US Prosecution of GrapheneOS User Sparks Debate Over Border Device Searches and Duress Wipes
A federal case involving a wiped Google Pixel phone places open-source encryption and border agent conduct under scrutiny.
Federal prosecutors in the United States are pursuing a criminal case brought by the US Department of Justice against Sam Tunick, a smartphone user who triggered an automated data wipe during an inspection by US Customs and Border Protection, bringing privacy-focused operating systems into a broader legal battle over federal search powers.
When confronted by a border officer, Tunick provided a duress password, a specialized protection mechanism available in GrapheneOS. Entering the credential triggered an instantaneous and irreversible wipe of the device’s storage and eSIM profiles, wiping all data before law enforcement could extract information from the hardware.
GrapheneOS, maintained by a non-profit foundation based in Toronto, Canada, is an open-source operating system designed for Google Pixel smartphones. Built around file-based encryption and hardware-enforced security features, the operating system executes a complete destruction of cryptographic keys during a duress wipe, rendering previously stored data mathematically unrecoverable by forensic tools.
In court filings, defense counsel representing Tunick has asked a federal judge to dismiss the evidence in the case. The attorney claims that the US Customs and Border Protection agent failed to advise Tunick of his Miranda rights during interrogation and ignored multiple requests to speak with a lawyer before demanding access to the device.
The prosecution underscores long-standing tension between digital encryption and the federal government’s border search authority. While US agents operate with expanded inspection powers at ports of entry, civil liberties groups such as the Electronic Frontier Foundation have repeatedly argued that constitutional protections against unreasonable searches and self-incrimination apply to mobile electronics.
Addressing the ongoing proceedings, the GrapheneOS Foundation affirmed that developing and using open-source privacy software is fully lawful under the US Constitution. The organization stated it has no obligation to weaken its system architecture or insert law enforcement backdoors, asserting that legislation aimed at criminalizing hardened security tools would face severe constitutional challenges.
However, the organization also advised users against viewing duress wipe features as a universal defense. Developers noted that triggering a data wipe while in law enforcement custody carries serious legal and physical risks, as destroying potential evidence can trigger independent criminal penalties such as obstruction of justice charges.









