Bug bounty program
The program lives at security.jup.ag and is split into two tracks:- Web3: Jupiter’s onchain programs and protocol infrastructure
- Web2: web applications, APIs, and supporting infrastructure
Reporting a vulnerability
- Read the scope and rules at security.jup.ag.
- Submit your report through the program page with reproduction steps and impact assessment.
- Do not disclose the vulnerability publicly until the report is resolved.
