NextFin

宝可梦粉丝涉 5500 万美元加密货币黑客案受审

由 NextFin AI 总结
  • Jonathan Spalletta faces trial in Manhattan federal court, accused of draining nearly $55 million from Uranium Finance in 2021 via smart-contract exploits and spending proceeds on rare collectibles.
  • Two attacks three weeks apart: the first netted about $1.4 million through a rewards-calculation flaw, while the second drained $53.3 million, nearly 90% of the exchange's assets, forcing permanent shutdown.
  • Legal stakes center on intent: defense argues code-permitted interaction is legitimate, while prosecutors frame it as theft, with a conviction extending DOJ precedent that 'the code allowed it' is not a defense.
  • DeFi risk has shifted, not vanished: protocol losses fell 74% to $680 million in 2025, yet protocol-logic exploits still caused 89% of losses, joined by key-management and operational failures.

NextFin News - Jonathan Spalletta, a Maryland cybersecurity consultant and collector of rare trading cards, went on trial Monday in Manhattan federal court accused of draining nearly $55 million from a decentralized cryptocurrency exchange in 2021 and spending a portion of the proceeds on Pokemon cards, Magic: The Gathering cards, and an antique Roman coin. The case, which opened with statements in the Southern District of New York, is one of the most colorful prosecutions to emerge from the decentralized finance boom — and one of the most consequential, because it asks whether exploiting a bug in "trustless" code is legally different from walking into a bank and taking money. Spalletta, 36, has pleaded not guilty to one count of computer fraud and one count of money laundering, charges carrying a maximum of 30 years in prison. His lawyers told the court that no hack occurred at all.

The Indictment: Two Attacks, Three Weeks Apart

The indictment, unsealed March 30, 2026, describes two attacks against Uranium Finance, an automated market maker deployed on the Binance Smart Chain that functioned as a clone of Uniswap. On April 8, 2021, prosecutors say Spalletta exploited a flaw in the platform's rewards calculation to withdraw about $1.4 million in cryptocurrency he was not entitled to receive. Uranium Finance then approached him and negotiated what the indictment describes as a sham bug bounty: Spalletta would keep $386,000 and return the remainder in exchange for a promise not to prosecute.

Three weeks later, on April 28, prosecutors allege Spalletta struck again — this time exploiting a different coding error across 26 liquidity pools and draining $53.3 million, nearly 90% of the exchange's assets. Uranium Finance shut down immediately and never reopened. The stolen funds were laundered through a series of decentralized exchanges and the Tornado Cash mixer before being converted into a collection of high-value collectibles.

The spending list reads like a catalog of alternative assets. According to the indictment, Spalletta bought a "Black Lotus" Magic: The Gathering card for approximately $500,000; 18 sealed packs of Alpha Booster Magic cards worth about $1.5 million; a first-edition complete base set of Pokemon cards for roughly $750,000; a sealed box of first-edition Pokemon cards for about $257,500; and an Eid Mar Denarius, an antique Roman coin commemorating the assassination of Julius Caesar, for approximately $601,545. Prosecutors also allege he purchased a piece of fabric from the Wright brothers' airplane that was later carried to the moon.

In February 2025 — nearly a year before the charges were filed — law enforcement seized the collectibles from Spalletta's Maryland residence and recovered approximately $31 million in cryptocurrency linked to the hack. The recovery was a joint effort between the Southern District of New York and Homeland Security Investigations in San Diego, with blockchain analytics firm TRM Labs assisting in tracing the laundered funds through mixers and decentralized exchanges.

The Legal Question Beneath the Trading Cards

The collectibles are the hook, but the legal question is the story. Spalletta's defense argues that he interacted with a public smart contract exactly as the code permitted — that no passwords were stolen, no servers were breached, and no access controls were bypassed. In the DeFi world, his lawyers contend, that is the definition of a legitimate transaction, and the bug-bounty negotiation after the first attack suggests the platform itself initially treated him as a researcher rather than a thief. The argument, presented to the court, is that this belongs in the realm of civil contract disputes, not federal criminal court.

