Phone running GrapheneOS wiped at the border — and it became a criminal case in the United States

The most discussed tech storyline of the last two weeks on Hacker News (1300+ points) — a story that makes everyone think who values the privacy of their devices. In the USA, a man was charged with a criminal offense after his phone on GrapheneOS erased itself during airport security screening. The prosecutor views this as intentional destruction of evidence — and lawyers say it is the first time in history that the law targets the operating system itself.

What happened

On January 24, 2025, Atlanta resident Sam Tuinick was returning from the Dominican Republic and was stopped for questioning at Hartfield-Jackson airport. Federal agents (his name within the agencies appeared with a note of “suspected terrorist activity” — in the backdrop of protests against the police center “Cop City”) during a secondary search demanded that the phone be unlocked.

According to the description, when Tuinik entered the password, “the screen went dark, flashed several times, and the phone seemed to reboot” — the data were erased. GrapheneOS is an open-source firmware for Pixel with a privacy focus, and it includes a device reset feature via a special password (duress PIN). What follows is a legal collision: the prosecution contends that the evidence was destroyed deliberately; the defense argues that the wipe could have happened automatically or due to the conditions of the search.

Why the case is unprecedented

Tuinik is charged under a federal statute about destruction of property to prevent its seizure. Lawyers note the unusual approach: essentially, for the first time the accusation is built around the behavior of the operating system, rather than the actions of a person in the usual sense.

This caused a buzz. Cybersecurity expert Christophe Butri articulated the community’s main fear: a case like this sends a signal that GrapheneOS is “criminal by default.” The Electronic Frontier Foundation agreed. The concern is simple: if a privacy-protecting tool can be turned into evidence of a crime, it risks anyone using it — not just the defendants in high-profile cases. A ruling on the defense motion is expected by late October 2026.

What this means for us

The GIG audience includes people for whom privacy and threat modeling are professional concerns: OSINT, circumventing blocks, self-hosting. A few practical takeaways.

  • Border crossing is a separate threat model. At the border (in most jurisdictions), law enforcement has special powers to search devices. The usual assumptions about home privacy do not apply here.
  • The auto-wipe feature is a two-edged sword. The duress reset protects data, but as the case shows, it can be interpreted as a “destruction of evidence.” Technically reliable protection and legally safe behavior are not the same thing.
  • The mere use of a private tool can attract attention. It’s not a reason to abandon it, but a reason to assess the context soberly.

Prudent assessment

It’s important not to panic or engage in alarmism.

  • This is a specific case in the USA, and it’s not decided yet. The accusation is not a verdict; it’s entirely possible the court will disagree with the prosecution’s interpretation. Don’t treat a single case as a universal law.
  • GrapheneOS is not “forbidden” and not declared criminal — this is about a controversial interpretation of actions in specific circumstances. The firmware itself remains a legal tool.
  • Jurisdictions vary greatly. Border-authority powers, the right to remain silent, the obligation to reveal passwords — all differ across countries. Conclusions from the American case cannot be mechanically transferred to your situation.
  • Panicking and deleting private tools is the wrong reaction; the right one is to understand the context of their use.

What to do

  1. Think through a separate “border” scenario. If you carry sensitive data across a border — minimize what physically sits on the device (a clean “travel profile,” data in encrypted cloud/home, and you restore access after entry).
  2. Understand how duress and auto-wipe work on your firmware, and decide consciously whether to enable them: understand not only the technical but also the legal effect in your jurisdiction.
  3. Review local device-search rules beforehand — the right to remain silent, the obligation (or lack thereof) to disclose passwords. It’s cheaper to clarify this before traveling than at the checkpoint.
  4. Don’t overreact to one case — monitor developments (the court’s decision is expected in October 2026) and calibrate your threat model, not your emotions.

Sources

How is your threat model for travel — a separate travel profile, minimal data on the device, auto-wipe? And where do you draw the line between technical protection and legal risk for you?