SOVEREIGN
← News/

News — July 2026

A Duress Password Is Going to Court

A US federal prosecution is asking whether wiping your own phone is a constitutional right or a crime. Here's what it means, and what it doesn't.

27 July 2026 · ~6 min read

A US federal court is being asked, apparently for the first time, whether triggering a phone's duress password — a passphrase that wipes the device instead of unlocking it — amounts to unlawfully destroying evidence. The defendant in United States v. Samuel Tunick is charged under 18 U.S.C. § 2232(a) over a January 2025 border encounter in which he allegedly used the GrapheneOS duress feature during questioning by US Customs and Border Protection.

No court has ruled on this question before. The case was heard on 21 July 2026 and remains ongoing. Tunick denies using the feature at all.

Key facts

Case
United States v. Samuel Tunick
Court
US District Court, Northern District of Georgia
Charge at issue
18 U.S.C. § 2232(a) — destruction of property to prevent seizure
Feature involved
GrapheneOS duress password (wipes the device instead of unlocking it)
Border encounter
24 January 2025
Arrest / indictment
November 2025 / December 2025
Hearing
21 July 2026
Status
Ongoing — no verdict. Tunick denies using the feature.

What happened

On 24 January 2025, Samuel Tunick, an Atlanta-based activist, was questioned by US Customs and Border Protection. Prosecutors allege that during that encounter he entered a duress password on his phone, irreversibly wiping it. His defence disputes that account, and Tunick has denied using the feature.

He was arrested roughly ten months later, in November 2025, and indicted in December 2025. The charge at the centre of the case is brought under 18 U.S.C. § 2232(a), a statute covering destruction or removal of property to prevent its seizure. His lawyers have separately argued that he was not read his Miranda rights and was denied access to a lawyer during the initial encounter, and that the prosecution is politically motivated.

Why this case matters beyond one defendant

Duress passwords have existed in privacy-focused software for years, and GrapheneOS has shipped the feature for some time. What has not existed until now is a court ruling on where the line sits between exercising a privacy protection you legitimately own and obstructing a lawful search.

Both readings are coherent. On one hand, the data belongs to the device owner, and the decision to hold no recoverable copy of your own information is ordinarily yours to make. On the other, deliberately destroying material during an active search is the kind of conduct evidence-tampering statutes exist to address. Privacy law observers have called the prosecution unprecedented precisely because no court has had to weigh those two positions against each other before.

Whichever way it lands, the outcome will be the first concrete guidance anyone has on a feature that is currently shipping on a lot of phones.

What this means in Australia

Directly: nothing. This is a United States federal prosecution. It sets no precedent in Australian courts and does not change Australian law.

That said, Australia is not a jurisdiction where device access is unregulated. Section 3LA of the Crimes Act 1914 (Cth) allows a magistrate to order a person to provide information or assistance to access a device, and non-compliance carries penalties. Australia also has its own laws covering destruction of evidence. The specifics of how any of that would interact with a duress password have not been tested here either.

We sell and configure phones. We are not lawyers, and nothing on this page is legal advice. If you have a specific situation where this matters, talk to an Australian criminal lawyer before you rely on any assumption about what a device feature does or does not permit you to do.

Our position

The duress password exists for a narrow and genuine scenario: someone is physically compelled to unlock a device, and the contents put a person at real risk. That scenario is not hypothetical for some of the people we work with. It is also not the situation most customers are in.

We configure duress passwords on request, and we explain the trade-offs before doing so — including the plain operational risk that a feature designed to irreversibly destroy your data will do exactly that if you mistype it under stress. We do not market it as a way to defeat a lawful investigation, and we would not sell a phone to someone who described that as their goal.

For the large majority of people, the protection that actually matters is auto-reboot combined with a strong passphrase: a phone that returns itself to a fully encrypted, keys-unloaded state on a timer, without destroying anything and without requiring a deliberate act under pressure. It solves most of the same threat, and it raises none of the questions this case is about.

Common questions

What is a duress password on GrapheneOS?
A duress password is a secondary PIN or passphrase that, when entered at the lock screen, immediately and irreversibly wipes the device rather than unlocking it. It is an optional GrapheneOS feature, off by default, designed for situations where someone is physically compelled to unlock their phone. Once triggered, the data is unrecoverable — there is no undo and no backup copy held anywhere.
Is it illegal to use a duress password?
That is precisely the question United States v. Tunick is testing, and it has not been answered yet. Merely having a duress password configured is not itself a crime in the United States or Australia. The legal exposure arises from the circumstances in which it is used — specifically, whether triggering it during a lawful search constitutes destroying evidence. No court has ruled on this point, which is why privacy law observers have described this prosecution as unprecedented.
Does this US case apply in Australia?
No. US v. Tunick is a United States federal prosecution and creates no precedent in Australian courts. Australia has its own separate legal framework governing device access, including section 3LA of the Crimes Act 1914 (Cth), which allows a magistrate to order a person to provide assistance in accessing a device, with penalties for non-compliance. Australian law on destroying evidence is also distinct. If this affects you, get advice from an Australian criminal lawyer — not from a phone vendor.
Does SOVEREIGN configure duress passwords?
We can, on request, and we document how the feature works so customers understand it before enabling it. We do not enable it silently or by default, because a feature that irreversibly destroys data on a mistyped passphrase carries real risk of accidental data loss, entirely separate from any legal question.
What is the difference between a duress password and auto-reboot?
Auto-reboot restarts the phone after a configurable period of inactivity, returning it to the Before First Unlock state where the encryption keys are not loaded into memory. It protects data without destroying it, and it triggers automatically on a timer rather than by a deliberate act. A duress password permanently wipes the device and requires someone to actively enter it. Auto-reboot carries none of the legal complexity raised by this case, which is one reason we consider it the more broadly useful of the two protections.

Not sure which protections suit your situation?

A right-sizing consult exists to work through exactly this — what your actual threat model is, and which features are worth enabling for it.

Reporting on this case: Gizmodo, 25 July 2026. Case details are as reported and may change as proceedings continue. This page is general information, not legal advice. GrapheneOS is a trademark of the GrapheneOS Project; SOVEREIGN is not affiliated with or endorsed by the GrapheneOS Project.