Security & the Law · Australia

Can police unlock a GrapheneOS phone?

Short answer: without your passcode, it is extremely difficult. A GrapheneOS phone uses strong full-disk encryption tied to a hardened secure element, and when it is powered off (or auto-reboots) the data sits in a fully-encrypted, "before first unlock" state that forensic tools cannot meaningfully attack. The technology is one half of the picture; the law is the other. This page explains both — factually, without scare stories.

The short answer

Forensic tools cannot simply "unlock" a properly configured GrapheneOS phone. Your data is encrypted with a key derived from your passcode and protected by the device's secure element, which rate-limits and throttles guessing attempts. In a powered-off or before-first-unlock state, the data is effectively inaccessible without the passcode. The realistic ways someone gains access are: you tell them the passcode, you are compelled by a valid court order to provide it, or the phone is seized while already unlocked. Strong technology raises the bar enormously; it does not place anyone above the law.

Why the encryption is hard to break

GrapheneOS runs on Google Pixel hardware, which includes a dedicated security chip (the Titan M2 secure element). Your encryption key is derived from your passcode and bound to that hardware. Crucially, the secure element enforces escalating delays on wrong attempts, so brute-forcing a strong passcode is not practical — a long alphanumeric passphrase pushes the time required beyond any useful window.

There is an important distinction forensic specialists use: Before First Unlock (BFU) versus After First Unlock (AFU). When a phone has been powered on but not yet unlocked since boot, encryption keys are not in memory and the data is at its most protected. Once you unlock it the first time, keys live in memory and the device is more exposed. This is why the state the phone is in when it is seized matters more than almost anything else.

How our devices stay in the strong state

Auto-reboot

GrapheneOS can automatically reboot after a period of inactivity, returning the phone to the fully-encrypted before-first-unlock state. A seized device that has been sitting idle reverts to its hardest-to-attack condition on its own.

Duress PIN

A duress PIN, when entered, can trigger an immediate, irreversible wipe of the device's encryption keys — rendering the data permanently unrecoverable. Configured as part of Phantom Protocol.

Hardened secure element

The Pixel secure element throttles passcode attempts and protects the key material, so offline guessing of a strong passphrase is not feasible.

Verified boot & minimal attack surface

Verified boot is relocked and the OS is hardened, reducing the exploit surface that forensic extraction tools rely on.

What the law can compel in Australia

Technology is only part of the answer. In Australia, the realistic legal routes are narrow and warrant-based. Under section 3LA of the Crimes Act 1914 (and equivalent state provisions), a magistrate can order a specified person to provide assistance — such as a passcode — to access a device already subject to a search warrant. Failing to comply with a valid order can itself be an offence. Separately, the Assistance and Access Act 2018 creates obligations for technology providers, not ordinary users, and it cannot compel building a "systemic weakness".

At the border, Australian Border Force has examination powers over devices, and a device can be detained. None of this is unique to GrapheneOS — these powers apply to every phone. What a hardened device changes is the technical default: idle and powered-off, it is genuinely hard to extract. We cover the legal detail in full on are encrypted phones legal in Australia and phone search powers in Australia.

The honest takeaway

A properly configured GrapheneOS phone is one of the most resistant consumer devices to forensic unlocking — when it is powered off, idle, or in a before-first-unlock state, and when it is protected by a strong passphrase. It is not magic, and it is not a way to defeat a lawful court order directed at you personally. The value is preparedness: reducing data exposure, ensuring a seized idle device reverts to its strongest state, and giving you control over your own information when used lawfully. For the full operational layer, see Phantom Protocol and device seizure preparation.

Can police unlock GrapheneOS — FAQ

Can police unlock a GrapheneOS phone without the passcode?

It is extremely difficult. GrapheneOS uses strong encryption tied to the Pixel secure element, which throttles passcode attempts. In a powered-off or before-first-unlock state the data is effectively inaccessible without the passcode. Realistic access routes are you providing the passcode, a valid court order compelling you to provide it, or the phone being seized while already unlocked.

What is the difference between Before First Unlock and After First Unlock?

Before First Unlock (BFU) is the state after a phone has powered on but has not yet been unlocked since boot; encryption keys are not in memory and the data is at its most protected. After First Unlock (AFU) is once it has been unlocked at least once; keys are in memory and the device is more exposed. This is why GrapheneOS auto-reboot, which returns the phone to BFU after inactivity, is valuable.

Does the GrapheneOS auto-reboot feature really help?

Yes. Auto-reboot returns the device to the fully-encrypted before-first-unlock state after a configurable period of inactivity. A seized device left idle reverts on its own to its hardest-to-attack condition.

Can a duress PIN wipe the phone?

A duress PIN can be configured to trigger an immediate, irreversible deletion of the encryption keys, making the data permanently unrecoverable. It is part of the Phantom Protocol configuration. It should only be used lawfully.

Can Australian police legally make me unlock my phone?

Compelled assistance generally flows from a warrant. Under section 3LA of the Crimes Act 1914 a magistrate can order a person to provide a passcode to access a device already under a search warrant, and non-compliance can be an offence. It is a targeted, judicially-supervised power, not something triggered by merely owning a secure phone. Whether it applies in a given case is a legal question for a qualified lawyer.

Is using a hard-to-unlock phone legal?

Yes. Owning and using an encrypted phone is legal in Australia. Strong encryption is lawful and is already part of everyday banking and messaging. See our dedicated page on whether encrypted phones are legal in Australia.

Every device ships pre-armed

Auto-reboot, duress PIN and a hardened secure element come configured on every model below — hand-set on GrapheneOS with Threema, Mullvad VPN and a global eSIM, backed by a 12-month warranty.

Browse all devices →Faraday signal-blocking pouch →Not sure? Take the quiz →

Strong by default. Prepared by us.

Auto-reboot, duress PIN and a hardened secure element — configured before your device ships. 12-month warranty. Crypto accepted.

Browse Prepared Devices → Phantom Protocol

Disclaimer. This page provides general information about device security and Australian law, current as of 2026. It is not legal advice and does not account for your specific circumstances. Our devices are intended for lawful use to reduce data exposure and improve security. For advice about your situation, consult a qualified Australian legal practitioner.