Skip to main content
Sign in
Jonathan Spalletta1 decision on this page

Audit log

Every state-changing event for Jonathan Spalletta: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-06-02 16:20:06Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 423,844,503
    sig
    4SCeC5pcnqkf…MHHvpPnSexplorer ↗
    hash
    2Ei4a3SBL4PZ…5d5dSW9Psha256 → base58
    verifying row…full verify ↗
    canonical bytes (23208 B) ▸
    {"actor":"system:backfill","investigation_id":"6e1564f1-7c5f-4644-9b1c-f18175a70026","kind":"publish","page_slug":"jonathan-spalletta","published_at":"2026-06-02T16:20:06.813Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Jonathan Spalletta","sections":[{"content":"On March 30, 2026, the U.S. Attorney's Office for the Southern District of New York (SDNY) unsealed an indictment against Jonathan Spalletta, 36, of Rockville, Maryland. Spalletta, who operated online under the aliases 'Cthulhon' and 'Jspalletta,' is charged with one count of computer fraud, carrying a maximum sentence of 10 years in prison, and one count of money laundering, carrying a maximum sentence of 20 years in prison, for a combined statutory maximum of 30 years. The case is assigned to U.S. District Judge Jed S. Rakoff. Spalletta surrendered to authorities on March 30, 2026, and appeared before U.S. Magistrate Judge Ona T. Wang. A trial date of September 2026 has been set. These are allegations only; Spalletta is presumed innocent until proven guilty.","heading":"Federal Charges and Indictment","severity":"critical","sources":[{"credibility":1,"name":"DOJ SDNY Press Release: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"regulatory","url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"credibility":2,"name":"The Block: Maryland man charged in $54 million Uranium Finance hacks faces up to 30 years","type":"news_article","url":"https://www.theblock.co/post/395766/maryland-man-charged-54-million-uranium-finance-hacks-faces-30-years"},{"credibility":2,"name":"MLex: Alleged Uranium Finance hacker gets September US trial date","type":"news_article","url":"https://www.mlex.com/mlex/financial-crime/articles/2466894"}]},{"content":"According to the indictment, between approximately April 6 and April 8, 2021, Spalletta allegedly exploited a vulnerability in Uranium Finance's rewards contract on the BNB Chain. The exploit involved manipulating an 'AmountWithBonus' variable by issuing zero-token withdrawal commands that forced unwarranted reward payouts, draining approximately $1.4 million in cryptocurrency from a liquidity pool. Following the theft, Spalletta allegedly contacted Uranium Finance and extorted the platform into paying him approximately $386,000 as a fraudulent 'bug bounty,' presenting the arrangement as legitimate vulnerability disclosure while retaining the extorted payment in exchange for returning the remainder of the stolen funds. Prosecutors characterize this as a sham designed to evade prosecution.","heading":"Alleged First Hack — April 8, 2021","severity":"critical","sources":[{"credibility":1,"name":"DOJ SDNY Press Release: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"regulatory","url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"credibility":2,"name":"BleepingComputer: Hacker charged with stealing $53 million from Uranium crypto exchange","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/"},{"credibility":2,"name":"CoinDesk: Maryland man charged in $50 million Uranium Finance hack","type":"news_article","url":"https://www.coindesk.com/policy/2026/03/31/maryland-man-charged-in-usd50-million-uranium-finance-hack-after-u-s-seized-usd31-million-in-crypto"}]},{"content":"According to prosecutors, on April 28, 2021, Spalletta conducted a second and significantly larger exploit against Uranium Finance. The attack exploited a single-character coding error in Uranium Finance's version 2 swap contract: the transaction-verification logic used a magic value of 10,000 (rather than the original 1,000), but the K-invariant sanity check retained the original value of 1,000, creating a factor-of-100 imbalance. This allowed an attacker to deposit a minimal token amount and withdraw substantially more than the algorithm should permit, effectively draining each affected pool. Spalletta allegedly exploited this flaw across 26 separate liquidity pools, fraudulently obtaining approximately $53.3 million in BNB, BUSD, Bitcoin, Ethereum, Polkadot, Cardano, and Uranium's native U92 token. The