{"investigation":{"slug":"uranium-finance","entity_name":"Uranium Finance","trust_score":4,"severity_base":null,"score_modifier":0,"confidence":0.95,"status":"published","content_type":"investigation","summary":"Uranium Finance was a Binance Smart Chain-based automated market maker (AMM) that was exploited twice in April 2021, resulting in total losses of approximately $54.7 million. The larger exploit on April 28, 2021, drained roughly $53.3 million across 26 liquidity pools due to a mathematical error in its forked Uniswap v2 pair contracts; the protocol subsequently shut down permanently. In March 2026, U.S. authorities indicted Jonathan Spalletta, a Maryland resident, on computer fraud and money laundering charges in connection with both attacks, after previously seizing approximately $31 million in cryptocurrency in February 2025.","sections":[{"content":"Uranium Finance was a decentralized exchange and automated market maker (AMM) operating on the Binance Smart Chain (BSC). Its codebase was forked from Uniswap v2. The project launched its v2 contracts and attracted over $50 million in total value locked (TVL) within approximately one month of its Twitter account being created, a pace that drew skepticism from community observers. The protocol ceased operations permanently following the April 28, 2021 exploit, leaving all liquidity providers without recovery.","heading":"Overview","sources":[{"url":"https://cointelegraph.com/news/50m-reportedly-stolen-from-bsc-based-uranium-finance","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/50m-drained-from-uranium-finance-hack-or-rug-pull/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://rekt.news/uranium-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"On or about April 8, 2021, an attacker exploited a flaw in Uranium Finance's rewards distribution smart contract. The vulnerability involved the AmountWithBonus variable, which the attacker manipulated by issuing zero-token withdrawal commands that caused the exchange to pay out liquidity rewards the attacker was not entitled to receive. Approximately $1.4 million was drained from the liquidity pool. Following the breach, the attacker negotiated a resolution with the Uranium team, returning the majority of funds while retaining approximately $386,000, which the team agreed to classify as a bug bounty payment. U.S. prosecutors later characterized this arrangement as a sham bug bounty, alleging the retained funds were extorted rather than legitimately earned. The retained $386,000 was subsequently laundered through Tornado Cash.","heading":"First Exploit — April 8, 2021 (~$1.4 Million)","sources":[{"url":"https://www.coindesk.com/policy/2026/03/31/maryland-man-charged-in-usd50-million-uranium-finance-hack-after-u-s-seized-usd31-million-in-crypto","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2026/03/31/u-s-authorities-charge-hacker-behind-54m-uranium-finance-hack/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 28, 2021, a far larger attack drained approximately $53.3 million (commonly cited as ~$57.2 million at peak valuations) from Uranium Finance's v2 pair contracts. The attack exploited a single mathematical error in the UraniumPair contract forked from Uniswap v2. Developers had changed the constant '1,000' to '10,000' in two locations within the balance modifier logic, but failed to update the corresponding sanity check in the swap function, which continued to use '1,000' squared (1,000,000) rather than the updated '10,000' squared (100,000,000). This 100x discrepancy in the invariant check allowed an attacker to send as little as 1 wei of an input token and withdraw approximately 98% of the output token reserve from each pair. The attacker exploited this across 26 separate liquidity pools in a single transaction sequence. Assets extracted included approximately 34,000 WBNB (~$18 million), 17.9 million BUSD (~$17.9 million), 1,800 ETH (~$4.7 million), 80 BTC (~$4.3 million), 5.7 million USDT (~$5.7 million), and smaller amounts of DOT, ADA, and other tokens. The attack occurred approximately two hours before the Uranium team had scheduled a migration to v2.1 contracts intended to address the known vulnerability. The Uranium Finance GitHub repository was removed shortly after the exploit, and the project's website was taken down, prompting widespread community speculation about potential insider involvement.","heading":"Second Exploit — April 28, 2021 (~$53.3 Million)","sources":[{"url":"https://rekt.news/uranium-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-uranium-finance-hack-april-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/building-a-poc-for-the-uranium-heist-ec83fbd83e9f","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/the-most-recently-hacked-defi-project-couldnt-even-copy-and-paste-uniswap-and-sushiswaps-code/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/uraniumfinancehack.