All news
regulationcybersecurityproductlegal

US Prosecutes Citizen Over Phone Duress Password

28 Jul 2026

Federal agents detained US citizen Sam Tunick at Atlanta's Hartsfield-Jackson airport after his phone was wiped via a duress password.

The government is now prosecuting Tunick, a US citizen, under a little-known statute that criminalizes destruction or damage of property intended to prevent its seizure by authorities. At the center of the case: a duress password feature built into GrapheneOS, a privacy-focused mobile operating system that wipes device data when triggered instead of granting access.

What happened

On January 24, 2025, federal agents detained Tunick at Hartsfield-Jackson airport in Atlanta. According to the government, Tunick provided agents with a duress password rather than his actual passcode, which caused his phone to wipe. Authorities are now pursuing prosecution over the incident.

Tunick's lawyers argue the detention was pretextual — a means to investigate his connections to the Stop Cop City movement rather than a routine security matter. They also allege that federal agents refused Tunick access to a lawyer, did not present a warrant, and failed to inform him of his legal rights during the encounter.

Marlon Kautz, commenting on the case, stated that individuals have a right to secure their private data against unconstitutional searches.

Why the statute matters

The property-destruction statute being applied here is obscure, and the report does not detail its specific language beyond its general purpose: criminalizing the destruction of property to prevent seizure by authorities. Applying it to a digital privacy feature — rather than physical evidence tampering — would be a novel use, and could set precedent for how courts treat privacy-protective software features going forward.

What's still unclear

Several details remain unreported: the exact statute being invoked, what data or materials agents were seeking on Tunick's phone, the government's response to allegations of denied counsel and a warrantless search, and whether Tunick has been formally charged or remains under investigation.

Why founders should care

This case could plausibly signal rising legal risk for companies that build privacy features like duress passwords or remote-wipe capabilities — especially those operating in contexts where users may encounter border searches or law enforcement. If the property-destruction statute is successfully applied to digital data wiping, it may establish a legal precedent that other prosecutors could draw on, increasing uncertainty for privacy and security tech builders.

Founders in this space should likely monitor how courts interpret this statute as applied to software-based privacy tools. The allegations of denied legal counsel and a warrantless search also suggest founders may need to think through how their products' users are protected — or exposed — during government interactions, particularly for tools marketed on the promise of protecting user data from search or seizure.

At the same time, the publicity around this case could increase market interest in privacy-focused mobile operating systems and related tools, as awareness of duress password features spreads among users concerned about border and law enforcement encounters.

The bigger picture

The prosecution ties into broader themes of digital privacy, government surveillance, and activist scrutiny — Tunick's lawyers specifically link the detention to his alleged ties to the Stop Cop City movement, suggesting individuals connected to activist causes may face heightened scrutiny during routine encounters like airport stops. For founders building privacy or security products, this case is worth watching closely as it develops, since its outcome could shape both the legal risk profile and market demand for this category of tools.

Sources