Prosecutors frame it differently. They say the withdrawals were a deceptive series of transactions designed to make the contract dispense value it never owed — theft by any other name. U.S. Attorney Jay Clayton stated the government's position plainly when the charges were announced:

"As alleged, Jonathan Spalletta repeatedly hacked smart contracts to steal millions of dollars' worth of other people's money for himself, and destroyed a cryptocurrency exchange in the process."

Clayton added a line that cuts to the heart of the defense's "no hack" framing:

"In describing his alleged 'heist,' Spalletta told another individual, 'Crypto is just fake internet money anyway.' Stealing from a crypto exchange is stealing — the claim that 'crypto is different' does not change that. For the victims, there is nothing different about having your money taken. Spalletta cost real victims real losses of tens of millions of dollars, and now he's under real arrest."

The case arrives as federal prosecutors have built a track record of treating DeFi exploits as criminal theft rather than gray-area tinkering. The operator behind the $110 million Mango Markets exploit was convicted in 2024; an Amazon employee pleaded guilty in 2023 to stealing about $12 million from two platforms; and a Canadian national was charged for stealing $65 million from two platforms between 2021 and 2023. A guilty verdict here would extend that line of authority to exploits involving no breach of access controls at all — only the manipulation of code that was, on its face, functioning as written.

Why the Code Failed — and Why It Still Matters

The technical story is almost embarrassingly simple. Security researchers who analyzed the Uranium Finance hack at the time found the vulnerability in the swap function of version 2 of the project's contracts. The "sanity check" governing balance adjustments used a value of 1000 squared — 1,000,000 — while the actual balance adjustments were calculated at 10,000, a figure 100 times lower. That discrepancy allowed an attacker to deposit a small amount of value and extract a much larger amount through the swap function, draining the contract's reserves.

What makes the Uranium case unusual is not the sophistication of the exploit but the timeline. The project had commissioned a security audit that detected the vulnerability. Developers investigated, reclassified it as severe, and fixed it — but version 2.0 of the code was already live, and the attacker struck roughly two hours before the transition to the patched version was performed. The team knew the door was unlocked, had the key in hand, and was two hours from changing the lock.

This is the mechanism that turns a coding error into a criminal case. Spalletta did not stumble on an obscure flaw by accident and report it. According to the indictment, after the first attack he negotiated a bounty, kept nearly $400,000, and then returned weeks later to exploit a second, separate error — this one draining 26 liquidity pools and nearly 90% of the platform's assets. The sequence matters: it is the difference between a white-hat researcher and a repeat offender who understood exactly what the code permitted and used that understanding twice.

The Market Moved On — But the Risk Did Not Disappear

The Uranium Finance hack occurred during the 2021 DeFi frenzy, when losses of this size were still rare enough to dominate headlines for months. At the time it was one of the largest monetary exploits in decentralized finance history and remains one of the most devastating attacks on the BNB Chain. The market has since absorbed the lesson unevenly. DeFi protocol losses fell approximately 74% from $2.62 billion in 2022 to $680 million in 2025, and the median loss per incident dropped 75%, from $6 million to $1.5 million. Yet protocol-logic exploits — the same category that killed Uranium — still caused 89% of DeFi protocol losses in 2025.

The composition of risk has shifted rather than vanished. In the first half of 2026, crypto hacks and exploits totaled 207 incidents with $972 million stolen. Infrastructure and operational compromise accounted for roughly 76% of losses, while smart-contract exploits represented 125 of the 207 incidents. North Korea-linked operations were attributed to about $643 million, roughly two-thirds of the first-half total. The lesson for investors is not that smart-contract risk has been solved, but that it has been joined — and in some periods eclipsed — by key-management, oracle, and operational failures.

The Second-Order Problem: When "Trustless" Means No One Is Liable

Here is the uncomfortable question the Uranium case raises for the DeFi industry. The promise of decentralized finance is that code replaces intermediaries — that users can transact without trusting a bank, a broker, or an exchange. But when the code fails, that promise cuts both ways. There is no chief executive to sue, no balance sheet to claim against, and no deposit insurance to fall back on. The Uranium investors who lost money when the platform shut down were left, by contemporary accounts, without answers or financial restitution.