attack rendered Uranium Finance insolvent and forced the exchange to shut down permanently. Independent security researchers later confirmed the vulnerability was attributable to a known smart contract flaw that had been flagged in a prior audit but inadequately remediated.","heading":"Alleged Second Hack — April 28, 2021","severity":"critical","sources":[{"credibility":1,"name":"DOJ SDNY Press Release: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"regulatory","url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"credibility":2,"name":"Halborn: Explained: The Uranium Finance Hack (April 2021)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-uranium-finance-hack-april-2021"},{"credibility":2,"name":"Decrypt: US Charges Hacker Behind $53 Million Uranium Finance Exploit","type":"news_article","url":"https://decrypt.co/362836/us-charges-hacker-53-million-uranium-finance-exploit"},{"credibility":2,"name":"The Record: US indicts Maryland man for 2021 theft of $54 million from Uranium Finance","type":"news_article","url":"https://therecord.media/us-indicts-maryland-man-54-million-crypto-theft"}]},{"content":"According to reporting citing the indictment, Spalletta and alleged co-conspirators allegedly orchestrated a deception campaign following the second hack to mislead victims and conceal their involvement. They allegedly created a public 'War Room' channel on Telegram, purporting to be an independent team investigating the theft and working to recover user funds. As part of this alleged ruse, approximately $2 million of the stolen funds was returned to a wallet that they controlled but presented to the community as the official developer's wallet, in order to lend credibility to a false 'white-hat hacker' narrative. This alleged social engineering effort is referenced in some reporting; however, it does not appear as a standalone charge in publicly available charging documents and the indictment details are partially paywalled. This claim should be treated with medium confidence pending full public access to the charging document.","heading":"Alleged Deception Campaign and False White-Hat Narrative","severity":"high","sources":[{"credibility":3,"name":"IQ.wiki: Jonathan Spalletta","type":"other","url":"https://iq.wiki/wiki/jonathan-spalletta"},{"credibility":2,"name":"Decrypt: US Charges Hacker Behind $53 Million Uranium Finance Exploit","type":"news_article","url":"https://decrypt.co/362836/us-charges-hacker-53-million-uranium-finance-exploit"}]},{"content":"The indictment alleges that between April 2021 and November 2023, Spalletta laundered a substantial portion of the stolen proceeds through a layered cryptocurrency laundering scheme. He allegedly used the Tornado Cash mixer to obscure the origin of funds, moving assets across multiple blockchains and wallets. Prosecutors allege that approximately $26 million was funneled through Tornado Cash during this period. Funds were reportedly converted from BNB and BUSD to Ethereum and then to Monero (XMR) to further complicate tracing. In December 2023, on-chain investigator ZachXBT published a report linking approximately 11,200 ETH (worth approximately $25 million at the time) withdrawn from Tornado Cash to the Uranium Finance attacker, documenting how stolen ETH was subsequently routed through brokers to purchase high-value physical collectibles. This ZachXBT report preceded and likely informed the subsequent law enforcement action.","heading":"Alleged Money Laundering via Tornado Cash","severity":"critical","sources":[{"credibility":1,"name":"DOJ SDNY Press Release: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"regulatory","url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"credibility":2,"name":"BleepingComputer: Hacker charged with stealing $53 million from Uranium crypto exchange","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/"},{"credibility":2,"name":"Decrypt: Feds Recover $31 Million in Crypto From 2021's Uranium Finance Exploit","type":"news_article","url":"https://decrypt.co/307601/feds-recover-31-million-in-crypto-from-2021s-uranium-finance-exploit"}]},{"content":"Federal prosecutors allege that Spalletta converted laundered cryptocurrency into rare physical collectibles, apparently as a strategy to further obscure the origin of funds and hold value in non-digital, difficult-to-trace assets. Items identified in the charging documents and subsequent reporting include: a Black Lotus Magic: The Gathering