A federal jury in Manhattan has convicted cybersecurity consultant Jonathan Spalletta over two 2021 attacks on Uranium Finance that prosecutors said drained nearly $55 million from the platform and ultimately led to its closure.

The U.S. Attorney’s Office for the Southern District of New York said on Oct. 7 that Spalletta, 36, of Rockville, Maryland, was found guilty on every count in his indictment after a six-day trial before U.S. District Judge Jed Rakoff. He was convicted of computer fraud and money laundering.

Verdict and possible sentence

According to Bloomberg, jurors deliberated for more than two hours before returning a unanimous verdict. Rakoff scheduled sentencing for Feb. 16.

Federal prosecutors said the computer fraud count carries a maximum prison term of 10 years and the money laundering count carries a maximum of 20 years. The U.S. Attorney’s Office noted that those are statutory limits set by Congress and that the judge will decide the actual sentence.

Defense lawyers, according to Bloomberg, argued that Spalletta had relied on publicly available smart contract functions rather than forged credentials or malicious code. Prosecutors, however, said the evidence showed he repeatedly used weaknesses in Uranium Finance’s code to take users’ cryptocurrency.

How prosecutors say the attacks unfolded

Uranium Finance operated through liquidity pools that let users deposit and exchange crypto assets. Prosecutors said the first attack took place on April 8, 2021, and targeted a smart contract that distributed rewards. By repeating a sequence of transactions, Spalletta allegedly withdrew far more than he was entitled to and emptied nearly all reward tokens from the affected pool. The government valued that theft at about $1.4 million.

Roughly two weeks later, prosecutors said, Spalletta wrote to another person that he had carried out a '$1.5MM' crypto heist by exploiting a smart contract bug. After that incident, the government said, he pushed Uranium Finance into an arrangement under which he kept around $386,000 and returned the rest, describing the retained amount as a sham bug bounty meant to avoid prosecution.

The second attack, according to prosecutors, came on April 28, 2021 and exploited an error in the contract handling liquidity-pool withdrawals. The original charging announcement said 26 pools were affected and put the stolen amount at about $53.3 million. Prosecutors said the losses from the two incidents forced Uranium Finance to shut down.

Tracing funds and high-value purchases

After the attacks, prosecutors said Spalletta moved stolen assets through a chain of crypto transactions, including the mixing service Tornado Cash, and used part of the proceeds to buy rare collectibles. The U.S. Attorney’s Office tied several multimillion-dollar purchases to those funds.

The items listed by prosecutors included a Black Lotus Magic: The Gathering card bought for about $500,000, 18 sealed Alpha Booster packs costing roughly $1.51 million, a sealed box of first-edition Pokémon booster packs for about $257,500, and a complete first-edition Pokémon base set valued at approximately $750,000.

Prosecutors also cited other purchases, including an Eid Mar Denarius, an ancient Roman coin, for about $601,545, and a piece of fabric from the Wright brothers’ original airplane that Neil Armstrong later carried to the moon, bought for about $137,500. Bloomberg separately reported that rare Pokémon and Magic cards seized from Spalletta’s Maryland home were worth more than $3 million.

Seizures and what comes next

The Justice Department said investigators, acting under a court-authorized search warrant, seized the Black Lotus card, the aircraft fabric and ancient coins from Spalletta’s residence. Separately, law enforcement seized cryptocurrency linked to the Uranium Finance thefts on Feb. 24, 2025. The government said those digital assets were worth about $31 million at the time of seizure.

The case had first been announced earlier this year, when federal authorities said Spalletta surrendered on March 30. Prosecutors identified him by the online aliases 'Cthulhon' and 'Jspalletta' and assigned the matter to the Southern District’s Complex Frauds and Cybercrime Unit.

For people who believe they were affected by the Uranium Finance hacks, federal investigators have provided a contact point through Homeland Security Investigations. Sentencing on Feb. 16 is the next confirmed step in the case.

Source: crypto.news