Jury Rejects 'Code Is Law' Defense, Convicts Uranium Finance Hacker Jonathan Spalletta
Key Takeaways
- •A Manhattan federal jury found Jonathan Spalletta guilty on every count of computer fraud and money laundering after a six-day trial and roughly two hours of deliberation.
- •Spalletta attacked Uranium Finance twice in April 2021, taking about $1.4 million in the first exploit and roughly $53.3 million in a second that targeted 26 liquidity pools.
- •Prosecutors said he spent laundered proceeds on collectibles, including a roughly $500,000 Black Lotus card, about $1.5 million in sealed Alpha Booster packs, and a $601,500 Roman 'Eid Mar' coin.
- •Authorities seized approximately $31 million in cryptocurrency tied to the exploits in February 2025, nearly four years after the first hack.
- •The conviction shows one jury rejected the 'code is law' argument, though its viability in court remains unresolved pending the Eisenberg appeal and the ongoing MEV brothers prosecution.

A federal jury in Manhattan has convicted Jonathan Spalletta of computer fraud money laundering for two April 2021 hacks that drained more than $50 million from decentralized exchange Uranium Finance — a verdict that rejects the "code is law" argument that has occasionally shielded smart-contract exploiters from conviction.
Guilty on every count
The U.S. Attorney's Office for the Southern District of New York announced on Wednesday (statement) that Spalletta, who also used the online handles "Cthulhon" and "Jspalletta," was found guilty on every count in the indictment. The verdict followed a trial before U.S. District Judge Jed S. Rakoff that the Justice Department described as lasting six days.
Jurors returned their decision after roughly two hours of deliberation, according to Inner City Press, which live-tweeted the proceedings from the SDNY courthouse.
U.S. Attorney Jamie McDonald said in the office's statement that Spalletta repeatedly "exploited vulnerabilities in the code of a decentralized cryptocurrency platform" in order to steal tens of millions of dollars.
Two exploits in April 2021
Uranium Finance, a protocol that lets users deposit and swap cryptocurrencies through liquidity pools, was attacked twice by Spalletta in April 2021. The breaches came during a year when smart-contract exploits repeatedly drained DeFi protocols across the industry.
The first attack occurred on April 8, 2021, when he used a looping set of transactions against Uranium's smart contract to claim far more reward tokens than he was owed. He repeated the process until he had pulled out about $1.4 million, draining the pool's rewards.
An even larger breach came on April 28, 2021, when Spalletta exploited a flaw in the contract that controlled how much he could withdraw, targeting 26 separate liquidity pools. The DOJ's original charging announcement (document) stated that Spalletta made off with roughly $53.3 million in that attack and left Uranium without the funds to keep operating.
Prosecutors said that about two weeks after the first exploit, Spalletta wrote to an acquaintance that he had pulled off "a crypto heist of $1.5MM," explaining that there was "a bug in a smart contract" he had exploited, before adding that "Crypto is all fake internet money anyway."
After that first hack, prosecutors say, he pressured Uranium into letting him keep roughly $386,000 as a "bug bounty." The DOJ characterized the arrangement as a sham offered only to shield Spalletta from prosecution.
Does the "code is law" defense work in court?
The "code is law" theory holds that anything a smart contract permits is fair game. It won a rare victory in May 2025, when a judge suspended the fraud convictions of Mango Markets exploiter Avraham Eisenberg, ruling in part that the platform had no terms stating that his conduct was not allowed. Prosecutors are currently appealing that reversal.
In a March 2026 hearing, a lawyer for one of the "MEV brothers" accused of a $25 million Ethereum scheme cited the Eisenberg ruling as precedent for their case.
Despite that history, the fast guilty verdict against Spalletta suggests at least one jury was unmoved by the idea that exploiting a flaw in on-chain code is anything other than theft. With prosecutors' appeal in the Eisenberg case pending and the MEV brothers' prosecution ongoing, how far the theory can carry in court remains unresolved.
How the laundered crypto was spent
Prosecutors said Spalletta spent the laundered funds on high-end collectibles, including a "Black Lotus" Magic: The Gathering card for about $500,000, 18 sealed packs of Alpha Booster Magic cards for roughly $1.5 million, and a sealed box of first-edition Pokémon Booster cards for about $257,500, among other items.
He also bought a Roman "Eid Mar" coin struck to mark the assassination of Julius Caesar for about $601,500. The purchases reportedly also included a piece of fabric from the Wright brothers' original airplane that Neil Armstrong carried to the Moon.
Authorities seized about $31 million in cryptocurrency tied to the exploit in February 2025 — nearly four years after the first hack — and the March indictment marked the first time a defendant was publicly named in the long-dormant investigation. Spalletta, 36, of Rockville, Maryland, surrendered when the charges were unsealed and now faces sentencing in a case that began more than four years before the verdict.
Source: Cryptopolitan