GrapheneOS, the privacy-hardened version of Android used by security researchers and journalists, says the duress password feature at the center of a federal criminal case is entirely legal. The statement comes after a man was charged following his decision to wipe his phone’s data using the feature during a U.S. airport checkpoint stop, according to a report from TechSpot.

The dispute centers on a built-in GrapheneOS tool that lets users set a secondary password. Entering that password instead of the real unlock code triggers an immediate, irreversible wipe of the device’s data. It is designed as a last-resort privacy safeguard for people who fear being coerced into unlocking their phones, whether by criminals, authoritarian officials, or, increasingly, U.S. border and airport agents.
What Happened at the Checkpoint
According to earlier reporting, the man was stopped at a U.S. airport and asked to unlock his phone. Rather than hand over the device’s contents, he entered his duress password, which erased the data on the spot. Federal prosecutors subsequently charged him, treating the wipe as an act that interfered with a law enforcement inquiry. NarwhalTV previously covered the initial charge in detail: Man Charged for Wiping GrapheneOS Phone Using Duress Password at Airport Checkpoint.
The case quickly became a flashpoint for privacy advocates, who argue that deleting one’s own data before it can be searched is fundamentally different from destroying evidence in an ongoing criminal investigation. The distinction, they say, is that the wipe occurred proactively, as a routine security posture, not in direct response to a warrant or a specific demand tied to a known crime.
GrapheneOS’s Position
In public statements addressing the prosecution, the GrapheneOS project maintained that the duress password functions exactly as any owner’s right to delete personal data from a device they legally possess. The developers have long marketed the feature as a defense against coercive unlocking, not as a tool for evading legitimate investigations, and they argue that treating routine privacy hygiene as a criminal act would set a troubling precedent for anyone using encryption or data-wiping tools.
The organization has pointed out that resetting a phone, wiping a hard drive, or using a password manager’s self-destruct option are common, legal practices among security-conscious users, including journalists, domestic violence survivors, and corporate employees handling sensitive information. Criminalizing that behavior, they contend, would effectively penalize privacy-conscious design itself rather than any specific wrongdoing.
Why the Case Matters
The prosecution raises a question that has not been definitively settled in U.S. courts: does deleting data on a personal device you own, before any formal legal process compels you to preserve it, constitute obstruction? Legal experts note that obstruction charges typically require that a person knew of a pending or foreseeable proceeding and acted specifically to impede it. Whether a routine airport stop meets that threshold is likely to be a central issue as the case proceeds.
The outcome could have far-reaching implications for how encryption and data-protection tools are treated under federal law. A ruling against the defendant might discourage the use of privacy features that are otherwise legal and increasingly common on privacy-focused operating systems. A ruling in his favor could reinforce that individuals retain broad control over their own data, even when law enforcement wants access to it.
NarwhalTV has also examined the broader legal stakes in a related piece: How a GrapheneOS Duress PIN Triggered a High-Stakes Legal Battle Over Smartphone Encryption, which details how the case is being framed by both prosecutors and digital rights groups.
Broader Context: Device Searches at the Border
The case lands amid heightened scrutiny of how U.S. Customs and Border Protection and other federal agencies handle electronic device searches. Civil liberties organizations, including the Electronic Frontier Foundation and the ACLU, have repeatedly challenged the legal basis for warrantless phone searches at airports and border crossings, arguing that travelers retain Fourth Amendment protections even in these settings.
Privacy tools like GrapheneOS’s duress password exist largely in response to this uncertainty. As device searches have become more routine, so has demand for software that gives users a way to protect sensitive data without necessarily refusing to comply with an officer’s request outright.
Digital rights advocates say the case will be closely watched as a test of whether privacy-by-design features can be treated as evidence of criminal intent.
What Comes Next
The case is expected to move through federal court in the coming months, with the defense likely to argue that the wipe was a lawful exercise of the defendant’s control over his own property. Prosecutors, meanwhile, are expected to argue that the timing and circumstances of the wipe suggest an intent to obstruct.
Regardless of the outcome, the dispute has already pushed the conversation about duress passwords and remote-wipe features into the mainstream, forcing a broader reckoning with how far privacy tools can go before they collide with law enforcement authority.