Destructive duress passcodes on smartphones are drawing attention after reports highlighted how the feature can wipe a device instead of unlocking it when a user is under coercion. On GrapheneOS for Google Pixel phones, the duress PIN feature introduced in June 2024 erases user profiles, their data, and the eSIM partition by destroying disk-encryption keys, making recovery impractical. The reports note that stock Android and iOS do not provide an equivalent built-in duress passcode, relying instead on slower local or remote wipe options.
The legal risks of using the feature came into focus through the case of Atlanta resident Samuel Tunick, who allegedly triggered a duress passcode during a Customs and Border Protection inspection at Hartsfield-Jackson International Airport in January 2025. Prosecutors charged him under 18 U.S.C. § 2232 for allegedly destroying property to prevent lawful seizure, while his attorneys are contesting the device seizure on Fourth Amendment grounds. The case underscores unresolved legal questions in the U.S. and other jurisdictions over compelled device unlocking and whether intentionally wiping a phone during a lawful search can itself become a criminal act.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Germany’s Federal Court of Justice issued a decision concluding that compelling a suspect to use a fingerprint to unlock a phone does not violate self-incrimination protections because it does not require the same active participation as entering a password.
During a Customs and Border Protection stop at Hartsfield-Jackson International Airport, Atlanta man Samuel Tunick allegedly provided a GrapheneOS duress passcode on his Android phone, causing the device data to be wiped instead of unlocked.
GrapheneOS introduced a duress PIN/passcode feature for supported Google Pixel devices that wipes user profiles, their data, and the eSIM partition by destroying disk-encryption keys.
Prosecutors charged Samuel Tunick with destroying property to prevent lawful seizure after the airport incident. His attorneys are seeking suppression on Fourth Amendment grounds, arguing the seizure was warrantless.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.