card purchased for approximately $500,000; 18 sealed Alpha Booster Magic: The Gathering packs purchased for approximately $1.5 million; a first-edition complete Pokemon base set purchased for approximately $750,000 to over $1 million; an ancient Roman 'Eid Mar' denarius coin — minted to commemorate the assassination of Julius Caesar — purchased for over $600,000; and a piece of muslin fabric from the Wright Brothers' original 1903 Flyer airplane that was carried to the lunar surface by astronaut Neil Armstrong during the Apollo 11 mission, purchased for approximately $137,500. These physical items were seized by law enforcement during a search warrant executed at Spalletta's Rockville, Maryland residence on February 24, 2025, along with approximately $31 million in cryptocurrency.","heading":"Alleged Proceeds: Rare Collectibles Purchased","severity":"high","sources":[{"credibility":1,"name":"DOJ SDNY Press Release: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"regulatory","url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"credibility":2,"name":"BleepingComputer: Hacker charged with stealing $53 million from Uranium crypto exchange","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/"},{"credibility":2,"name":"Daily Voice Maryland: $50M Crypto Heist Spent On Pokemon, Magic Cards, Moon Relic By Maryland Man","type":"news_article","url":"https://dailyvoice.com/md/bel-air/50m-crypto-heist-spent-on-pokemon-magic-cards-moon-relic-by-maryland-man-feds-say/"},{"credibility":2,"name":"Help Net Security: Hacker stripped more than $50 million from Uranium crypto exchange","type":"news_article","url":"https://www.helpnetsecurity.com/2026/03/31/uranium-finance-crypto-hack-man-charged/"}]},{"content":"On February 24, 2025, U.S. law enforcement — coordinated between the SDNY U.S. Attorney's Office and Homeland Security Investigations (HSI) San Diego — executed a search warrant at Spalletta's Rockville, Maryland residence, seizing the physical collectibles described above and approximately $31 million in cryptocurrency linked to the Uranium Finance exploits. This seizure predated the public filing of charges by approximately 13 months. Blockchain intelligence firm TRM Labs assisted law enforcement in tracing the movement of stolen assets across multiple blockchains and identifying key laundering patterns. The SDNY subsequently invited Uranium Finance victims to contact UraniumVictims@hsi.dhs.gov to submit claims for potential recovery of a portion of the seized funds.","heading":"Asset Seizure and Recovery","severity":"high","sources":[{"credibility":2,"name":"BleepingComputer: US recovers $31 million stolen in 2021 Uranium Finance hack","type":"news_article","url":"https://www.bleepingcomputer.com/news/cryptocurrency/us-recovers-31-million-stolen-in-2021-uranium-finance-hack/"},{"credibility":2,"name":"CoinDesk: U.S. Law Enforcement Seizes $31M in Crypto Tied to Uranium Finance Hack","type":"news_article","url":"https://www.coindesk.com/policy/2025/02/24/u-s-law-enforcement-seizes-usd31m-in-crypto-tied-to-uranium-finance-hack"},{"credibility":2,"name":"Decrypt: Feds Recover $31 Million in Crypto From 2021's Uranium Finance Exploit","type":"news_article","url":"https://decrypt.co/307601/feds-recover-31-million-in-crypto-from-2021s-uranium-finance-exploit"}]},{"content":"Spalletta operated under two primary online aliases identified in the indictment: 'Cthulhon,' used in on-chain and crypto community contexts, and 'Jspalletta,' used on other platforms. Additional aliases referenced in some secondary reporting include 'Jonny Boy,' 'Nass,' and 'SirJonathan,' though the latter three do not appear in primary source documents reviewed for this report and should be treated as lower-confidence identifiers. The alias 'Cthulhon' — a reference to the H.P. Lovecraft entity Cthulhu — was identified by on-chain investigator ZachXBT in his December 2023 public investigation as belonging to the Uranium Finance attacker, predating the government's public identification of Spalletta by over two years.","heading":"Online Identity and On-Chain Aliases","severity":"medium","sources":[{"credibility":1,"name":"DOJ SDNY Press Release: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"regulatory","url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"credibility":2,"name":"SC Media: Maryland man charged in $53 million Uranium Finance crypto heist","type":"news_article","url":"https://www.scworld.com/brief/maryland-man-charged-in-53-million-uranium-finance-crypto-heist"}]},{"content":"As