FraudHIGH

Hacker Charged - $53 Million Stolen from Uranium Crypto Exchange

Featured image for Hacker Charged - $53 Million Stolen from Uranium Crypto Exchange
BCBleepingComputer·Reporting by Sergiu Gatlan
📰 5 sources·Summary by CyberPings Editorial·AI-assisted·Reviewed by Rohit Rana
Updated:
🎯

A man hacked a cryptocurrency exchange, stole a lot of money, and then tried to hide it by mixing it with other money. He bought expensive collectibles with the stolen cash but got caught by the police.

Quick Summary

Jonathan Spalletta faces serious charges for stealing over $53 million from Uranium Finance, a decentralized crypto exchange, and laundering the funds through a mixer.

What Happened

U.S. prosecutors have charged 36-year-old Jonathan Spalletta, known online as "Cthulhon" and "Jspalletta," with stealing more than $53 million after executing two sophisticated hacks against the Uranium Finance crypto exchange. Spalletta appeared in court after surrendering to law enforcement on Monday.

The Breaches

The first breach occurred on April 8, 2021, when he exploited a flaw in Uranium's smart contract code, manipulating the AmountWithBonus variable to issue zero-token withdrawal commands that drained approximately $1.4 million from the liquidity pool. Following this, he extorted the exchange, demanding nearly $386,000 of the stolen funds as a sham "bug bounty" in exchange for returning the remainder. On April 28, Spalletta struck again, exploiting a separate coding error that allowed him to withdraw nearly 90% of the assets held across 26 liquidity pools, netting him approximately $53.3 million and forcing the exchange to shut down.

Who's Affected

The U.S. Attorney's office emphasized that theft in the crypto space is no different from traditional theft, stating, "Crypto is just fake internet money anyway" does not excuse the crime.

What Data Was Exposed

Spalletta laundered the stolen assets through the Tornado Cash mixer, using the proceeds for high-value collectibles, including a rare "Black Lotus" Magic: The Gathering card for about $500,000, 18 sealed packs of Alpha Booster Magic cards for around $1.5 million, and an ancient Roman coin commemorating Julius Caesar's assassination for over $601,000. Law enforcement seized these collectibles and recovered approximately $31 million in cryptocurrency linked to Spalletta's wallets.

What You Should Do

He now faces up to 10 years in prison for computer fraud and up to 20 years for money laundering.

The case highlights the vulnerabilities in decentralized finance platforms and the legal repercussions of exploiting such weaknesses. As crypto theft becomes more prevalent, regulatory scrutiny and law enforcement actions are likely to increase.

Original article from

BCBleepingComputer· Sergiu Gatlan
Read Full Article

Also covered by

SCSC Media

Maryland man charged in $53 million Uranium Finance crypto heist

Read Article
HEHelp Net Security

Hacker stripped more than $50 million from Uranium crypto exchange, spent it on trading cards

Read Article
SESecurityWeek

US Charges Uranium Crypto Exchange Hacker

Read Article
THThe Record

US indicts Maryland man for 2021 theft of $54 million from Uranium Finance

Read Article

Related Pings

HIGHFraud

Device Code Phishing - Attacks Surge 37 Times in 2026

Device code phishing attacks have skyrocketed this year, with a 37x increase. Users of IoT and streaming devices are particularly at risk. New phishing kits like EvilTokens are making these attacks easier for cybercriminals. Stay alert and protect your accounts.

BleepingComputer·
HIGHFraud

Job Scams - Coca-Cola and Ferrari Offers Are Traps

Scammers are impersonating Coca-Cola and Ferrari with fake job offers to steal your passwords. Job seekers are at high risk as these scams become more sophisticated. Protect your personal information by verifying job offers directly with companies.

Malwarebytes Labs·
HIGHFraud

FCC Proposes $4.5 Million Fine for Voxbeam's Fraudulent Calls

The FCC is proposing a hefty fine against Voxbeam for allowing fraudulent calls to reach American consumers. This could lead to stricter regulations on voice service providers. Stay alert to protect your personal information from scams.

The Record·
HIGHFraud

Windows Extortion Plot - Engineer Pleads Guilty to Charges

A former engineer has pleaded guilty to locking Windows admins out of servers in an extortion scheme. This incident underscores the risks of insider threats. Rhyne's actions could lead to a 15-year prison sentence. Companies must strengthen their cybersecurity measures to prevent similar attacks.

BleepingComputer·
MEDIUMFraud

Business Email Compromise - The New Threat Landscape Explained

A recent fraud attempt shows how business email compromise is evolving. Small organizations are now prime targets for these scams. Awareness is key to staying safe.

Cisco Talos Intelligence·
HIGHFraud

Vacant Homes - Adversaries Exploit Mail for Fraud

Criminals are exploiting vacant homes to intercept mail and commit fraud. This method targets sensitive information, leading to identity theft. Stay vigilant and monitor your mail to protect yourself.

BleepingComputer·