“Code is law” lost to a jury in just over two hours

Cybersecurity consultant Jonathan Spalletta drained Uranium Finance twice in April 2021, taking nearly $55M in total

The first attack netted about $1.4M. Afterward, he even negotiated a “bug bounty” of around $386,000 in exchange for returning the rest. The second attack came down to a one-digit error: 1000 instead of 10000, and about $53.3M

The defense in court rested on one argument: all the contract’s functions were public, and he had simply used them

It didn’t work. Guilty on all counts, and he faces up to 20 years for money laundering alone

This is worth showing to everyone who says, “It’s not a hack, it’s arbitrage.” A bug in the code doesn’t make someone else’s money yours. Does a public function in a contract mean you’re allowed to take the money? I say no—what do you think?

#хак #defi #Кібербезпека