0x1a3a9fbe1a3a…1a3a9fbb

ConfirmedRegulation & Policy616 vB54 sat/vB3 min decode

Jury Conviction Secured in $50M Uranium Finance Exploit Case

A U.S. court has convicted a defendant tied to the April 2021 Uranium Finance hack, in which an attacker drained $50M from Binance Smart Chain pools.

Outputs

  1. A conviction has been secured in the Uranium Finance hack case, BankInfoSecurity reported.

  2. The April 2021 exploit drained approximately $50 million from Uranium Finance pools on Binance Smart Chain.

  3. The bug over-credited attacker liquidity by a factor of 10 due to a modified Uniswap V2 fork.

  4. Uranium Finance TVL collapsed from over $100 million to under $2 million after the hack.

A U.S. court has returned a conviction connected to the April 2021 hack of Uranium Finance, the automated market maker that lost approximately $50 million when an attacker drained its liquidity pools on Binance Smart Chain, according to a report by BankInfoSecurity's weekly cryptohack roundup.

The case centers on one of the most damaging smart-contract exploits of the last bull cycle. Uranium Finance, a fork of Uniswap V2, operated on what was then called the Binance Smart Chain (now BNB Chain). On April 28, 2021, an attacker exploited a flaw in the protocol's rebasing logic to withdraw vastly more tokens than they had deposited, draining roughly $50 million in assets from the pair contracts in a sequence of on-chain transactions.

What went wrong at Uranium Finance?

The root cause was a code defect introduced when the development team modified the Uniswap V2 fork. In Uniswap's original pair contracts, the protocol keeps a running balance to track deposits. The Uranium implementation multiplied that balance figure by a factor of 10 during a routine upgrade of the codebase.

The error meant the contract over-credited the attacker's contributed liquidity by ten times. The exploiter then burned the inflated liquidity position and withdrew the underlying tokens — an arbitrage of the protocol's own accounting rather than a key compromise or flash-loan attack. On-chain records showed the funds moving rapidly through Binance Smart Chain addresses, with a portion subsequently traced to the Tornado Cash mixer on Ethereum.

The exploit forced Uranium Finance to halt operations within hours. The project's total value locked collapsed from over $100 million to under $2 million overnight, according to DefiLlama data from the period. Liquidity providers who held positions in the affected pools absorbed the losses directly, as the drained assets belonged to the pools themselves rather than to a treasury or custodial wallet.

Why the conviction matters

The BankInfoSecurity roundup identifies the Uranium case as part of a broader enforcement pattern: prosecutors and financial regulators have increasingly treated major DeFi exploits as criminal matters rather than purely technical incidents, pursuing operators and beneficiaries of drained funds through blockchain-analytics tracing.

The conviction carries operational consequences beyond the individual case:

  • It demonstrates that mixed funds — even routed through Tornado Cash after crossing chains — remain traceable and legally actionable.
  • It signals to DeFi developers that code audits do not shield projects from downstream liability when modified fork code introduces exploitable defects.
  • It gives liquidity providers a precedent for expecting criminal referrals, not just insurance payouts, when pools are drained.

The wider enforcement picture

The Uranium conviction lands amid a sustained enforcement push against crypto-linked financial crime. U.S. authorities have secured convictions in several high-profile cases tied to exchange collapses, mixing services and protocol exploits over the past two years, with the Department of Justice and the Securities and Exchange Commission dividing jurisdiction depending on whether the conduct involves theft, fraud or unregistered securities activity.

For DeFi protocols specifically, the enforcement calculus has shifted. Exploits that once ended with a post-mortem blog post and a partial reimbursement now routinely trigger subpoenas, asset freezes and, in cases like this one, criminal charges that carry prison terms.

Uranium Finance never recovered. The protocol's interface went offline months after the hack, and its governance token lost effectively all residual value, leaving the conviction as the final chapter in a case that began with a single erroneous multiplication in a copied codebase.

Further sentencing details and restitution terms for affected liquidity providers are expected as the court process concludes, and additional enforcement actions tied to 2021-era exploits remain likely as tracing techniques continue to mature.

via Google News - Crypto Hack Exploit (Source)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles