Skip to main content
Jupiter runs a public bug bounty program for security researchers. If you find a vulnerability in Jupiter’s onchain programs, APIs, or web infrastructure, report it through the program rather than disclosing it publicly.

Bug bounty program

The program lives at security.jup.ag and is split into two tracks:
  • Web3: Jupiter’s onchain programs and protocol infrastructure
  • Web2: web applications, APIs, and supporting infrastructure
Rewards are reserved for vulnerabilities that materially threaten user funds, protocol solvency, governance integrity, or user data. Theoretical issues and deviations from best practice are out of scope. The program page lists the full asset scope, reward tiers, and rules of engagement. Good-faith research conducted under the program guidelines is not subject to legal action.

Reporting a vulnerability

  1. Read the scope and rules at security.jup.ag.
  2. Submit your report through the program page with reproduction steps and impact assessment.
  3. Do not disclose the vulnerability publicly until the report is resolved.
  • Audits: formal audit reports for Jupiter programs
  • Support: developer support channels for non-security issues