Skip to main content
Jupiter welcomes reports from security researchers. If you find a vulnerability in Jupiter’s onchain programs, APIs, or web infrastructure, report it to security@jup.ag rather than disclosing it publicly.

Scope

Reports fall into two scopes:
  • Web3: Jupiter’s onchain programs and protocol infrastructure
  • Web2: web applications, APIs, and supporting infrastructure
Focus on vulnerabilities that materially threaten user funds, protocol solvency, governance integrity, or user data. Theoretical issues and deviations from best practice are out of scope. Good-faith research conducted in line with these guidelines is not subject to legal action.

Reporting a vulnerability

  1. Email security@jup.ag with reproduction steps and an impact assessment.
  2. Do not disclose the vulnerability publicly until the report is resolved.
  • Audits: formal audit reports for Jupiter programs
  • Support: developer support channels for non-security issues