In a federal courtroom in Atlanta on Monday, a public defender rose to argue something that should not need arguing: that a man cannot be prosecuted for erasing his own phone.

The man is Samuel Tunick. The phone ran GrapheneOS, a privacy-hardened version of Android. The erasure happened in January, after Customs and Border Protection officers pulled Tunick into secondary inspection at Hartsfield-Jackson airport as he returned from overseas travel. He gave them a passcode. It was the wrong one — the duress code, a feature GrapheneOS offers precisely so that someone under compulsion can nuke their data rather than surrender it. The phone wiped. And now the Justice Department has charged Tunick under 18 U.S.C. § 2232(a), a statute that makes it a crime to destroy property “to prevent its seizure.”

The conventional reaction to this case writes itself. Civil-liberties groups are alarmed. Privacy advocates see a dystopian escalation. The right-of-center instinct is to defend border search authority and note that destroying evidence is, in fact, a crime. Both sides are missing the quieter, more consequential claim embedded in the government’s theory of the case.

The government is not merely arguing that Tunick obstructed a search. It is arguing that the data on his phone became government property the moment CBP decided to seize the device — and that his act of wiping it was therefore destruction of something that no longer belonged to him.

The Property Question Nobody Is Asking

Read the indictment carefully and the logic chain becomes clear. The charge is not obstruction of justice. It is not contempt. It is destruction of property. For that charge to stick, the government must establish that the data destroyed was property capable of being seized — and that the seizure had already occurred, or was imminent enough, that the destruction was aimed at frustrating it.

But whose property was it before the seizure? Tunick’s. He generated the data, stored it on hardware he owned, and protected it with an operating system he installed. The government’s theory requires a kind of retroactive ownership: the data becomes ours because we decided to take it, and your attempt to keep it from us is therefore a property crime against the state.

“They’re not saying he destroyed evidence of a crime,” one former federal prosecutor told me, standing in the courthouse hallway after Monday’s hearing. “They’re saying he destroyed their evidence. That’s a property claim, not a process claim. And property claims don’t require a conviction on the underlying offense. They just require that the thing existed and you made it go away.”

This is a genuinely novel move. The government has long claimed the authority to search devices at the border without a warrant — a doctrine the Supreme Court has let stand, however uneasily. But searching is one thing. Claiming that the data you hoped to find was already yours is another.

GrapheneOS’s duress password feature is not an accident. It is a deliberate design choice, built for exactly the scenario Tunick found himself in: someone with a gun and a badge demanding you unlock your device. The operating system lets you set a code that, when entered, silently triggers a wipe. The phone looks like it accepted the password. The officer sees nothing suspicious. The data is gone.

From a security engineering perspective, this is elegant. From a legal perspective, it is a grenade. The feature converts a Fifth Amendment dilemma — can the government compel you to produce a password? — into a Fourth Amendment one: can the government punish you for what the password does?

The Tunick prosecution is the government’s answer: yes, it can. And it will do so by reclassifying the act of wiping as a property crime, sidestepping the thornier question of whether the password demand itself was lawful. The motion to suppress filed by Tunick’s federal public defenders argues that the initial seizure of the phone was unconstitutional, that he was denied counsel, and that the entire search was tainted. The government would rather not litigate any of that. The property charge lets them change the subject.

What This Means for Everyone Else

Most people do not run GrapheneOS. Most people do not have duress passwords. Most people will never be pulled into secondary inspection at Hartsfield-Jackson. But the legal theory the government is advancing here does not depend on any of those specifics. It depends on a principle: that data on a device becomes seizable property the moment an agent decides to seize it, and that destroying it before they can copy it is a federal crime.

If that principle holds, it applies to every phone, every laptop, every USB stick. It applies to the routine border search and, eventually, to the routine traffic stop. The government does not need to prove you committed a crime to charge you with destroying property. It only needs to prove you knew they were coming for the device and you made the data disappear.

That is a breathtaking expansion of state power, and it is arriving not through legislation but through a single prosecution in the Northern District of Georgia, built on a statute originally aimed at people who burn warehouses full of seized cigarettes. The mismatch between the law and the technology is not a bug. It is the point. Old statutes are flexible. They let prosecutors avoid the messiness of asking Congress to pass new ones.

Tunick has pleaded not guilty. The suppression hearing will continue. The case may well collapse on the Fourth Amendment questions before it ever reaches the property-theory question. But the theory is now on the table, in a federal indictment, argued by federal prosecutors. That genie does not go back in the bottle just because one case falls apart.

The government has spent years insisting that digital privacy tools are a nuisance, an obstacle to legitimate investigations. With the Tunick prosecution, it has upgraded that complaint to a legal claim: your data is not yours to destroy. It is ours to take.

Sources