GrayKey Maker Says It Can Bypass Apple’s New iPhone Reboot Lockdown

Apple recently added a tough new defense in iOS 18.1 that locks down key data if an iPhone isn’t unlocked for 72 hours after a reboot. The device enters what’s called the “Before First Unlock” (BFU) state, obscuring encryption keys and blocking access—even for hardware-based cracking tools. But the building arms race around iPhone security may have just evolved again.

GrayKey’s New Twist: “Preserve” and Evidence Preservation Mode

Manufacturer Magnet Forensics is now promoting a feature called “GrayKey Preserve.” Alongside its existing Evidence Preservation Mode, this tweak claims to hold the phone in the more permissive “After First Unlock” (AFU) state even after a reboot. That’s significant because AFU maintains access to encryption keys—undoing the protections Apple designed into iOS’s 72-hour inactivity reboot safeguard.

The feature was unveiled in a law enforcement instructional video dated early 2025. According to the video, GrayKey Preserve also takes steps to preserve sensitive data—such as cached location logs, recently deleted photos, and iMessages—preventing them from expiring or disappearing. After gaining initial access, the tool locks down cellular, Bluetooth, and Wi-Fi radios so that no new external data enters, freezing the device’s state until legal clearance is obtained.

How Might It Work?

The video does not explain the technical mechanism behind this bypass. Security researcher Jiska Classen speculates that the trick could involve manipulating the device’s clock or targeting internal routines that typically trigger data expiration. The source of the exploit—whether via hardware, firmware, or a software vulnerability—remains undisclosed.

Why This Matters

Apple’s BFU state is intended to protect user data in scenarios where a device is lost, seized, or inactive. By design, unlocking the device at least once after a reboot (entering AFU) is the gateway for key accesses—something Apple assumes only the legitimate owner can do. Any method that subverts this safety net potentially undermines millions of users’ privacy.

This development comes amid a broader tension between law enforcement’s demand for device access and Apple’s commitment to data security. Apple has repeatedly emphasized that strong encryption and state-of-the-art protections like BFU are central to protecting personal privacy.

What to watch now: how Apple responds, whether this bypass is patched, and whether Magnet or others’ tools are legally challenged. If the preservation tweak works reliably, it could force Apple to further harden BFU, audit background clock-handling, or redesign parts of iOS that allow post-unlock persistence.