Learn

The duress password felony: when deleting your data becomes the crime

A traveler came home to the US, got stopped at the border, and typed a code. The phone erased itself — a duress password had done its job. Now that traveler faces a federal destruction-of-evidence felony: not for anything on the phone, but for the erasing itself. Here is what the case means — and why the safest answer to pressure is not destroying data at all.

Key takeaways

  • In July 2026, a US traveler was charged with a felony for allegedly wiping a phone with a special “duress” code during a border search — the first known case of its kind.
  • The charge is not about what was on the phone. It is about deleting it: erasing data during a search can be treated like shredding documents during a raid.
  • A wipe is visible. One moment the data exists; the next, in front of the person demanding it, it is gone. That moment can itself become the accusation.
  • Deniability works without any such moment: you open a vault with nothing sensitive in it, and nothing on the phone can prove any other vault exists. Nothing is deleted, because nothing needs to be.
  • Sealby still offers a duress PIN as a last resort — but it moves your vaults off the device rather than destroying them. With iCloud backup on, they can be restored later with their recovery phrases.

What happened at the border

In July 2026, The New York Times reported on a US citizen stopped at the border and asked to unlock a phone. The code typed in was, prosecutors say, a duress password (also called a duress PIN) — a special passcode that erases the device instead of opening it. What followed was a federal felony charge for destroying evidence: the first known case of its kind, still undecided, and a new light on every panic-wipe feature in any product.

Why deleting can be worse than showing

The charge rests on a simple idea: if officials have the right to examine something, destroying it while they wait looks like shredding documents during a raid — and an erased phone cannot prove its own innocence. There is a practical problem too, far beyond borders: a wipe is visible. One moment the data exists; the next, right in front of the person demanding it, it is gone. Whether that person is an official, an abusive partner, or a thief, visible destruction tends to escalate the moment, not end it.

The other way: have nothing to find

Deniability flips the question from “how do I destroy my data under pressure?” to “why should the pressure find anything at all?” In Sealby, every code opens its own vault — so you keep one filled with ordinary, harmless things and open exactly that one on demand. Sealby stores no list of vaults, no count, nothing that says “there is more here”; a vault you have not opened looks like random leftover data. Showing the harmless vault is full cooperation. Nothing was deleted. There was simply nothing else to find.

Sealby’s duress PIN: moving, not destroying

For situations worse than a border queue, Sealby still has a duress PIN — built differently from a self-destruct. You mark a harmless decoy vault; entering its PIN opens it normally and quietly removes your other vaults from that device, once. At the same moment the phone stops syncing — on purpose — so the wipe never reaches your iCloud backup. The encrypted copy of your vaults stays in your own iCloud, and each one comes back on a new device with its recovery phrase. Your data did not die. It left the phone.

Moved is not destroyed — but be honest about the law

With backup on, Sealby’s duress feature is not a destruction tool — the device carries nothing while your data survives, encrypted, under your control. But an engineering difference is not a legal shield: removing data during a lawful search could still be treated as obstruction, and no app feature changes that. The law on duress codes is unsettled and varies by country; the first US case is still being argued, and this article is not legal advice. What good design can genuinely do is make the desperate option unnecessary — when nothing can prove your private vaults exist, opening a decoy is usually answer enough.

If the risk is real for you

Lead with the decoy, not the wipe. If your situation truly calls for the duress PIN: turn on iCloud backup first, so triggering it moves your data instead of losing it; put believable content in the decoy; choose a PIN you could never type by accident; and write each vault’s recovery phrase down somewhere safe, away from the device. Those words are what your data ultimately answers to — the phone is just the thing that carries it.

Quick answers

Is a duress password illegal?

Nobody knows yet — that is exactly what makes this case important. Prosecutors say that wiping a phone during a lawful search destroys evidence, like shredding papers during a raid. The defense says the search itself was improper. No court has decided, and the rules differ from country to country. This article is not legal advice — if this risk is real in your life, talk to a lawyer who knows your jurisdiction.

Does Sealby’s duress PIN delete my data forever?

Not if iCloud backup is on. The duress PIN opens a harmless decoy vault and removes your other vaults from that phone — while stopping sync, on purpose, so the encrypted copy in your own iCloud stays untouched. On a new device, each vault comes back with its recovery phrase. Without a backup the loss really is permanent — and Sealby warns you about exactly that before letting you turn the feature on.

Can someone tell that a duress PIN was used?

Not from the screen. The decoy vault opens like any normal vault — no alarm, no message, nothing unusual. And afterwards, entering any other code shows an outsider what it always showed: nothing. The duress PIN works once, then switches itself off until you set it up again.

Is wiping your phone destruction of evidence?

That is the exact question the border case will answer. Prosecutors argue it is — that erasing data during a lawful search is like shredding papers during a raid; no court has ruled yet. What is already clear is the practical shape of the risk: a wipe is a visible event that can be held against you. The safer position is never needing one — opening a harmless decoy vault while nothing can prove any other vault exists.

Does my duress setting copy to my other devices?

No. It is set up on each device separately and never travels with your synced data. Your iPhone can have a duress PIN while your iPad has none.

Your vault is waiting.

Download Sealby and protect what matters. Setup takes under a minute, and there’s no account to create.

Download on the App Store

iPhone & iPad · iOS 17+ · Free