechanism Penalty for refusal
United States No compelled-disclosure law; § 2232 destruction charge used in Tunick case Up to 5 years (destruction, not refusal)
United Kingdom RIPA 2000, Section 49 notices compelling decryption Up to 2 years; up to 5 in national-security cases
New Zealand Customs and Excise Act 2018 password demands at the border Fine up to NZ$5,000
Australia Assistance orders under the Crimes Act (Section 3LA) Criminal penalties for non-compliance

The UK has actually jailed people for refusing to decrypt, per Open Rights Group’s documentation of Section 49 convictions. The American approach is less codified but not necessarily gentler: the Tunick prosecution converts a phone’s security feature into the basis of a felony charge.

What it means

Three things make this case bigger than one traveler. First, it criminalizes a configuration decision made months in advance: a duress code must be set up long before any officer asks, so the government’s theory treats preparation for coercion as intent to obstruct. That logic, if it holds, reaches every tool that auto-protects data, including Apple’s opt-in setting that erases an iPhone after ten consecutive wrong passcodes. Google’s standard Android ships theft-protection and remote-lock features but nothing resembling a duress wipe — GrapheneOS exists precisely because some users want protections platform vendors will not ship.

Second, the outcome will calibrate how much travelers can trust device security at all. GrapheneOS is used by journalists, activists and security researchers; a conviction would signal that using such tools near a border is legally dangerous even when — as here — the government never alleged the phone contained anything illegal. As we found when examining what AI chatbots retain about their users, the gap between what technology protects and what law permits is where ordinary people get caught.

Third, the suppression fight matters as much as the charge. The defense says Tunick asked for a lawyer repeatedly and was refused. If the court suppresses the evidence, the case may collapse without answering the big question — leaving the next traveler to litigate it from scratch.

The India angle

Indian travelers have more exposure to this regime than almost any other nationality: few cross as citizens. The US logged more than 2 million visits from India in January–November 2024, per International Trade Administration data. Indians received 73% of approved H-1B visas in fiscal 2023, according to Pew Research Center, and 363,019 Indian students — 30.8% of all international students — were enrolled in the US in 2024-25, per the Open Doors report. Nearly all of them sit in the table’s bottom row: refuse to unlock, and entry itself is at risk. Security experts’ standard guidance — travel with a clean device, keep sensitive data in the cloud, power off before landing — matters most for exactly this group.

The contrast with India’s own rules is instructive. India’s Customs Act, 1962 was written around physical contraband; its search provisions contain no dedicated language on digital devices or passcode demands — a legal gray zone rather than a codified power. And India’s new data-protection law would not restrain border officers much anyway: as we explained in our DPDP Act breakdown, Section 17 lets the central government exempt any state agency on sovereignty or security grounds and exempts crime-investigation processing outright. At any border — American or Indian — data-protection statutes offer little shelter; plan around what officers can physically access. More of our coverage of how governments regulate technology lives in the Policy & Society hub.

What to watch

The Atlanta federal court’s suppression ruling, expected after late October 2026, is the next hinge: suppression likely ends the § 2232 test case; denial pushes it toward trial and, potentially, appeal. Watch, too, whether the pending Second and Third Circuit appeals — where the EFF is arguing that device searches require warrants — deepen the circuit split the Fourth Circuit just widened. And for the millions of Indian travelers headed to US ports of entry this year, the practical takeaway is settled regardless of verdict: the safest phone to hand an officer is one with nothing sensitive on it.

General information, not legal advice — consult a qualified attorney about your own situation.

Frequently asked questions

Can US border agents search your phone without a warrant?

Yes. Under CBP policy, officers can manually look through any traveler's device with no warrant and no suspicion. Connecting forensic equipment — an 'advanced' search — requires reasonable suspicion and a senior manager's approval, but still no judge.

Can a US citizen refuse to unlock their phone at the border?

A US citizen cannot be denied entry for refusing to unlock a device or share a passcode. The trade-offs: the phone can be seized and held — five days by default, longer with approvals — and the traveler can face hours of secondary questioning.

Is it illegal to wipe your phone before or during a border search?

Wiping your own phone before travel is lawful and widely recommended by security experts. The Tunick case tests something narrower: whether triggering a wipe during an active inspection is 'destruction of property to prevent seizure' under 18 U.S.C. § 2232, a felony carrying up to five years.

Can visa holders be denied entry for refusing to unlock a phone?

Yes. CBP states that a non-citizen's refusal to allow a device inspection can affect admissibility — in practice, visa holders and visitors risk denial of entry, visa revocation or expedited removal.

Sources & further reading

  1. GrapheneOS features documentation — duress PIN/password (primary source)
  2. CBP — Border Search of Electronic Devices (policy and FY2024 statistics) (primary source)
  3. CBP Directive 3340-049A — Border Search of Electronic Media (court-hosted copy) (primary source)
  4. 18 U.S.C. § 2232 — Destruction or removal of property to prevent seizure (primary source)
  5. EFF — Fourth Circuit says border agents can search your phone by hand, no suspicion required (primary source)
  6. Apple Platform Security — passcodes and the Erase Data option (primary source)
  7. Google — Android theft protection features (primary source)
  8. US accuses American of allegedly wiping his phone using a 'duress' password during border search — TechCrunch
  9. 'The government hopes to set a precedent' — 404 Media interview with Samuel Tunick
  10. US prosecutors charge Atlanta man after GrapheneOS phone wipes itself — TechSpot
  11. CBP phone searches and US citizens' rights — Newsweek
  12. GrapheneOS defends security model after US prosecutors target user — CyberInsider
  13. CBP electronic device searches jump 17%, wearables now in scope — VisaHQ
  14. US records over 2 million Indian visits — Skift, citing US International Trade Administration
  15. What we know about the US H-1B visa program — Pew Research Center
  16. Open Doors 2025: Indians remain largest international-student cohort — ThePrint
  17. New Zealand's border device password fine — TIME
  18. RIPA 2000 Part III, Section 49 — Open Rights Group wiki
  19. DPDP Act 2023, Section 17 exemptions — text and explainer
  20. The Customs Act, 1962 — India Code (primary legislative text)
How this article was made: topic selected from same-day search-trend and community-momentum data across India and the US; researched, drafted and fact-checked with AI assistance under the site's automated quality gates (source citations, originality, no-clickbait and accuracy checks), on the editorial standards set by Saurab Jain. Details in our editorial policy. Spotted an error? Email a correction.

More of today, in 60 seconds: Today's Docket →