Uranium Finance Hacker Convicted Over $53.3M DeFi Theft

Nick Sawinyh on 08 Oct 2026

At 18:02 UTC on October 7, 2026, the U.S. Attorney’s Office for the Southern District of New York announced that a Manhattan jury had convicted Jonathan Spalletta over hacks that took more than $50 million from Uranium Finance. The corresponding Justice Department release, numbered 26-285, says jurors found him guilty of computer fraud and money laundering after a six-day trial before U.S. District Judge Jed S. Rakoff.

Spalletta, 36, of Rockville, Maryland, was convicted on every count in the indictment. The computer fraud count carries a maximum prison sentence of 10 years. The money laundering count carries a maximum of 20 years. Those are statutory maximums, and the judge will determine the sentence. The release does not give a sentencing date.

How the two attacks worked

Uranium Finance was a decentralized exchange where users deposited and exchanged cryptocurrencies through liquidity pools. Prosecutors said Spalletta attacked it twice in April 2021. The methods differed, but each abuse let him withdraw assets beyond what the protocol authorized.

The first attack occurred on April 8, 2021. According to the trial evidence described by the Justice Department, Spalletta sent a deceptive series of transactions to Uranium’s smart contract. Those transactions returned more reward tokens than he was entitled to receive. He repeated the sequence until the liquidity pool held almost none of its reward tokens, extracting approximately $1.4 million in cryptocurrency.

About two weeks later, Spalletta described the episode in writing to another person. The message quoted in the release said: “I did a crypto heist of $1.5MM a couple of weeks ago . . . There was a bug in a smart contract, and I exploited it . . . Crypto is all fake internet money anyway.”

The protocol recovered part of the first loss, but prosecutors did not characterize the arrangement as a legitimate disclosure process. They said Spalletta extorted Uranium into letting him retain approximately $386,000 as a sham bug bounty in exchange for returning the rest. For protocol operators, that account draws a clear line between a bounty negotiated after unauthorized withdrawals and a security program that defines permission, scope, and payment before testing begins.

The second attack occurred on April 28, 2021. This time, Spalletta exploited an error in the smart contract’s calculation of how much cryptocurrency a user could withdraw from a liquidity pool. He applied the issue across multiple Uranium pools and obtained approximately $53.3 million. Uranium then shut down because it lacked funds.

The verdict establishes criminal liability for both attacks, but it does not restore the pools or reopen the exchange. For former liquidity providers, the useful parts of the release concern assets seized by investigators and the channel for identifying victims.

What the verdict establishes

The jury convicted Spalletta after hearing the indictment, public filings, and evidence presented at trial. The Justice Department’s account attributes both attacks to him, specifies the contract behavior exploited in each one, and records the amounts obtained. The conviction covers the unauthorized withdrawals and the subsequent movement of the proceeds.

U.S. Attorney Jamie McDonald focused on the effect on depositors. He said Spalletta’s crimes cost people more than $50 million and caused the platform to collapse. McDonald also quoted Spalletta’s statement that crypto was “fake internet money” and said the victims’ losses showed the opposite. The statement matters because the case treated losses from a decentralized exchange as losses to identifiable people, even though users interacted with smart contracts and liquidity pools rather than a conventional trading venue.

The verdict also distinguishes the initial exploit from the later handling of funds. Computer fraud covers one count and money laundering covers a separate count. Prosecutors said Tornado Cash formed part of the laundering sequence, while the collectible purchases documented where some proceeds went after that sequence.

The Southern District’s Complex Frauds and Cybercrime Unit prosecuted the case. Assistant U.S. Attorneys Kevin Mead, William C. Kinder, and Shaun Werblow handled the prosecution, and McDonald credited Homeland Security Investigations for its work.

Laundering, seizures, and victim claims

Prosecutors said Spalletta moved the stolen assets through a complex sequence of cryptocurrency transactions that included Tornado Cash. The release does not identify the routes, transaction hashes, assets, or destination addresses. It therefore supports the laundering verdict and the use of the mixer, but it does not provide an on-chain reconstruction that users can independently follow.

The spending record presented at trial was unusually specific. The Justice Department said Spalletta used stolen funds to buy a Black Lotus Magic: The Gathering card for approximately $500,000 and 18 sealed Alpha Booster packs for approximately $1,512,500. He also bought a sealed box of first-edition Pokémon booster packs for approximately $257,500 and a complete first-edition Pokémon base set for approximately $750,000.

Other purchases included an Eid Mar denarius, a Roman coin commemorating Julius Caesar’s assassination, for approximately $601,545. Spalletta also paid approximately $137,500 for fabric from the original Wright brothers’ airplane that Neil Armstrong later carried to the moon. Investigators seized the Black Lotus card, the airplane fabric, and some antique coins from his home under a court-authorized search warrant.

The largest disclosed recovery is cryptocurrency seized on February 24, 2025. The Justice Department valued it at approximately $31 million at the time of seizure and said it came from the Uranium hacks. The release does not say which assets were seized, how their value changed after seizure, or what portion may ultimately be available to victims.

Former Uranium users should not treat the conviction as proof that a claim has been recorded. The Justice Department directs anyone who believes they were a victim of the Uranium hack to contact UraniumVictims@hsi.dhs.gov. The unresolved question is how the seized cryptocurrency and physical collectibles will be handled, and how much of their value will reach verified victims. The release provides no distribution schedule or sentencing date.

DeFi is coming. Don't get left behind

About the author
Nick Sawinyh founded DeFiprime in 2019 and has edited it ever since. His current editorial focus is stablecoin infrastructure, real-world assets on-chain, DeFi yield and risk, and crypto regulation. Based on the East Coast, US. He holds small positions across a range of crypto assets; nothing he publishes is investment advice.

More from the blog