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The core vulnerability was a modification error within the UraniumPair contract, a fork of Uniswap v2's pair contract. In Uniswap v2, the constant product invariant check uses the value 1,000 as a fee denominator. Uranium Finance developers updated this constant to 10,000 in two locations to reflect a different fee structure, but did not update the corresponding require statement in the swap function, which continued to validate against 1,000 squared (1,000,000). The actual balance adjustments were computed using 10,000 (i.e., 10,000 squared = 100,000,000), creating a 100x discrepancy. This allowed an attacker to satisfy the invariant check while sending a negligible input amount and receiving nearly the full output token reserve. An independent security review had flagged an associated concern as low-severity; the Uranium team subsequently identified it as critical and prepared a fix, but the vulnerable contracts remained live in the interim. The Immunefi team published a proof-of-concept demonstrating the exploit mechanics.","heading":"Smart Contract Vulnerability Analysis","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-uranium-finance-hack-april-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/building-a-poc-for-the-uranium-heist-ec83fbd83e9f","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/the-most-recently-hacked-defi-project-couldnt-even-copy-and-paste-uniswap-and-sushiswaps-code/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the April 28, 2021 exploit, stolen funds were routed through multiple obfuscation methods. At least 2,200–2,400 ETH were passed through Tornado Cash, an Ethereum-based privacy mixer, in batches. The AnySwap cross-chain bridge was used to move assets from the Binance Smart Chain to the Ethereum network. U.S. prosecutors later alleged that Jonathan Spalletta spent a substantial portion of the stolen proceeds on high-value physical collectibles, including: a 'Black Lotus' Magic: The Gathering card valued at approximately $500,000; sealed Alpha Booster packs valued at approximately $1.5 million; a first-edition Pokémon base set valued at approximately $750,000; an ancient Roman 'Eid Mar' coin valued at approximately $601,500; and lunar artifacts. These physical purchases were identified as a method of converting cryptocurrency into harder-to-trace assets. On-chain investigator ZachXBT had previously flagged a suspected connection between the Uranium Finance hacker and Magic: The Gathering card purchases as part of his independent tracing efforts.","heading":"Money Laundering and Fund Movements","sources":[{"url":"https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/266790/uranium-finance-hacker-may-have-cashed-out-via-magic-the-gathering-cards-zachxbt-says","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.banklesstimes.com/articles/2026/03/31/doj-alleged-uranium-finance-hacker-blew-54m-on-pokemon-cards-lunar-artifacts/","name":"banklesstimes.com","type":"other","credibility":3},{"url":"https://rekt.news/uranium-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"In February 2025, U.S. authorities — specifically the Southern District of New York (SDNY) and Homeland Security Investigations (HSI) San Diego — seized approximately $31 million in cryptocurrency linked to the 2021 Uranium Finance exploits. This was the first time any individual had been publicly linked to the case. On March 31, 2026, Jonathan Spalletta, 36, of Rockville, Maryland, was indicted and surrendered to authorities in Manhattan. He faces one count of computer fraud (maximum 10-year sentence) and one count of money laundering (maximum 20-year sentence). At the time of indictment, law enforcement had also seized various physical collectibles purchased