When Wiping Your Phone Became a Felony

Saturday 22 August 2026 topic: how a property-destruction charge is being stretched to criminalise wiping your own encryption keys at the border

This is a conceptual editorial lead image about a legal argument (data-as-property vs. constitutional rights at the border), not a quantitative comparison — no numbers to plot, so…

An activist lands back in the United States, a border officer demands his phone, and instead of handing over the keys he types a second PIN that wipes them. For that he now faces five years in federal prison, and the way they have done it tells you exactly where privacy tooling stands at the border.

The charge is not hacking or obstruction in the usual sense, but property destruction. Sam Tunick, an Atlanta activist, is now charged under 18 U.S.C. § 2232(a) for allegedly destroying property to prevent lawful seizure.1 The maximum sentence for the alleged crime is five years in federal prison.2 The statute was written for smashing crates or tossing contraband overboard, not for scrambling the maths that make bits readable. Yet the indictment treats the erasure of those keys inside a device that stays in government hands as if you had taken a hammer to the phone itself. The move only works if data counts as tangible property subject to seizure, and if a border phone search counts as a lawful seizure where constitutional protections are already thin. As one analysis put it, “Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.”3 That is the trapdoor. Until you are admitted, the rights you think you have to withhold a password have not fully attached.

There is context around why Tunick had that feature at all. His phone ran GrapheneOS, which ships a duress PIN that silently wipes encryption keys. The project is blunt: “GrapheneOS is completely legal. We have no obligation to weaken any of the security protections it provides. Creating and using GrapheneOS is strongly protected by the US constitution.”3 Federal authorities had put him on a terrorism watchlist because of his alleged association with the movement against Cop City before he ever reached the inspection booth.4 His lawyer says the detention, which agents claimed was about alleged child sexual abuse materials, was a “fishing expedition into Mr. Tunick’s connections with the Defend the Atlanta Forest movement.”5 The usual warrant for a border search is contraband, yet phones of activists now hold the map of a movement, which makes these searches uniquely pointed.

Now the pushback, because there is a serious counterargument and I do not want to handwave it. If you are the subject of a lawful search and you destroy evidence rather than handing it over, that is spoliation. As one commenter put it, “If you’re the subject of a lawful search and you destroy evidence rather than handing it over, that’s spoliation.”6 On that view wiping is not a privacy exercise, it is destruction of evidence during a seizure, and courts are allowed to infer the worst about what was destroyed. The problem is the view assumes what it needs to prove: that a compelled decryption at the border is a lawful seizure of contents, and that data is property that can be seized like a suitcase. No court has settled that. As another practitioner noted, “A court has not yet determined whether the use of the duress PIN/password was legal. There’s definitely no consensus among legal experts of it being illegal as you’re portraying it.”7 There is also the common sense rebuttal that keeps coming up: “A wiped phone can’t contain contraband, so wiping the phone serves the same purpose as a search. It’s not destroying evidence anymore than throwing away a water bottle before going through TSA is destroying evidence.”8 You have not deprived the state of a thing it owned, you have made sure there was nothing to take.

I reckon the felony framing does transform a rights claim into a property crime, and that is precisely why it is corrosive. The state does not need to win the argument that you must decrypt. It only needs to make not decrypting punishable as vandalism. The chill is immediate. If typing a PIN you installed for your own security can be charged as destroying government property, the tool itself feels illicit, which is why one security expert warned the case sends the message that GrapheneOS is criminal by default. That precedent does not require a court to finally declare that bits are bricks. It only requires the threat of five years to make nobody willing to test whether they are not. Tunick himself framed the stakes as “I hope people understand that the charges against me are meant to intimidate people against protecting their data and their privacy, and the government hopes to set a precedent that no one has the right to privacy”.5 Until a judge actually rules that scrambling your own keys is the same as smashing your own phone while it sits on a border bench, I think we should call this what it looks like: a constitutional argument repackaged as a property offence, slipped through the gap where the border is treated as outside the country.

Sources

How this was made
  • 01-research z-ai/glm-5.2 $0.136
  • 03-annotate z-ai/glm-5.2 $0.058
  • 04-nominate deepseek/deepseek-v4-pro $0.002
  • 05-select google/gemini-3.7-flash $0.003
  • 06-write meta/muse-spark-1.2 $0.058
  • 08-visualise anthropic/claude-sonnet-5 $0.046

total $0.303

What each stage does, drawn out →