Law enforcement's ability to trace and recover stolen crypto has improved dramatically. The $31 million recovery in this case — roughly 57% of the alleged take — was made possible by blockchain analytics that followed the funds through mixers and decentralized exchanges to Spalletta's residence. But recovery is not the same as restitution, and a criminal conviction does not automatically make victims whole. The structural problem remains: in a system designed to eliminate trusted intermediaries, the victim's only reliable counterparty is the prosecutor's office, and that office is under no obligation to make anyone whole.

The Counter-Thesis — and What Would Prove It Wrong

The strongest argument for the defense is also the most technically coherent one. Spalletta interacted with a public smart contract exactly as the code allowed. No passwords were stolen, no servers were breached, no access controls were bypassed. In the DeFi world, that is the definition of a legitimate transaction — and the bug-bounty negotiation after the first attack suggests the platform itself initially treated him as a researcher rather than a thief. If the jury accepts that framing, the second attack becomes a civil dispute over contract interpretation rather than a federal crime.

That argument, however, collides with the sequence of events. A researcher who reports a bug does not launder the proceeds through Tornado Cash, buy a $500,000 Magic card, and return three weeks later to drain 26 more pools. The prosecution's narrative rests on intent and pattern, not merely on the mechanics of a single transaction. The falsifying signal for the government's case would be an acquittal on the money-laundering count specifically — because that charge depends on proving that Spalletta knew the funds were stolen and took deliberate steps to conceal their origin. If the jury convicts on computer fraud but not on laundering, it would signal that the exploit itself was criminal but the government failed to prove the cover-up.

What to Watch — and What Comes Next

The trial's immediate stakes are personal: Spalletta faces up to 10 years on the computer fraud count and up to 20 years on the money laundering count. But the broader stakes extend well beyond one defendant. A conviction would add another precedent to the Justice Department's campaign of treating DeFi exploits as criminal theft, reinforcing a legal environment in which "the code allowed it" is not a defense. That matters for the entire ecosystem of bug hunters, auditors, and protocol developers, who now operate with clearer notice that exploiting a vulnerability for personal profit — even without breaching access controls — can bring federal charges.

In the short term, the trial is a courtroom story: opening statements, technical testimony about smart-contract mechanics, and a jury's verdict on intent. Over the medium term, the outcome will shape how protocols structure bug-bounty programs and how auditors document vulnerabilities — expect more formal responsible-disclosure frameworks and clearer boundaries between testing and exploitation. In the long term, the case is a data point in the slow construction of legal infrastructure for decentralized systems: the rules are being written one prosecution at a time, and this one says that "fake internet money" is real enough to send someone to prison for decades.

The trial of Jonathan Spalletta is not really about Pokemon cards. It is about whether the most radical promise of crypto — that code can replace trust — comes with a radical exemption from the law. Five years after a 100-times math error drained an exchange, the answer from a Manhattan courtroom is likely to be no.

更多独家洞察尽在 nextfin.ai.

洞察

谁因加密货币黑客攻击案受审?

什么是 Uranium Finance DeFi 协议?

被盗资金总额是多少?

哪些稀有卡牌为此次购买提供了资金?

利用代码漏洞属于合法盗窃吗?

辩方是否声称并未发生黑客攻击?

导致资金被转走的漏洞是什么?

Uranium Finance 为何关闭?

被盗加密货币追回多少?

面临的最高刑期是多少?

DeFi 损失趋势如何?

还有谁面临 DeFi 漏洞利用指控?

Mango Markets 运营商是否被定罪?

为何无信任代码责任界定模糊?

代码能否在法律上取代信任?

TRM Labs 如何追踪资金?

漏洞赏金是否覆盖首次攻击?

陪审团裁定有罪之后会发生什么?

漏洞赏金规则会改变吗?

加密货币是虚假的互联网货币吗?

联网搜索
NextFinNextFin
NextFin.Al
No Noise, only Signal.
打开 App