A New York jury has convicted cybersecurity consultant Jonathan Spalletta of computer fraud and money laundering over two Uranium Finance attacks that drained nearly $55 million, with the money laundering count carrying up to 20 years in prison.
Summary
- Spalletta was convicted on both counts after a six-day federal jury trial in Manhattan.
- Prosecutors traced the theft to two April 2021 attacks that forced Uranium Finance to close.
- Authorities seized about $31 million in cryptocurrency and rare collectibles tied to the stolen funds.
- Sentencing is set for Feb. 16, while federal investigators have provided a contact for victims.
The U.S. Attorney’s Office for the Southern District of New York announced on Oct. 7 that Spalletta, 36, of Rockville, Maryland, had been found guilty on every count in his indictment following a trial before U.S. District Judge Jed Rakoff.
According to Bloomberg, jurors deliberated for more than two hours before returning their verdict, and Rakoff scheduled sentencing for Feb. 16. The report said defense lawyers had argued that Spalletta used publicly available smart contract functions rather than forged credentials or malicious code.
Uranium Finance convictions carry separate prison limits
In its statement, the U.S. Attorney’s Office said the computer fraud count carries a maximum prison term of 10 years, while the money laundering count carries a maximum of 20 years. The office stressed that Congress sets those limits and that a judge will determine the actual sentence.
Earlier in the case, crypto.news reported on March 31 that federal authorities had charged the Maryland resident over the two attacks. The report identified computer fraud and money laundering as the charges and described the losses as exceeding $54 million.
At the indictment stage, the Justice Department said Spalletta surrendered on March 30 and was due to appear before U.S. Magistrate Judge Ona T. Wang. Prosecutors identified him by the online aliases “Cthulhon” and “Jspalletta,” and assigned the case to the office’s Complex Frauds and Cybercrime Unit.
In announcing the verdict, U.S. Attorney Jamie McDonald said a unanimous Manhattan jury had found that Spalletta repeatedly used weaknesses in the platform’s code to take users’ cryptocurrency. The office said its account of the attacks drew on the indictment, public filings and evidence presented during the trial.
Two April attacks drained rewards and trading pools
According to prosecutors, Uranium Finance allowed users to deposit and exchange cryptocurrencies through liquidity pools. Spalletta’s first attack, on April 8, 2021, targeted a smart contract that paid cryptocurrency rewards.
By repeating a series of transactions, prosecutors said, he withdrew far more rewards than he was entitled to receive and drained nearly all the reward tokens from the affected pool. The office valued the cryptocurrency taken in that attack at approximately $1.4 million.
In a written message sent about two weeks later, Spalletta described his actions to another person, according to the prosecution:
“I did a crypto heist of $1.5MM a couple of weeks ago . . . There was a bug in a smart contract, and I exploited it . . . Crypto is all fake internet money anyway.”
After that theft, the office said, Spalletta pressured Uranium into accepting an arrangement under which he kept about $386,000 and returned the remaining funds. Prosecutors described the retained payment as a sham “bug bounty” intended to help him avoid prosecution.
For the second attack, on April 28, prosecutors said he exploited an error in the contract governing withdrawals from liquidity pools. The original charging announcement identified 26 affected pools and put the stolen cryptocurrency at about $53.3 million, while the conviction announcement said the loss forced Uranium to shut down.
In April 2021, reporting on the platform’s $50 million breach cited Uranium’s announcement that the incident occurred during its migration to version 2.1. The same report said the project was working with Binance’s security team and had asked users to report the stolen funds through their Binance accounts.
Prosecutors traced laundering and multimillion-dollar card purchases
Following the attacks, the U.S. Attorney’s Office said Spalletta moved the stolen assets through a series of cryptocurrency transactions, including the mixing service Tornado Cash, before spending part of the proceeds on collectibles.
Separate reporting in January 2024 documented a 2.5 million BUSD transfer from an address labeled as the Uranium exploiter. Citing PeckShield, the report said the funds moved from BNB Chain to Ethereum through Li.fi, with the receiving address obtaining 812 ETH and about $505,500 in stablecoins.
Among Spalletta’s purchases, prosecutors listed a Black Lotus Magic: The Gathering card costing about $500,000 and 18 sealed Alpha Booster packs costing approximately $1,512,500. The office also identified a sealed box of first-edition Pokémon booster packs bought for about $257,500 and a complete first-edition Pokémon base set costing approximately $750,000.
Beyond trading cards, prosecutors said he paid about $601,545 for an Eid Mar Denarius, an ancient Roman coin commemorating Julius Caesar’s assassination. Another purchase, according to the office, was a $137,500 piece of fabric from the Wright brothers’ original airplane that Neil Armstrong later carried to the moon.
U.S. investigators seized assets and provided a victim contact
Under a court-authorized search warrant, investigators seized the Black Lotus card, the aircraft fabric and ancient coins from Spalletta’s residence, the Justice Department said. Bloomberg reported that rare Pokémon and Magic: The Gathering cards seized from the Maryland home were worth more than $3 million.
Separately, the U.S. Attorney’s Office said law enforcement seized cryptocurrency linked to the Uranium thefts on Feb. 24, 2025. Those assets were worth approximately $31 million at the time of seizure.
For affected users, the office’s Oct. 7 announcement directs anyone who believes they were a victim of the Uranium hack to contact Homeland Security Investigations at [email protected].
Powered by WPeMatico