A federal jury in Manhattan is deciding what, exactly, counts as stealing in decentralized finance. Jonathan Spalletta, a 36-year-old cybersecurity consultant from Maryland, is on trial for computer fraud and money laundering over two 2021 exploits that prosecutors say drained roughly $53.3 million from the decentralized exchange Uranium Finance and forced the protocol to shut down for lack of funds.
Opening statements began Monday, September 29, in the Southern District of New York, reported by Law360. The indictment was unsealed on March 30, 2026,Spalletta surrendered and was presented before U.S. Magistrate Judge Ona T. Wang, per the Justice Department announcement. The case is assigned to U.S. District Judge Jed S. Rakoff. Spalletta has pleaded not guilty. The most serious charge, money laundering, carries up to 20 years.
Two hacks, five weeks apart
Prosecutors say Spalletta hit the DEX twice in April 2021. The first attack, on or about April 8, took roughly $1.4 million by exploiting a bug in a smart contract. In the words the government says he used himself in writing to another individual, “There was a bug in a smart contract, and I exploited it.” The larger attack came two weeks later, on April 28, when an error in the Uranium contract that governed withdrawal limits across liquidity pools let him extract cryptocurrency worth approximately $53.3 million across 26 separate pools. Uranium Finance shut down afterward because it had no funds left. Bloomberg put the total closer to $55 million; mlex reports prosecutors at roughly $53.3 million, a discrepancy the two outlets have not reconciled.
The man charged used the online aliases “Cthulhon” and “Jspalletta,” per the DOJ. He was working in cybersecurity at the time, which is the detail that makes the trial a bigger story than one theft. A week before the second exploit, Spalletta allegedly wrote to someone, “Crypto is just fake internet money anyway.” The then-U.S. attorney for SDNY, in the DOJ release announcing charges, drew a straight line under the idea that code is different from locks: “Stealing from a crypto exchange is stealing. The claim that ‘crypto is different’ does not change that. For the victims, there is nothing different about having your money taken.”
Where the defense draws its line
The defense argument matters beyond this defendant. Spalletta’s lawyer, Shrey Sharma, does not deny that his client interacted with Uranium Finance. He argues Spalletta used publicly available functions built into the exchange’s own smart contracts, the buttons the code itself exposed, rather than bypassing any access control with stolen credentials or injected code. In a system designed to let anyone execute any function the contract exposes, what separates a user from an attacker is intent, not the call. That is the question a jury now has to grade.
The defense also targets attribution on the money trail. Bloomberg reports that the collectible purchases, rare Pokmon and Magic: The Gathering trading cards, did not begin until 2023, two years after the exploit, and that prosecutors have no direct proof the crypto drawn out of Uranium is the same crypto that paid for the cards. Proof of specific lacing in crypto flows is hard to establish to a criminal standard when assets move through mixers and bridges.
Prosecutors put the chat logs in front of the jury. Law360 reports that on Thursday, October 1, the jury was shown threads purporting to show Spalletta saying “I did a crypto heist” and, after the second attack, “I did a crypto heist of $1.5MM a couple of weeks ago. There was a bug in a smart contract, and I exploited it.” That self-description is the prosecution’s cleanest exhibit, taking the case out of gray-zone smart contract theory and into plain theft.
The card spending gets the headlines, the exploitation gets the risk case
The colorful detail, that an alleged crypto thief spent stolen funds on rare collectible trading cards, will carry the press coverage. It is also the least important part. What the trial actually tests is a question DeFi has never cleanly answered: if code is exposed onchain and available to anyone, does calling its widest-open function carry criminal liability, or is that just fast liquidity extraction of a badly designed contract? Most protocols patch these bugs within hours and call it a loss. Uranium did not survive it.
Civil regulators and securities prosecutors have run this lane repeatedly. A $53.3 million exploit across 26 liquidity pools in a single afternoon is the kind of event that tends to produce a criminal indictment only years later, once attribution tools catch up. Chainalysis and similar firms have made cross-chain tracing routine. Spalletta’s alleged move through Tornado Cash was reported by Gate News as part of the asset flow, a path that once looked clean and now is one of the strongest points a prosecutor can present.
The trial is a test with a name attached. For projects, it is a reminder that the frame around a smart contract bug shifts depending on what a jury thinks the defendant’s intent was, not on whether the contract allowed the call. Jurors are not protocol engineers. They will read chat logs, spending patterns and timing, and weigh them against a defense that says, essentially, the door was open.
No verdict has been reached. The charges remain allegations until the jury returns one, and both sides have presented cases the record will keep even if the verdict lands either way.
