Uranium crypto exchange hacker convicted for stealing $53 million
Description
Jonathan Spalletta was convicted for hacking the decentralized crypto exchange Uranium Finance twice in April 2021, stealing over $53 million. He exploited two separate smart contract vulnerabilities to withdraw funds without proper authorization, causing the exchange to shut down. He laundered the stolen cryptocurrency through mixers and decentralized exchanges and used some proceeds to purchase high-value collectibles. Law enforcement recovered about $31 million in assets. Spalletta faces significant prison time for computer fraud and money laundering.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In April 2021, Jonathan Spalletta exploited two distinct flaws in Uranium Finance's smart contract code. The first exploit allowed him to issue zero-token withdrawal commands, draining approximately $1.4 million from the liquidity pool. After extorting a sham bug bounty, he returned for a second attack, exploiting a transaction-verification logic error that used 1,000 instead of 10,000 as a divisor, enabling him to withdraw nearly 90% of the exchange's liquidity pools while depositing effectively zero tokens. This second exploit netted about $53.3 million, forcing Uranium Finance to shut down. Spalletta laundered the stolen funds through Tornado Cash and decentralized exchanges, spending part on expensive collectibles. Law enforcement seized assets and recovered roughly $31 million. He was charged with computer fraud and money laundering.
Potential Impact
The attacker stole over $53 million in cryptocurrency, causing Uranium Finance to shut down due to lack of funds. The theft resulted in significant financial losses for users and the platform. The laundering of stolen funds complicated recovery efforts. Approximately $31 million was recovered by law enforcement. The incident demonstrates the severe financial and operational impact of smart contract vulnerabilities in decentralized finance platforms.
Defensive Guidance
No specific patch or remediation information is provided for the vulnerabilities exploited. Users and operators of decentralized finance platforms should ensure thorough smart contract audits to identify and fix logic errors, particularly in withdrawal and transaction verification functions. Since Uranium Finance shut down after the incident, no direct remediation is available for this platform. Monitoring for suspicious activity and employing multi-layer security controls in smart contract design are recommended to prevent similar exploits.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6ac79bb22cdf04f6561a9083
Added to database: 10/08/2026, 13:33:38 UTC
Last enriched: 10/08/2026, 13:33:45 UTC
Last updated: 10/09/2026, 00:56:19 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.