Maryland cybersecurity consultant goes on trial for $55M crypto theft

5 hours ago 5

A cybersecurity consultant from Rockville, Maryland is facing a Manhattan federal jury after allegedly doing the thing he was supposed to prevent: hacking into a financial platform and walking off with tens of millions of dollars in digital assets.

Jonathan Spalletta, 36, went on trial September 28 on charges he hacked the decentralized finance platform Uranium Finance in April 2021, stealing approximately $54.7 million in crypto across two separate attacks. He faces one count of computer fraud, carrying up to 10 years in prison, and one count of money laundering, which carries a maximum sentence of 20 years.

Two strikes and the platform was out

The prosecution’s case centers on two distinct intrusions. The first, on April 8, 2021, drained roughly $1.4 million from Uranium Finance. The second hit landed on April 28, 2021. Prosecutors allege Spalletta exploited vulnerabilities across 26 separate liquidity pools, siphoning out $53.3 million in a single attack. The platform, which operated on the Binance Smart Chain, did not survive the blow. Uranium Finance shut down in the aftermath, its liquidity essentially gone.

Prosecutors argued in opening statements that whatever the technological complexity underneath, the conduct amounted to ordinary theft. The digital wrapping, they said, does not change what happened.

Defense attorneys are expected to contest whether the government can actually place Spalletta’s hands on the keyboard for either attack. The argument is not that the hacks did not happen, but that the prosecution cannot conclusively prove he was the one responsible for them.

From DeFi exploit to Black Lotus

Prosecutors say he laundered stolen funds through Tornado Cash, the crypto mixing protocol that obscures transaction trails by pooling deposits from multiple users before sending them back out.

He also, allegedly, went shopping. The purchases authorities flagged include a Black Lotus card from Magic: The Gathering valued at approximately $500,000, and a Roman “Eid Mar” coin worth over $601,500. The coin commemorates the assassination of Julius Caesar in 44 BC. Combined with other collectibles, prosecutors say the total haul of physical purchases exceeded $1 million.

Investigators ultimately traced enough of the money to build a case. In February 2025, roughly $31 million in crypto was seized from Spalletta. The indictment was unsealed on March 30, 2026, after he surrendered to authorities.

What this case means for DeFi security and enforcement

What makes the Spalletta trial notable is not just the scale of the alleged theft, but the fact that it reached a courtroom at all. DeFi exploits have historically been difficult to prosecute because pseudonymous blockchain transactions obscure the identity of the attacker.

The $31 million seizure in 2025 suggests that federal investigators, working with blockchain forensics tools, were able to follow the money even after it passed through Tornado Cash. That is significant. Mixers have long been treated as a near-definitive break in the investigative chain, but the ability to seize funds more than three years after the alleged exploit indicates that the chain was not, in fact, broken.

For the broader legal conversation around crypto theft, the prosecution’s framing matters. By arguing in opening statements that stealing from a DeFi protocol is just theft, full stop, prosecutors are attempting to establish that existing computer fraud and money laundering statutes are fully sufficient to cover digital asset crime.

The trial is expected to continue in Manhattan federal court. Spalletta has not entered a guilty plea, and the outcome will depend heavily on whether the government can satisfy the jury that its blockchain forensics tell a complete and accurate story linking the defendant to the attacks.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article