with alleged proceeds. The case was prosecuted by the SDNY with investigative support from HSI.","heading":"Law Enforcement Response and Asset Recovery","sources":[{"url":"https://www.coindesk.com/policy/2026/03/31/maryland-man-charged-in-usd50-million-uranium-finance-hack-after-u-s-seized-usd31-million-in-crypto","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/307601/feds-recover-31-million-in-crypto-from-2021s-uranium-finance-exploit","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.coindesk.com/policy/2025/02/24/u-s-law-enforcement-seizes-usd31m-in-crypto-tied-to-uranium-finance-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.trmlabs.com/resources/blog/u-s-authorities-seize-31-million-in-uranium-finance-exploits-investigation","name":"trmlabs.com","type":"other","credibility":3},{"url":"https://www.securitiesdocket.com/2026/03/31/maryland-man-charged-with-defrauding-crypto-exchange-of-over-50-million-in-hacks/","name":"securitiesdocket.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The circumstances surrounding the April 28, 2021 exploit generated significant community skepticism regarding potential insider involvement, though no formal determination of insider complicity by the project team has been made public. Key concerns raised by community members and analysts include: (1) The Uranium Finance Twitter account was created approximately one month before the exploit, yet the protocol had accumulated over $50 million in TVL in that period. (2) The exploit occurred approximately two hours before the team's own scheduled migration to v2.1 contracts that would have patched the vulnerability — a timing coincidence that observers found suspicious. (3) The project's GitHub repository was deleted shortly after the hack, and the website was taken down, behavior inconsistent with a team acting in good faith toward harmed users. (4) The stolen funds were rapidly routed through privacy mixers and cross-chain bridges, suggesting pre-planned laundering infrastructure. Rekt News noted that the v2.0 buggy contract had been live for ten days before the scheduled fix date, and raised the question of whether the bug was intentionally introduced. These remain alleged concerns based on circumstantial evidence and community reporting. The DOJ indictment of Jonathan Spalletta, framing the attack as an external exploit by a third-party hacker, has not resolved all questions about whether any team members had advance knowledge.","heading":"Insider Involvement Suspicions and Community Concerns","sources":[{"url":"https://rekt.news/uranium-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://cryptopotato.com/50m-drained-from-uranium-finance-hack-or-rug-pull/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/hacks/upstart-amm-uranium-finance-suffers-50m-hack-second-attack-in-a-month","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the April 28, 2021 exploit, Uranium Finance ceased all operations permanently. The project's website, social media, and GitHub repository were taken offline. Liquidity providers who had deposited funds into the protocol's 26 affected pairs lost the totality of their deposits with no recourse or compensation mechanism offered by the team. The protocol did not pursue any restitution program, governance vote, or relaunch. Approximately $31 million of the stolen approximately $54.7 million in total losses has since been recovered by U.S. law enforcement as of February 2025, though the disposition of those recovered funds with respect to victims had not been publicly confirmed at the time of this report.","heading":"Project Shutdown and Victim Impact","sources":[{"url":"https://cointelegraph.com/news/50m-reportedly-stolen-from-bsc-based-uranium-finance","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/bsc-protocol-uranium-finance-hacked-50-million/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://decrypt.co/307601/feds-recover-31-million-in-crypto-from-2021s-uranium-finance-exploit","name":"decrypt.co","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain investigator ZachXBT conducted independent tracing of the Uranium Finance stolen funds and identified a suspected link between the hacker and purchases of rare Magic: The Gathering cards. ZachXBT traced approximately $25 million of the stolen funds and published his findings, flagging