Jonathan Spalletta convicted in $53 million Uranium Finance hacks
A federal jury in Manhattan convicted Jonathan Spalletta of computer fraud and money laundering for two hacks that drained the decentralized exchange Uranium Finance of more than $50 million in April 2021. Uranium was a DeFi platform where users traded crypto through liquidity pools, smart contracts that hold deposited tokens and set prices automatically without a central operator.
- Jury found Spalletta guilty on all counts after a six-day trial before Judge Jed S. Rakoff
- Second hack on April 28, 2021 pulled roughly $53.3 million and forced Uranium to shut down
- Law enforcement seized about $31 million in crypto from Spalletta in February 2025
- $53.3M extracted in the second Uranium hack, April 28, 2021
- $1.4M taken in the first hack two weeks earlier
- $31M in crypto seized from Spalletta in February 2025
According to the release from the U.S. Attorney’s Office for the Southern District of New York, Spalletta, 36, of Rockville, Maryland, was convicted of one count of computer fraud and one count of money laundering. The computer fraud count carries a maximum ten-year sentence; the money laundering count carries up to 20 years. No sentencing date is listed in the release.
Two Separate Hacks, Two Weeks Apart
On April 8, 2021, Spalletta ran repeated deceptive transactions against Uranium’s smart contract to withdraw far more reward tokens than he was owed, draining the pool of about $1.4 million. He later told someone in writing that he found “a bug in a smart contract” and exploited it, adding “Crypto is all fake internet money anyway,” per the indictment cited in the release.
Uranium then agreed to let him keep roughly $386,000 as a sham “bug bounty” in exchange for returning the rest, which the release characterizes as extortion rather than a negotiated settlement.
Twenty days later, on April 28, 2021, Spalletta exploited a separate error governing withdrawal limits across multiple Uranium liquidity pools. That hack pulled approximately $53.3 million and emptied the platform’s funds entirely, which the release says caused Uranium to shut down.
Laundering Through Tornado Cash And Trading Cards
The release says Spalletta laundered the stolen funds “through a complex series of cryptocurrency transactions, including by using the cryptocurrency mixer Tornado Cash.”
He then converted proceeds into physical collectibles: a Black Lotus Magic: The Gathering card for about $500,000, sealed first-edition Pokémon cards for roughly $1 million combined, Roman antique coins, and a fragment of the Wright brothers’ airplane fabric flown to the moon by Neil Armstrong, purchased for about $137,500.
Investigators seized those items from his residence under a search warrant.
What The Release Does Not Say
The document does not state a sentencing date or say how much restitution, if any, Uranium’s users will recover beyond the $31 million seized in February 2025.
It also does not name which chain or which specific tokens Uranium’s liquidity pools held, nor does it say whether Uranium as an entity or its users have filed separate civil claims. The release directs potential victims to an HSI email address for claims, which suggests restitution proceedings are still open.
What Changes For DeFi Exploit Cases
This is a jury verdict, not a plea, which means SDNY proved intent and the laundering chain to a jury rather than negotiating a settlement. For protocol teams, the case shows prosecutors will pursue smart-contract exploits as computer fraud even when the attacker frames the action as a “bug bounty” negotiation after the fact.
The $31 million seizure in 2025, nearly four years after the hacks, shows how long asset recovery can take even once a mixer like Tornado Cash is used. For liquidity providers on other DEXs, the case is a reminder that reward-calculation bugs and withdrawal-limit errors remain the two exploit categories cited here.
“Spalletta’s crimes cost real people to lose real money, over $50 million dollars, and caused an entire crypto platform to collapse.”
Jamie McDonald, U.S. Attorney for the Southern District of New York, in the Department of Justice release
The CCS read. A jury conviction on a DeFi exploit sends a clearer signal than any civil settlement: code bugs do not create a legal safe harbor, and “it was just a smart contract exploit” is not a defense a jury will buy. Protocols still need audits before launch, not forensic accountants after a hack.
Judge Rakoff has not yet set a sentencing date; that hearing, and any restitution order tied to the $31 million already seized, is the next event to watch.