
A Manhattan federal jury convicted a Maryland cybersecurity consultant of stealing about $55 million in cryptocurrency, money prosecutors say he partly spent on rare Pokémon and Magic cards, on Wednesday, October 7.
Story Highlights
- Jonathan Spalletta, 36, of Rockville, Maryland, was found guilty of computer fraud and money laundering on every count.
- Prosecutors say he drained a crypto exchange called Uranium Finance in two 2021 hacks by abusing flaws in its computer code.
- Prosecutors say he hid the money’s trail through a crypto mixer, then bought a $750,000 first-edition Pokémon set and a $500,000 “Black Lotus” Magic card.
- He faces up to 10 years for computer fraud and up to 20 years for money laundering when a judge sentences him.
What the Jury Found and Why
The jury found that Spalletta, a cybersecurity consultant, used weak spots in Uranium Finance’s code to take far more money than he was owed, then washed the stolen coins so they would be hard to trace. Uranium Finance was a crypto exchange, an online marketplace where people deposit and trade digital money such as Bitcoin. A hack, in this case, meant using the exchange’s own software against it: he sent a series of transactions that tricked the system into paying out money that belonged to other users.
Crypto hacker Jonathan Spalletta (“Cthulhon”) found guilty after turning himself in. The Maryland cybersecurity consultant was convicted of hacking Uranium Finance in 2021 for over $50 million and laundering the funds through Tornado Cash. The theft forced the exchange to shut… pic.twitter.com/TxlOeqXwBs
— Crumb (@CrumbOSRS) October 7, 2026
The trial ran six days before U.S. District Judge Jed Rakoff, a longtime federal judge in Manhattan. Jurors began deliberating Tuesday afternoon and returned guilty verdicts Wednesday after a little more than two hours of talks, according to reports. Jamie McDonald, the U.S. Attorney for the Southern District of New York, said Spalletta “repeatedly exploited vulnerabilities” and that his crimes “cost real people to lose real money—over $50 million dollars—and caused an entire crypto platform to collapse.”
The Shopping List Prosecutors Laid Out
According to prosecutors, Spalletta spent part of the stolen money on high-end collectibles. The government listed these purchases and their rough prices:
- A complete first-edition Pokémon base set, about $750,000
- A sealed box of first-edition Pokémon booster packs, about $257,500
- A “Black Lotus” Magic: The Gathering card, one of the rarest cards in that game, about $500,000
- 18 sealed “Alpha” Magic booster packs from the game’s first print run, about $1.5 million
- An ancient Roman coin known as the “Eid Mar” denarius, about $601,545
- A piece of fabric from the Wright brothers’ airplane, about $137,500
Agents later seized the Black Lotus card, the airplane fabric and some antique coins from his home under a search warrant, prosecutors say. In February 2025, law enforcement also seized cryptocurrency linked to the thefts that was worth about $31 million at the time.
How the Two Hacks Worked
The first attack came on April 8, 2021. Prosecutors say Spalletta found a flaw in the part of Uranium’s system that paid out rewards to users. He repeated the same set of transactions until the rewards pool was nearly empty, taking about $1.4 million. Two weeks later, he wrote to another person that he had pulled off a “$1.5MM” heist.
Prosecutors say he then pressured Uranium into a deal. He returned most of the money but kept about $386,000, calling it a “bug bounty.” A bug bounty is a reward a company pays to someone who finds and reports a flaw in its software. Prosecutors called this one a sham.
The second attack came on April 28, 2021. Prosecutors say he used a mistake in the code that limited how much money users could withdraw, and pulled about $53.3 million out of the exchange’s pools of customer funds. Uranium ran out of money and shut down.
Hiding the Money Trail
Prosecutors say Spalletta then ran the stolen coins through Tornado Cash, a crypto mixer. A mixer is a service that pools coins from many users and shuffles them together, which makes it hard to tell where any one person’s money came from. From there, prosecutors say, he moved the money through a chain of complex trades before spending it.
His own messages became part of the case. Prosecutors say he wrote that “crypto is all fake internet money anyway,” and told a Uranium representative, “Get your code audited next time.” McDonald said of the “fake internet money” line, “those words could not be further from the truth.”
What the Defense Argued
His defense lawyers argued that prosecutors could not prove “whose fingers were on the keyboard,” according to reports. They said Spalletta did not write Uranium’s faulty code, did not break past any locks or use fake passwords or harmful software, and only used functions that anyone could reach. They also described Tornado Cash as a privacy tool. The jury rejected those arguments on both counts.
What Comes Next
Judge Rakoff will decide Spalletta’s sentence. Computer fraud carries a maximum of 10 years in prison and money laundering a maximum of 20 years, but those are upper limits, and the judge sets the actual term. Sentencing is set for Feb. 16, according to reports. The case was investigated by Homeland Security Investigations, and federal prosecutors have asked anyone who believes they lost money in the Uranium hacks to contact that agency.
For everyday investors, the verdict carries a plain lesson. Stealing from people through a crypto platform is still stealing, and the trail of a big theft can lead investigators straight to a collector’s shelf. Clear rules and steady enforcement help protect the savings of honest people who use these platforms.
Sources:
news.bloomberglaw.com, bloomberg.com, gizmodo.com, news.bitcoin.com, ground.news, crypto.news









