Maryland Man Convicted in $50M Crypto Theft
The U.S. Department of Justice said Wednesday that Spalletta exploited flaws in the code at Uranium Finance, a now-closed exchange where users swapped tokens through liquidity pools. Citing the indictment and trial evidence, the first…
Briefs Finance
Publisher
Oct 7, 2026 at 11:14 PM UTC · 2 min de lectura

Key Signal
$53.3M Second exploit proceeds
Last Updated
hace un día
The U.S. Department of Justice said Wednesday that Spalletta exploited flaws in the code at Uranium Finance, a now-closed exchange where users swapped tokens through liquidity pools. Citing the indictment and trial evidence, the first breach landed on April 8, 2021, when he chained together deceptive transactions against a smart contract to pull more rewards than authorized, repeating the move until he had about $1.4 million.
He then extorted Uranium, compelling a deal that let him keep about $386,000 as a "bug bounty" in return for giving back the rest of the stolen funds. On April 28, 2021, he executed a second exploit, aiming at a flaw that set limits on the amount of crypto that a liquidity pool was permitted to release. Because the vulnerability extended across multiple pools, he was able to take about $53.3 million. Starved of funds, Uranium Finance shut down.
Crypto theft prosecutions are setting the enforcement playbook as they go. Market Briefs covers crypto crime free every morning.
Where the money went
Authorities say Spalletta pushed the stolen cryptocurrency through a complex maze of transactions. They also say some of it bankrolled splashy buys: around $500,000 for a "Black Lotus" Magic card; about $1.5 million for 18 sealed "Alpha Booster" Magic packs; roughly $257,500 for a sealed first edition Pokémon booster box; and about $750,000 for a complete first edition Pokémon base set.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
