On January 24, 2025, Samuel Tunick came off an international flight at Hartsfield-Jackson International Airport in Atlanta and was pulled aside for a secondary inspection. Customs officers asked for the passcode to his phone and despite his protests, the government says Tunick eventually gave officers a PIN number. But rather than unlocking the phone, when an officer entered the PIN they say “the screen went blank, flashed several times and the phone appeared to restart.” Tunick was eventually released. But now, some twenty months later, federal prosecutors are pursuing a case against Tunick under a statute that makes it a crime to destroy property in an effort to prevent the government from taking it.
At the heart of the case is Tunick’s phone, which ran a hardened, privacy-focused version of Android called GrapheneOS. GrapheneOS has a so-called duress PIN feature, which allows a user to program a secondary PIN number that, when entered, renders data on the device unrecoverable. The government alleges the PIN provided by Tunick at the airport deleted the contents of his phone and, in a first-of-its-kind case, Tunick violated federal law when he knowingly gave it to officers.
The problem, however, is that the government’s view of the case does not appear to be supported by the underlying technology or by the language of the statute Tunick is charged with. Most of the discussion surrounding this case has been about whether it was lawful for federal officers to demand Tunick’s passcode in the first place. This is an important aspect of the case which has been widely discussed and argued by his defense, but I think there is another overlooked angle to this story that strongly challenges the government’s view of the case.

The indictment hinges on one issue.
Tunick is charged with 18 U.S.C. § 2232(a), which reads:
(a) Destruction or Removal of Property To Prevent Seizure.— Whoever, before, during, or after any search for or seizure of property by any person authorized to make such search or seizure, knowingly destroys, damages, wastes, disposes of, transfers, or otherwise takes any action, or knowingly attempts to destroy, damage, waste, dispose of, transfer, or otherwise take any action, for the purpose of preventing or impairing the Government’s lawful authority to take such property into its custody or control or to continue holding such property under its lawful custody and control, shall be fined under this title or imprisoned not more than 5 years, or both.
Essentially, the statute protects the government’s ability to lawfully take property into its “custody or control.” Every verb in front of that part—destroys, damages, wastes, disposes of, transfers, or otherwise takes any action—describes something a person does to that property that the government sought to seize. It’s a reasonable enough statute: Agents are coming for a thing and the suspect gets rid of it first. The drugs go down the toilet or the cargo goes over the side of the ship.
The language of the statute means the case against Tunick is about one issue: did Tunick interfere with the government’s “custody and control” of something that it had lawful authority to seize? But in order to answer that, the government has to be clear about what that “something” is.

What exactly was interfered with?
The indictment against Tunick is sparse and in many ways reads as though parts were lifted from the statute itself. The government states that during “the search for and seizure of property” by Customs and Border Patrol[1], Tunick did “knowingly destroy, damage, waste, dispose of, and otherwise take any action to delete the digital contents of a Google Pixel cellular phone, for the purpose of preventing and impairing the Government’s lawful authority to take said property into its custody and control.”
There are three options for what the government alleges Tunick interfered with, but only one of them makes sense. First, there is simply “property”–a non-specific and generic term used at the beginning of the indictment; second, the Google Pixel phone itself; or third, the “digital contents” of that Pixel.
The government cannot simply allege that “property” was destroyed or damaged. It has to specify what property Tunick meddled with. It also cannot be the Google Pixel phone itself. The phrase “Google Pixel cellular phone” in the indictment follows “digital contents” and is used only as a way of telling us where the “digital content” is. Further, the government, as far as I can tell, has made no allegation that Tunick attempted to damage or destroy the actual handset itself.[2] Instead, we’re left to assume that the government is alleging that Tunick damaged or destroyed the “digital contents” of his phone.
Given this, the government needs to show that Tunick actually, or attempted to, damage or destroy the digital contents of his phone such that it interfered with the government's custody or control of it.

The duress PIN did not "wipe" Tunick's phone.
Virtually all modern smartphones are encrypted by default. That means all the data on the device–your notes, contacts, messages, etc.–sits on the storage chip as a bunch of unreadable data and only once you provide your PIN or biometric data can the operating system then unscramble it. But when you enter a duress PIN on GrapheneOS–contrary to popular belief and common parlance surrounding this story[3]–it doesn’t actually “wipe” the device’s data. GrapheneOS stated as much on Reddit after Tunick’s case came to light:
“It would be highly insecure and broken to erase all the data as you’re imagining it. It can’t do that while the OS is running since it’s using that data. It prevents ever accessing any of it again by removing 3 necessary forms of data needed to derive the key encryption keys.”
In sum, the underlying user data is not removed from the device when the duress PIN is entered but only the ability to use the encryption keys to decrypt that data. I verified this directly with Andrew Fenton at GrapheneOS, who confirmed to me that when the duress PIN is entered, “user data on the device is not erased.” Instead, Fenton confirmed, the primary function of the duress PIN is to wipe what is needed to use the decryption keys.[3]
This presents a problem for the government which has based its indictment on the allegation that Tunick took action to “delete the digital contents of a Google Pixel cellular phone.” But according to GrapheneOS, Tunick's user data was not deleted when the officer entered the alleged duress PIN. Instead, Tunick's data remains intact just as it was before the government stopped him at the airport. It is still sitting there on the phone's storage chip in an evidence locker somewhere. The only difference now is that the ability to decrypt that data is gone.

