Uranium Finance Hacker Convicted After $50M+ DeFi Drain and Card-Collecting Spree

Market Intel · Just now · Not financial advice

A Manhattan jury has convicted a Maryland man of draining more than $50 million out of the DeFi exchange Uranium Finance — then spending part of it on Pokémon cards and a rare Magic: The Gathering collectible.

Two hacks, three weeks apart

Jonathan Spalletta, 36, of Rockville, Maryland, was found guilty on all counts of computer fraud and money laundering after a six-day trial before Judge Jed S. Rakoff. The first attack landed on April 8, 2021, when he ran a repeated series of transactions against Uranium's smart contract to withdraw far more reward tokens than he was entitled to, netting roughly $1.4 million. Three weeks later he hit a second flaw — this one in how the contract calculated withdrawals across several liquidity pools. That drain pulled about $53.3 million and left Uranium so short of funds that it shut down.

"Fake internet money"

Prosecutors leaned on Spalletta's own messages. About two weeks after the first hack, he wrote to another person that he had done "a crypto heist of $1.5MM," adding that "there was a bug in a smart contract, and I exploited it." His closing thought: "Crypto is all fake internet money anyway."

He also pressured Uranium into letting him keep about $386,000 as a sham bug bounty, in exchange for handing back the rest of the stolen funds. The money then moved through a chain of transactions and the mixer Tornado Cash.

What the money bought

When agents searched his home, they seized a Black Lotus, moon-flown Wright brothers fabric and Roman coins — including one commemorating Julius Caesar's assassination. For collectors, the Black Lotus is the holy grail of Magic: The Gathering. Law enforcement had already grabbed crypto tied to the hacks worth roughly $31 million at the time, back in February 2025.

Why DeFi users should care

Spalletta faces up to 10 years for computer fraud and 20 for money laundering, with the actual sentence left to the judge. For anyone farming or trading onchain, the lesson is uncomfortably simple: this was not a cryptographic break. It was a logic error in the contract, the same class of bug that still turns up in unaudited pools. Code can be patched. Greedy assumptions cannot.

↑ Back to top