the collectibles angle as a potential off-ramp for laundered proceeds. His investigation is credited as having contributed to the eventual identification of the alleged perpetrator. ZachXBT has flagged Uranium Finance as a high-risk entity on his investigative platforms.","heading":"ZachXBT Investigation","sources":[{"url":"https://www.theblock.co/post/266790/uranium-finance-hacker-may-have-cashed-out-via-magic-the-gathering-cards-zachxbt-says","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.theblock.co/post/343165/us-authorities-seize-31-million-in-crypto-linked-to-2021-uranium-finance-hack","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-03","event":"Uranium Finance Twitter account created, approximately one month before the major exploit. Protocol rapidly accumulates over $50 million in TVL.","source":"","date_original":"2021-03-01"},{"date":"2021-04-08","event":"First exploit: Jonathan Spalletta allegedly drains approximately $1.4 million by abusing the AmountWithBonus variable in Uranium's rewards contract. Attacker later returns most funds but retains ~$386,000 as a purported bug bounty, which prosecutors would later call a sham.","source":""},{"date":"2021-04-28","event":"Second exploit: A mathematical error in the UraniumPair v2 swap function (1,000 vs. 10,000 constant mismatch) is exploited across 26 liquidity pools, draining approximately $53.3 million (~$57.2 million at peak valuation) about two hours before a scheduled v2.1 patch migration.","source":""},{"date":"2021-04-28","event":"Post-exploit: Uranium Finance removes its GitHub repository and takes down its website. Stolen funds begin moving through Tornado Cash and AnySwap bridge.","source":""},{"date":"2021-04-29","event":"Rekt News publishes analysis of the exploit, flagging suspicious timing and the GitHub deletion, and questioning whether the bug may have been intentionally introduced.","source":""},{"date":"2021-05","event":"Immunefi publishes a proof-of-concept analysis of the exploit mechanics, confirming the 100x constant mismatch vulnerability.","source":"","date_original":"2021-05-01"},{"date":"2023","event":"ZachXBT publishes tracing of stolen Uranium Finance funds, identifying suspected conversion through rare Magic: The Gathering card purchases as a laundering vector.","source":"","date_original":"2023-01-01"},{"date":"2025-02-24","event":"U.S. authorities (SDNY and HSI San Diego) seize approximately $31 million in cryptocurrency linked to the 2021 Uranium Finance exploits. This marks the first public linkage of an individual to the case.","source":""},{"date":"2026-03-31","event":"Jonathan Spalletta, 36, of Rockville, Maryland (aliases: 'Cthulhon', 'Jspalletta'), is indicted by federal prosecutors in Manhattan and surrenders to authorities. He faces one count of computer fraud (max 10 years) and one count of money laundering (max 20 years).","source":""}],"sources_used":[{"url":"https://cointelegraph.com/news/50m-reportedly-stolen-from-bsc-based-uranium-finance","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260331055328/https://cointelegraph.com/news/50m-reportedly-stolen-from-bsc-based-uranium-finance","credibility":3,"archive_timestamp":"2026-03-31T05:53:28+00:00"},{"url":"https://cryptopotato.com/50m-drained-from-uranium-finance-hack-or-rug-pull/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260410192611/https://cryptopotato.com/50m-drained-from-uranium-finance-hack-or-rug-pull/","credibility":3,"archive_timestamp":"2026-04-10T19:26:11+00:00"},{"url":"https://rekt.news/uranium-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260503004406/https://rekt.news/uranium-rekt","credibility":3,"archive_timestamp":"2026-05-03T00:44:06+00:00"},{"url":"https://www.coindesk.com/policy/2026/03/31/maryland-man-charged-in-usd50-million-uranium-finance-hack-after-u-s-seized-usd31-million-in-crypto","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260401054639/https://www.coindesk.com/policy/2026/03/31/maryland-man-charged-in-usd50-million-uranium-finance-hack-after-u-s-seized-usd31-million-in-crypto","credibility":3,"archive_timestamp":"2026-04-01T05:46:39+00:00"},{"url":"https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/","name":"bleepingcomputer.com","type":"other","archive_url":"http://web.archive.org/web/20260726111351/https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