of June 2026, Jonathan Spalletta has been charged but not convicted. He surrendered to authorities on March 30, 2026, appeared before U.S. Magistrate Judge Ona T. Wang, and was assigned to U.S. District Judge Jed S. Rakoff of the Southern District of New York. A trial date has been set for September 2026. Spalletta is presumed innocent of all charges. No guilty plea has been publicly reported. The maximum statutory sentence if convicted on both counts is 30 years (10 years for computer fraud, 20 years for money laundering).","heading":"Current Legal Status","severity":"critical","sources":[{"credibility":2,"name":"MLex: Alleged Uranium Finance hacker gets September US trial date","type":"news_article","url":"https://www.mlex.com/mlex/financial-crime/articles/2466894"},{"credibility":1,"name":"DOJ SDNY Press Release: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"regulatory","url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"}]}],"sources_used":[{"credibility":1,"name":"DOJ SDNY: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"regulatory","url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"credibility":2,"name":"The Block: Maryland man charged in $54 million Uranium Finance hacks faces up to 30 years","type":"news_article","url":"https://www.theblock.co/post/395766/maryland-man-charged-54-million-uranium-finance-hacks-faces-30-years"},{"credibility":2,"name":"Help Net Security: Hacker stripped more than $50 million from Uranium crypto exchange","type":"news_article","url":"https://www.helpnetsecurity.com/2026/03/31/uranium-finance-crypto-hack-man-charged/"},{"credibility":2,"name":"SecurityWeek: US Charges Uranium Crypto Exchange Hacker","type":"news_article","url":"https://www.securityweek.com/us-charges-uranium-crypto-exchange-hacker/"},{"credibility":2,"name":"BleepingComputer: Hacker charged with stealing $53 million from Uranium crypto exchange","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/"},{"credibility":2,"name":"CoinDesk: Maryland man charged in $50 million Uranium Finance hack","type":"news_article","url":"https://www.coindesk.com/policy/2026/03/31/maryland-man-charged-in-usd50-million-uranium-finance-hack-after-u-s-seized-usd31-million-in-crypto"},{"credibility":2,"name":"Decrypt: US Charges Hacker Behind $53 Million Uranium Finance Exploit","type":"news_article","url":"https://decrypt.co/362836/us-charges-hacker-53-million-uranium-finance-exploit"},{"credibility":2,"name":"The Record (Recorded Future News): US indicts Maryland man for 2021 theft of $54 million from Uranium Finance","type":"news_article","url":"https://therecord.media/us-indicts-maryland-man-54-million-crypto-theft"},{"credibility":2,"name":"MLex: Alleged Uranium Finance hacker gets September US trial date","type":"news_article","url":"https://www.mlex.com/mlex/financial-crime/articles/2466894"},{"credibility":2,"name":"MLex: Maryland man charged with hacking, stealing $53m from DeFi exchange","type":"news_article","url":"https://www.mlex.com/mlex/articles/2459497/maryland-man-charged-with-hacking-stealing-53m-from-defi-exchange"},{"credibility":2,"name":"BleepingComputer: US recovers $31 million stolen in 2021 Uranium Finance hack","type":"news_article","url":"https://www.bleepingcomputer.com/news/cryptocurrency/us-recovers-31-million-stolen-in-2021-uranium-finance-hack/"},{"credibility":2,"name":"CoinDesk: U.S. Law Enforcement Seizes $31M in Crypto Tied to Uranium Finance Hack","type":"news_article","url":"https://www.coindesk.com/policy/2025/02/24/u-s-law-enforcement-seizes-usd31m-in-crypto-tied-to-uranium-finance-hack"},{"credibility":2,"name":"Decrypt: Feds Recover $31 Million in Crypto From 2021's Uranium Finance Exploit","type":"news_article","url":"https://decrypt.co/307601/feds-recover-31-million-in-crypto-from-2021s-uranium-finance-exploit"},{"credibility":2,"name":"Halborn: Explained: The Uranium Finance Hack (April 2021)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-uranium-finance-hack-april-2021"},{"credibility":2,"name":"SC Media: Maryland man charged in $53 million Uranium Finance crypto heist","type":"news_article","url":"https://www.scworld.com/brief/maryland-man-charged-in-53-million-uranium-finance-crypto-heist"},{"credibility":2,"name":"Daily Voice Maryland: $50M Crypto Heist Spent On Pokemon, Magic Cards, Moon Relic By Maryland