U.S. prosecutors charged Jonathan Spalletta of Rockville, Maryland, with computer fraud and money laundering for allegedly exploiting vulnerabilities in Uranium Finance smart contracts and stealing more than $50 million from the decentralized exchange in 2021. According to the unsealed indictment in the Southern District of New York, Spalletta — also identified as “Cthulhon” and “Jspalletta” — first exploited the platform’s rewards mechanism on April 8, 2021, taking about $1.4 million, then later drained roughly $53.3 million from 26 liquidity pools in a second attack that helped force Uranium Finance to shut down.
Authorities said they seized about $31 million in cryptocurrency tied to the case in February 2025 and alleged that Spalletta laundered the proceeds through multiple transactions, including use of Tornado Cash and another cryptocurrency mixer. Prosecutors also said he spent stolen funds on high-value collectibles, including rare Magic: The Gathering cards, Pokémon sets, and a Roman Eid Mar coin. Spalletta has surrendered to authorities and is expected to appear before a U.S. magistrate judge in Manhattan; if convicted, he faces up to 10 years in prison for computer fraud and 20 years for money laundering.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
Homeland Security Investigations San Diego said it is seeking additional victims connected to the Uranium Finance hack as the criminal case against Jonathan Spalletta proceeds. The appeal indicates investigators believe more affected parties may exist beyond those already described in the indictment.
Federal prosecutors unsealed an indictment in the Southern District of New York charging Jonathan Spalletta with computer fraud and money laundering for the 2021 Uranium Finance exploits. Spalletta surrendered to authorities and was expected to appear before a U.S. magistrate judge in Manhattan.
U.S. authorities seized approximately $31 million in cryptocurrency connected to the Uranium Finance case. The seizure occurred before charges were publicly announced.
According to the indictment, the stolen cryptocurrency was laundered through multiple transactions, including Tornado Cash or another crypto mixer, and some proceeds were used to buy high-value collectibles such as trading cards, Pokémon sets, and a Roman coin. This describes the post-hack movement and use of funds.
Prosecutors allege Spalletta later exploited Uranium Finance smart-contract vulnerabilities again, extracting about $53.3 million from 26 liquidity pools. The losses from the 2021 attacks contributed to Uranium Finance shutting down.
After the initial exploit, prosecutors say Spalletta negotiated a sham bug bounty arrangement that allowed him to retain roughly $386,000 of the stolen cryptocurrency. This was part of the aftermath of the first hack.
Prosecutors allege Jonathan Spalletta first exploited a vulnerability in Uranium Finance's rewards mechanism, stealing about $1.4 million. The event is described as the first of the 2021 exploits against the platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcecoindesk.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.