/","credibility":3,"archive_timestamp":"2026-07-26T11:13:51+00:00"},{"url":"https://www.cryptotimes.io/2026/03/31/u-s-authorities-charge-hacker-behind-54m-uranium-finance-hack/","name":"cryptotimes.io","type":"other","archive_url":"https://web.archive.org/web/20260830132400/https://www.cryptotimes.io/2026/03/31/u-s-authorities-charge-hacker-behind-54m-uranium-finance-hack/","credibility":3,"archive_timestamp":"2026-08-30T13:24:00+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-uranium-finance-hack-april-2021","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260605222942/https://www.halborn.com/blog/post/explained-the-uranium-finance-hack-april-2021","credibility":3,"archive_timestamp":"2026-06-05T22:29:42+00:00"},{"url":"https://medium.com/immunefi/building-a-poc-for-the-uranium-heist-ec83fbd83e9f","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptoslate.com/the-most-recently-hacked-defi-project-couldnt-even-copy-and-paste-uniswap-and-sushiswaps-code/","name":"cryptoslate.com","type":"other","archive_url":"https://web.archive.org/web/20260829192321/https://cryptoslate.com/the-most-recently-hacked-defi-project-couldnt-even-copy-and-paste-uniswap-and-sushiswaps-code/","credibility":3,"archive_timestamp":"2026-08-29T19:23:21+00:00"},{"url":"https://www.quadrigainitiative.com/casestudy/uraniumfinancehack.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260417195225/https://quadrigainitiative.com/casestudy/uraniumfinancehack.php","credibility":3,"archive_timestamp":"2026-04-17T19:52:25+00:00"},{"url":"https://www.theblock.co/post/266790/uranium-finance-hacker-may-have-cashed-out-via-magic-the-gathering-cards-zachxbt-says","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.banklesstimes.com/articles/2026/03/31/doj-alleged-uranium-finance-hacker-blew-54m-on-pokemon-cards-lunar-artifacts/","name":"banklesstimes.com","type":"other","archive_url":"http://web.archive.org/web/20260411121315/https://www.banklesstimes.com/articles/2026/03/31/doj-alleged-uranium-finance-hacker-blew-54m-on-pokemon-cards-lunar-artifacts/","credibility":3,"archive_timestamp":"2026-04-11T12:13:15+00:00"},{"url":"https://decrypt.co/307601/feds-recover-31-million-in-crypto-from-2021s-uranium-finance-exploit","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260610084120/https://decrypt.co/307601/feds-recover-31-million-in-crypto-from-2021s-uranium-finance-exploit","credibility":3,"archive_timestamp":"2026-06-10T08:41:20+00:00"},{"url":"https://www.coindesk.com/policy/2025/02/24/u-s-law-enforcement-seizes-usd31m-in-crypto-tied-to-uranium-finance-hack","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260331100805/https://www.coindesk.com/policy/2025/02/24/u-s-law-enforcement-seizes-usd31m-in-crypto-tied-to-uranium-finance-hack","credibility":3,"archive_timestamp":"2026-03-31T10:08:05+00:00"},{"url":"https://www.trmlabs.com/resources/blog/u-s-authorities-seize-31-million-in-uranium-finance-exploits-investigation","name":"trmlabs.com","type":"other","archive_url":"http://web.archive.org/web/20260308130623/https://www.trmlabs.com/resources/blog/u-s-authorities-seize-31-million-in-uranium-finance-exploits-investigation","credibility":3,"archive_timestamp":"2026-03-08T13:06:23+00:00"},{"url":"https://www.securitiesdocket.com/2026/03/31/maryland-man-charged-with-defrauding-crypto-exchange-of-over-50-million-in-hacks/","name":"securitiesdocket.com","type":"other","archive_url":"https://web.archive.org/web/20260830133032/https://www.securitiesdocket.com/2026/03/31/maryland-man-charged-with-defrauding-crypto-exchange-of-over-50-million-in-hacks/","credibility":3,"archive_timestamp":"2026-08-30T13:30:32+00:00"},{"url":"https://thedefiant.io/news/hacks/upstart-amm-uranium-finance-suffers-50m-hack-second-attack-in-a-month","name":"thedefiant.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptobriefing.com/bsc-protocol-uranium-finance-hacked-50-million/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260218161231/https://cryptobriefing.com/bsc-protocol-uranium-finance-hacked-50-million/","credibility":3,"archive_timestamp":"2026-02-18T16:12:31+00:00"},{"url":"https://www.theblock.co/post/343165/us-authorities-seize-31-million-in-crypto-linked-to-2021-uranium-finance-hack","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:58.165341+00:00","updated_at":"2026-08-30T13:44:40.836384+00:00"}}