Man","type":"news_article","url":"https://dailyvoice.com/md/bel-air/50m-crypto-heist-spent-on-pokemon-magic-cards-moon-relic-by-maryland-man-feds-say/"},{"credibility":2,"name":"Securities Docket: Maryland Man Charged With Defrauding Crypto Exchange Of Over $50 Million In Hacks","type":"news_article","url":"https://www.securitiesdocket.com/2026/03/31/maryland-man-charged-with-defrauding-crypto-exchange-over-50-million-hacks/"},{"credibility":3,"name":"IQ.wiki: Jonathan Spalletta","type":"other","url":"https://iq.wiki/wiki/jonathan-spalletta"}],"summary":"Jonathan Spalletta, 36, of Rockville, Maryland, was charged on March 30, 2026 by the U.S. Attorney's Office for the Southern District of New York with one count of computer fraud and one count of money laundering in connection with two hacks of the decentralized exchange Uranium Finance in April 2021 that allegedly yielded approximately $54.7 million in stolen cryptocurrency. He is alleged to have laundered proceeds through Tornado Cash and converted them into rare collectibles including Magic: The Gathering cards, first-edition Pokemon sets, and antiquities. He surrendered to authorities on March 30, 2026, entered a not-guilty plea, and is awaiting trial scheduled for September 2026 before U.S. District Judge Jed S. Rakoff.","timeline":[{"date":"2021-04-08","event":"Alleged first hack of Uranium Finance: approximately $1.4 million drained from a rewards liquidity pool via AmountWithBonus variable manipulation.","source":"DOJ SDNY Press Release","source_url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"date":"2021-04-08","event":"Alleged extortion: Spalletta allegedly contacted Uranium Finance and extracted approximately $386,000 as a fraudulent 'bug bounty' in exchange for returning the remainder of the first theft.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/hacker-charged-with-stealing-53-million-from-uranium-crypto-exchange/"},{"date":"2021-04-28","event":"Alleged second hack of Uranium Finance: approximately $53.3 million drained across 26 liquidity pools via a single-character swap-contract coding error; exchange forced to shut down permanently.","source":"DOJ SDNY Press Release","source_url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"date":"2021-04-28","event":"Alleged Telegram 'War Room' deception: Spalletta and co-conspirators allegedly posed as investigators and promoted a false white-hat narrative, returning approximately $2 million to a wallet they controlled but presented as the official developer wallet.","source":"Decrypt / IQ.wiki","source_url":"https://decrypt.co/362836/us-charges-hacker-53-million-uranium-finance-exploit"},{"date":"2023-12-01","event":"On-chain investigator ZachXBT published a report linking approximately 11,200 ETH withdrawn from Tornado Cash to the Uranium Finance attacker, documenting the conversion into rare physical collectibles via U.S. brokers.","source":"Decrypt: Feds Recover $31 Million in Crypto From 2021 Uranium Finance Exploit","source_url":"https://decrypt.co/307601/feds-recover-31-million-in-crypto-from-2021s-uranium-finance-exploit"},{"date":"2025-02-24","event":"Federal agents executed a search warrant at Spalletta's Rockville, Maryland residence, seizing approximately $31 million in cryptocurrency and multiple high-value physical collectibles including the Black Lotus MTG card, sealed Alpha Booster packs, first-edition Pokemon sets, a Julius Caesar Eid Mar coin, and Wright Brothers airplane fabric.","source":"BleepingComputer: US recovers $31 million stolen in 2021 Uranium Finance hack","source_url":"https://www.bleepingcomputer.com/news/cryptocurrency/us-recovers-31-million-stolen-in-2021-uranium-finance-hack/"},{"date":"2026-03-30","event":"Indictment unsealed by SDNY; Jonathan Spalletta surrendered to authorities and appeared before U.S. Magistrate Judge Ona T. Wang. Charged with one count of computer fraud and one count of money laundering.","source":"DOJ SDNY Press Release","source_url":"https://www.justice.gov/usao-sdny/pr/maryland-man-charged-defrauding-crypto-exchange-over-50-million-hacks"},{"date":"2026-09-01","event":"Trial scheduled before U.S. District Judge Jed S. Rakoff, SDNY. Exact September 2026 date pending court scheduling.","source":"MLex: Alleged Uranium Finance hacker gets September US trial date","source_url":"https://www.mlex.com/mlex/financial-crime/articles/2466894"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 739a3666-d095-4d53-9bde-5c87067f9d7d
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.