Skip to main content

Morning Overview

A Maryland man was convicted of hacking a crypto exchange twice and stealing more than $53 million

A federal jury in Manhattan convicted Jonathan Spalletta, 36, of Rockville, Maryland, on all counts for draining the decentralized exchange Uranium Finance in two separate attacks in April 2021. The second one alone took about $53.3 million and ended the platform, according to the U.S. Attorney’s Office for the Southern District of New York.

Prosecutors say the money went into rare trading cards, an ancient Roman coin and a swatch of Wright brothers airplane fabric.

Two exploits, three weeks apart

The Southern District’s conviction announcement, issued Oct. 7 after a six-day trial before U.S. District Judge Jed S. Rakoff, describes two hacks of Uranium, an exchange built on smart contracts rather than a company ledger. On April 8, 2021, Spalletta withdrew far more reward tokens than he was entitled to and pulled out about $1.4 million. He then bargained with Uranium to keep roughly $386,000 as a sham “bug bounty” and returned the rest.

The second attack came on April 28, 2021. Prosecutors say he exploited an error in the contract’s withdrawal limits across multiple liquidity pools and took about $53.3 million. Uranium shut down for lack of funds. Counting both attacks, the exchange lost more than $53 million to a single user, with about $1.4 million taken on April 8 and about $53.3 million on April 28, a total that prosecutors headlined as “over $50 million” and that BleepingComputer reported as a $53 million theft. The two incidents were separate exploits of the same platform, three weeks apart, and the sham bounty deal after the first is part of what prosecutors describe as extortion of the exchange.

A missing zero in the contract

The mechanics are laid out in BleepingComputer’s account of the verdict: a transaction check that used 1,000 where the code needed 10,000, which let the attacker withdraw almost 90 percent of a pool’s assets while depositing effectively nothing. CoinDesk reported the loss the day it happened, tracing it to a missing zero in the section of the v2 contracts that manages reserves, and recorded that the attack landed about two hours before a fixed v2.1 version went live. BNB and BUSD pools lost about $18 million each in that report’s tally.

The conviction covers computer fraud, which carries a maximum of 10 years, and money laundering, which carries a maximum of 20. No sentencing date has been announced, and Gizmodo reported that a judge is expected to set the sentence next year.

Blockchain sleuthing also fed the case. BleepingComputer reports that the on-chain investigator ZachXBT linked more than 11,200 ETH, worth about $25 million at the time, that came out of Tornado Cash in December 2023 to the person behind the hack, a trail that preceded the seizures of 2025 by more than a year. The same account says Spalletta surrendered to authorities on March 30 and that investigators recovered about $31 million in cryptocurrency from wallets tied to him, the same sum the Justice Department puts at seizure value.

Tornado Cash and the collectibles

Moving the money was a separate offense from taking it. Prosecutors say Spalletta laundered the proceeds through the Tornado Cash mixer and then spent them on objects that could be held in a safe. The release lists a “Black Lotus” Magic: The Gathering card at about $500,000, 18 sealed Alpha Booster packs at about $1.51 million, a first-edition Pokemon base set at about $750,000, a sealed first-edition Pokemon booster box at about $257,500, Wright brothers airplane fabric at about $137,500 and an “Eid Mar Denarius” Roman coin at about $601,545.

The March 30, 2026 charging announcement records that Spalletta surrendered that day and appeared before Magistrate Judge Ona T. Wang. Law enforcement had already seized about $31 million in cryptocurrency obtained from Uranium on Feb. 24, 2025, and BleepingComputer reports that the collectibles were taken from his home that month.

Fake internet money and the verdict

Prosecutors quoted a message Spalletta sent about two weeks after the first hack: “Crypto is all fake internet money anyway.” The line anchors the government’s case, which treated the exploits as theft even though the contract code technically allowed each withdrawal to execute. Gizmodo’s report quotes a second message, in which Spalletta told someone that he had done a “crypto heist of $1.5MM a couple of weeks ago,” a figure that matches the first hack rather than the far larger second one, which had not yet happened. U.S. Attorney Jamie McDonald said Spalletta “repeatedly exploited vulnerabilities in the code of a decentralized cryptocurrency platform.”

Anyone who believes Uranium cost them money can write to [email protected], an address Homeland Security Investigations set up for the case. The prosecution came from the office’s Complex Frauds and Cybercrime Unit, with Assistant U.S. Attorneys Kevin Mead, William C. Kinder and Shaun Werbelow handling the trial, and Homeland Security Investigations praised by McDonald for the investigation. Spalletta faces sentencing on a computer fraud count capped at a decade and a laundering count capped at two.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.