U.S. jury finds Spaletta guilty in the $53.3 million Uranium Finance hack case
A U.S. court has found Spaletta guilty of computer fraud and money laundering over two attacks on the now-defunct Uranium Finance platform in April 2021. For anyone running a crypto venue or a PSP touching crypto flows, the useful part is simple: smart-contract bugs still turn into very expensive shutdowns, and the money can move through mixers and collectibles before law enforcement catches up.
- According to prosecutors, Spaletta exploited a vulnerability in Uranium Finance’s code twice in April 2021. Uranium Finance let users deposit and swap cryptocurrencies through liquidity pools, and the first attack on 8 April 2021 used repeated smart-contract manipulations to drain rewards and eventually empty the pool. The stolen crypto in that first incident was worth about $1.4 million.
- After that first hack, prosecutors say Spaletta persuaded Uranium to pay him $386 000 as a bug bounty in exchange for returning the stolen funds. That did not end the story. On 28 April 2021, he allegedly used another smart-contract error affecting the amount of crypto available for withdrawal from liquidity pools, hitting several pools at once and stealing cryptoassets worth $53.3 million. The platform then shut down because it did not have enough funds.
- The stolen cryptoassets were laundered through Tornado Cash, according to the case. Prosecutors also say the proceeds were used to buy collectibles, including a Black Lotus Magic: The Gathering card for $500 000, 18 sealed Alpha Magic: The Gathering booster packs for $1.5 million, rare Pokémon cards, a fragment of the Wright brothers’ original aircraft skin that Neil Armstrong had taken to the Moon, and an ancient Roman coin called the Eid Mar for $601 545.
- In February 2025, law enforcement confiscated $31 million in cryptocurrency from the collector. Spaletta was convicted on one count of computer fraud, which carries up to ten years in prison, and one count of money laundering, which carries a maximum sentence of 20 years. Sentencing is due next year.
The case sits in the same category as a lot of high-risk crypto operations never want to read about at all: code-level failure, liquidity extraction, and a cleanup trail that goes through mixers and asset purchases. It is also a reminder that “bug bounty” negotiations do not necessarily close exposure once the same actor can keep working the same system.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!