Uranium Finance hacker found guilty of $53M crypto theft
A jury has found Jonathan Spalletta guilty of stealing more than $53 million from Uranium Finance, a decentralized crypto exchange he attacked twice in April 2021. The losses forced the platform to shut down.
Spalletta is a 36-year-old from Maryland who used the online handles "Jspalletta" and "Cthulhon." He surrendered to law enforcement on March 30 and was charged with computer fraud and money laundering. He now faces up to 10 years in prison on the computer fraud charge and up to 20 years for money laundering.
Uranium ran as an automated market maker (AMM) on Binance's BNB Chain. An AMM is a type of decentralized exchange that relies on smart contracts and pooled user funds, known as liquidity pools, to set prices and complete trades. No traditional order book or intermediary is involved. Court documents say Spalletta took nearly $53.3 million in cryptocurrency from the platform, which left it without the funds to keep operating.
Two attacks, two coding errors
The first attack took place on April 8, 2021. Spalletta found a flaw in Uranium's smart contract code that let him submit withdrawal commands for zero tokens. The exchange still paid out rewards on these requests, even though he had no right to them. He drained about $1.4 million from the liquidity pool this way.
He then used the stolen money as leverage. To get most of it back, Uranium had to agree to a fake "bug bounty" of almost $386,000, paid out of the stolen funds. On paper, the payment looked like a reward for responsibly reporting a vulnerability. In reality, it was an extortion payment.
About three weeks later, Spalletta struck again through a different bug. Uranium's transaction-verification logic used the value 1,000 where it should have used 10,000. That mistake let him withdraw nearly 90% of the assets in the exchange's liquidity pools while depositing practically nothing. The second attack took most of Uranium's holdings, and the exchange shut down right away.
Laundering and spending the proceeds
Spalletta moved the stolen cryptocurrency through Tornado Cash and several decentralized exchanges. Tornado Cash is a mixer, a service that pools and shuffles crypto transactions to make it harder to trace where funds came from.
He spent part of the money on rare collectibles, including:
- 18 sealed packs of Alpha Booster Magic cards, for around $1.5 million
- a first-edition complete Pokemon base set, for roughly $750,000
- a "Black Lotus" Magic: The Gathering card, for about $500,000
- an ancient Roman coin commemorating the assassination of Julius Caesar, for more than $601,000
Prosecutors say he bought other items as well. Agents seized the collectibles from his home in February 2025. They also recovered about $31 million in cryptocurrency from wallets linked to him.
The trail had been public for some time before the arrest. In December 2023, crypto fraud investigator ZachXBT linked more than 11,200 ETH withdrawn from Tornado Cash to the Uranium hacker. Those coins were worth $25 million at the time.
"Fake internet money"
U.S. Attorney Jamie McDonald singled out a remark Spalletta had made about his crimes when announcing the verdict on Wednesday.
"Spalletta's own words are indicative of his dangerously misguided indifference for his victims and the hardships he caused, saying: 'Crypto is just fake internet money anyway.' As Spalletta's many victims know, those words could not be further from the truth," McDonald said.
"Spalletta's crimes cost real people to lose real money-over $50 million dollars-and caused an entire crypto platform to collapse."
Our take
The case shows how small coding errors in DeFi can have outsized consequences. One bug accepted zero-value withdrawals. The other came down to a single constant set to 1,000 instead of 10,000. Together they were enough to empty a live exchange. Smart contracts handle real money directly and are hard to fix once deployed, so code audits and careful review before launch matter far more than in many traditional applications.
The fake "bug bounty" deserves attention too. Paying an attacker to return funds and calling it a bounty can blur the line between security research and extortion. This conviction suggests prosecutors are willing to treat such deals as part of the crime. For platforms, it is a reason to think twice before negotiating on those terms.
The verdict also fits a pattern of US authorities pursuing crypto-related crime years after the fact. Other examples include the recent sentencing of an Empire Market co-creator and the court appearance of the alleged Ploutus ATM malware developer. Mixers like Tornado Cash did not stop investigators from following the money here, and on-chain analysis by independent researchers seems to have played a role.
It is worth watching what sentence Spalletta receives and whether any of the recovered $31 million and seized collectibles end up returned to Uranium's users.
