The Hammer That Never Swung: Why a Wiped Phone at the Border Is Now a Federal Felony

The Code at the Counter

A Customs officer in secondary inspection at Hartsfield-Jackson entered a passcode into Sam Tunick's Google Pixel. The screen went blank, flashed several times, and appeared to restart. The phone had been running GrapheneOS. The agents kept it, told Tunick he was free to enter the country, and let him leave the terminal.

Tunick was returning from a vacation in the Dominican Republic on January 24, 2025. He was thirty, a barista and musician, according to the ABA Journal. The indictment came on November 13. One count under 18 U.S.C. 2232(a) accuses him of knowingly taking action to delete the digital contents of a Google Pixel before and during a search and seizure by a CBP Tactical Terrorism Response Team supervisory officer. The statute carries a maximum sentence of five years.

The phone itself still existed. The government's theory is that its digital contents were property subject to custody, and that entering the code prevented that custody from taking effect. The object in the officer's hand remained. The part Tunick used to protect his data was the alleged felony.

The Search Behind the Search

Agents told Tunick they were investigating child-exploitation imagery, according to his lawyer, W. Matthew Dodge of the Federal Defender Program in Atlanta. Dodge also says federal authorities had placed Tunick on a terrorism watchlist because of his protest work against the Atlanta police training complex commonly called Cop City. Tunick moved from Chicago to Atlanta in 2022 and joined Defend the Atlanta Forest, according to the ABA Journal. He is not charged with a crime arising from those protests.

In secondary inspection, Tunick repeatedly asked to speak with a lawyer and was ignored, according to defense court filings reported by TechCrunch. His lawyers argue that officers coordinated the detention to investigate domestic activity and that the search violated his constitutional rights. Those are defense allegations in a pending case. They have not been adopted by the court.

The defense says the real target was Tunick's political activity. The phone case turns on the authority claimed at the airport, whatever motive a jury eventually finds behind the stop.

What Section 2232 Says

Section 2232(a) reaches conduct before, during, or after a search or seizure. It covers someone who knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes action for the purpose of preventing or impairing the government's lawful authority to take property into custody or keep holding it. Cornell's text sets the maximum at five years.

The indictment uses that language against the phone's digital contents. It says Tunick acted “before and during the search for and seizure of property” by the CBP officer and “otherwise” took action to delete the contents. The charging document contains a typo in its reference to the United States Code. It remains an indictment, not a conviction.

Kyle Courtney, who teaches cyber law and privacy at Northeastern University School of Law, told the ABA Journal that the statute historically involved a physical act, such as smashing a hard drive with a hammer or throwing a laptop into a river. He called the government's use of a native software security method a novel theory and said proving that a duress PIN is legally equivalent to intentionally destroying physical evidence would be a massive hurdle.

Daniel Richman of Columbia Law School told the ABA Journal that the reported facts “seem to fall within the statute.” He also said intentional wiping to avoid a lawful search could be prosecuted. That view supplies the government's cleanest reading: the code was an action, the phone was about to be seized, and the wipe impaired the government's ability to take the data into custody. The legal fight is over whether that reading fits this statute and whether the government's authority over the phone was lawful.

Atlanta Is the Hard Place

Here's the thing about the border. Federal authorities already claim broad power over travelers and their property at the point of entry. The Eleventh Circuit, which includes Georgia, held in United States v. Touset that a forensic search of an electronic device at the border does not require suspicion. The decision rejected a reasonable-suspicion requirement for that kind of device search. The Ninth Circuit has required reasonable suspicion for a forensic phone search, creating a split that matters because Tunick landed in Atlanta.

Tunick's lawyers argue that a phone holds an unusually revealing record of a person's life and that the court should require some suspicion before the government searches it. The defense motion also argues that officers could not simply discard constitutional protections because Tunick was still being processed at the airport. Judge Christopher C. Bly held an evidentiary hearing on the suppression motion on July 20 and left the record open for more testimony, according to Law Commentary.

The schedule reported in that account sets Tunick's post-hearing brief for September 18, the government's response for October 9, and the defense reply for October 23. The court has not ruled on the suppression request. Tunick has pleaded not guilty.

The Password That Does the Wiping

GrapheneOS documents the feature in plain language. An owner can configure a duress PIN or password under Settings, Security & privacy, Device unlock. Entering it where device credentials are requested irreversibly wipes the device and any installed eSIMs. The documentation says the wipe does not require a reboot and cannot be interrupted.

The indictment does not name GrapheneOS or call the password a duress code. It charges the result and the alleged purpose. That distinction matters. A security feature configured before the airport encounter becomes evidence of intent under the government's theory. The owner's preparation is recast as proof that the owner meant to impair the seizure.

W. Matthew Dodge says the Federal Defender Program in Atlanta knows of no other prosecution under Section 2232 for activating a digital security feature. Kabbas Azhar of the Electronic Privacy Information Center told the ABA Journal that a traveler may refuse to provide a phone password. He said Tunick would have been within his rights to refuse, while also explaining that Tunick's decision to provide a duress passcode could be construed as impairing the government's control of the property.

That is the trap at the counter. Refusal can keep the credential private while the government still holds the hardware. Handing over the real credential opens the data under the search authority recognized in the Eleventh Circuit. Using a configured duress credential is the choice now written into a federal indictment as destruction.

The Feature Is the Evidence

Runa Sandvik, who works on security for people at risk, told TechCrunch that travelers should avoid carrying sensitive data across certain borders when possible and download what they need after arrival. That advice treats the border as a place where possession itself creates exposure. Your phone can still be yours while someone else claims the authority to reach what is on it.

The Federal Defender is pushing back through the suppression motion, while GrapheneOS supplies a documented mechanism that worked as designed. Neither is a promise of safety. The case will decide whether the government may turn that mechanism into the charged act of destruction when it operates during a border search.

Prosecutors do not need to outlaw encryption to make the setting dangerous. They need a court to accept that using the credential in front of an officer prevented lawful custody of the data. Once that theory is accepted, a traveler has to calculate the criminal risk of every privacy feature before crossing the border. The phone remains a piece of hardware. The decision about who may reach the life inside it becomes the thing the government says can carry five years.

0 comments

Leave a comment