A federal jury in Manhattan convicted cybersecurity consultant Jonathan Spalletta on Wednesday on both counts he faced — computer fraud and money laundering — for the two April 2021 attacks that drained roughly $54.7 million from the BNB Chain decentralized exchange Uranium Finance and forced it to shut down.

The U.S. Attorney's Office for the Southern District of New York announced the verdict on October 7. Spalletta, 36, of Rockville, Maryland — identified by prosecutors through the online aliases "Cthulhon" and "Jspalletta" — was found guilty on every count after a six-day trial before U.S. District Judge Jed Rakoff. Sentencing is scheduled for February 16. The computer fraud count carries a statutory maximum of 10 years in prison and the money laundering count 20 years, with the actual sentence to be determined by the court.

According to prosecutors, the first attack on April 8, 2021 repeatedly invoked a flawed reward-distribution contract to withdraw far more tokens than entitled, netting about $1.4 million. In a message to another person two weeks later, quoted by the government, Spalletta wrote: "I did a crypto heist of $1.5MM a couple of weeks ago . . . There was a bug in a smart contract, and I exploited it . . . Crypto is all fake internet money anyway." Prosecutors said he then pressured Uranium into letting him keep about $386,000 as a sham "bug bounty" while returning the rest.

The second attack on April 28, 2021 exploited an arithmetic error introduced during the project's migration to version 2.1: the pair contracts overstated their own balances by a factor of one hundred, allowing the attacker to drain 26 liquidity pools of approximately $53.3 million. The exchange never reopened. Loss figures vary across sources — prosecution figures for the second attack, incident databases from 2021, and trade press tallies combining both attacks — but the honest range is $53.3 million to $57.2 million, as Cryptoticker documented. Notably, the project had reason to suspect a critical flaw existed, and several prior code reviews had not identified the migration bug as critical.

The defense the jury refused

Spalletta's lawyers argued he had called only publicly accessible functions of the smart contract, forged no credentials and deployed no malicious code — the "code is law" position that whatever a contract permits is therefore allowed. According to Bloomberg, jurors deliberated for a little over two hours before rejecting it on all counts.

The speed matters beyond this case. As Cryptopolitan observed, the same theory previously helped Mango Markets exploiter Avraham Eisenberg win a reversal of his fraud convictions. A unanimous jury has now drawn the line the other way: technical possibility and legal permission are separate questions, and exploiting a known arithmetic defect to take other people's funds is fraud even on permissionless infrastructure.

Tornado Cash to trading cards

Prosecutors traced the laundering chain through a series of cryptocurrency transactions, including the Tornado Cash mixing service, followed by purchases of physical collectibles: a Black Lotus Magic: The Gathering card for about $500,000, 18 sealed Alpha booster packs for approximately $1.5 million, and antique Roman coins for $601,545. The mixer obscured the on-chain trail; the collectibles recreated it off-chain with invoices, sellers and shipping records. Authorities seized about $31 million in cryptocurrency and collectibles on February 24, 2025 — roughly half the theft by value — and federal investigators have provided a contact for victims.

For DeFi users the practical takeaway predates the verdict: the flaw sat in migration code that users were asked to migrate into, survived multiple reviews, and the protocol's collapse left depositors with no counterparty for five years. A conviction, however satisfying, is not compensation. Code review depth on migrated contracts — and the speed of independent verification — remains the control that matters.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.