Were encryption keys what the government was after?
The government could argue that the encryption keys, rather than his personal data, are the “digital contents” it described in the indictment against Tunick. This, to me, seems to be the only way to reconcile what the government describes in the indictment with what we know about the duress PIN’s underlying technology and the statute Tunick is charged with. I cannot rule out that this is actually the crux of the government’s argument because the government hasn’t really said much about its theory of the case and what it means by “digital contents” in the indictment.
But if this is their argument, does it make sense? Does it make sense that the thing the government sought to lawfully seize from Tunick was his encryption keys? It’s safe to assume that the government was actually seeking his personal data, i.e. his messages, notes, contacts, etc. The keys were merely a means of accessing that data.
I think we can reasonably say that Tunick's personal data (i.e., what the government really sought custody and control of) and what Tunick allegedly interfered with (i.e., the encryption keys) are two different things. It’s an argument that the government has actually made itself in the same appeals circuit where Tunick’s case is being litigated. The government has, in the past, argued that the rights implicated in the government seeking to compel someone to unlock their encrypted device or hard drive are different than the rights implicated in accessing their underlying data.[4]
I'm not saying that the government cannot win an argument that the phone’s encryption keys were the “digital contents” cited in the indictment and that destroying those keys should be enough for charges under § 2232(a). But the government should have to engage with the key vs. data distinction, the potential inconsistencies with its past arguments, and whether § 2232(a) does what the government says it does.

Does § 2232(a) protect the government's use of seized property?
The real grievance the government seems to have in this case is that it cannot make use of Tunick’s digital contents because they remain hopelessly scrambled. But is that what 18 U.S.C. § 2232(a) was meant to protect? Does § 2232(a) concern the government’s evidentiary value in a piece of property, or does it protect against interference with the “custody and control” of lawfully seized property, as the text reads? The government would likely prefer that a court and jury mash its evidentiary and custodial concerns into one thing, but that’s not what § 2232(a) says. The government has Tunick’s phone and it has his digital contents–isn’t that all § 2232(a) was meant to protect?
Eventually, the government will have to specify what its theory of the case is and exactly what property the government alleges Tunick damaged or destroyed in violation of the law. Since it cannot be Tunick's actual user data, since that data is still on the device, then we have to ask: is the violation of a federal statute that carries up to five years in prison really invoked by the deletion of an encryption key rather than the property the government was actually seeking? Put another way, is destroying the keys to a safe really the same as setting fire to the documents inside it?
It’s in the government’s interest that this nuance regarding GrapheneOS’ duress PIN remains unconsidered, and that the public, courts, and juries consider the government’s evidentiary interest the same as its property interest. But the government should have to grapple with the technology. If it was after Tunick’s data–his messages, contacts, notes, etc.–then it needs to explain how the duress PIN impaired that data in violation of § 2232(a), since, as far as we can tell, it’s all still there.
Read this—it’s important! Nothing here reflects the views of anyone but me. Further, I am not a lawyer. I am not here to provide advice or tell you what to do. If you find yourself the subject of a law enforcement investigation, hire a licensed attorney who can advise you on your specific situation.
Footnotes
[1] It is actually Customs and Border Protection–the government incorrectly named the agency in the indictment.
[2] Andrew Fenton with GrapheneOS confirmed to me that when using its duress PIN feature, the phone itself is not damaged or destroyed. The device can be reset to its original working state.
[3] Many news articles and headlines have erroneously stated that the GrapheneOS duress PIN "deleted" or "wiped" Tunick's device. As I argue, that is not the case.
[4] It should be noted that GrapheneOS' documentation states that its duress PIN feature also wipes the phone’s eSIM partition. I asked Andrew Fenton at GrapheneOS whether any user data is stored in that partition or whether it is simply carrier data. He could not confirm with certainty that there is no user data stored there, but said that he did not believe so. Given the limitations of what I can say about the technology here, I want to acknowledge this feature and state that it could change my argument if the government actually sought data inside that partition. However, because it seems unlikely there was user data there, I would direct readers to sections five and six of this column with regard to the importance of the eSIM partition's deletion.
[5] In re Grand Jury Subpoena Duces Tecum, 670 F.3d 1335, 1346 (11th Cir. 2012). In that case, the government tried to have “John Doe” held in contempt for refusing to decrypt hard drives the government had lawfully seized. The government ultimately lost, but the government argued there was a distinction between Doe's rights against compelled decryption and Doe's rights in the underlying contents. The government tried to argue "that it does not seek the combination or the key, but rather the contents," per the court.