"I only used public functions" just failed in front of a jury.
On Oct 7, prosecutors in the Southern District of New York announced that Jonathan Spalletta, a 36-year-old cybersecurity consultant from Maryland, was convicted on every count over the 2021 Uranium Finance hack.
Quick recap of the case:
- In April 2021, Uranium Finance, an AMM on BNB Chain, was hit twice. 26 liquidity pools were drained, roughly $53-55M, and the protocol had to shut down.
- Prosecutors say the funds were moved through Tornado Cash.
- Authorities seized about $31M in crypto from his home, plus more than $3M in rare Pokemon and Magic: The Gathering cards.
- After a six-day trial before Judge Jed Rakoff, the jury convicted him of computer fraud and money laundering. The laundering count alone carries up to 20 years. Sentencing is set for Feb 16, 2027.
The most important detail is the defense. His lawyers argued he didn't forge credentials or plant malicious code, he simply called smart contract functions anyone could call. The jury didn't buy it.
That matters far beyond one case. "Code is law" has been the quiet excuse behind a lot of DeFi exploits. This verdict says US courts look at intent and outcome, not just whether the contract technically allowed the transaction.
The fair counterpoint: some builders worry this blurs the line between exploiting a bug and aggressive but legal trading, and that whitehats could face the same risk.
Where do you draw the line: is draining a buggy contract theft, or the protocol's fault?
Like and follow for more crypto crime and court stories explained simply.
#DeFi #CryptoCrime