Scope
Reports fall into two scopes:- Web3: Jupiter’s onchain programs and protocol infrastructure
- Web2: web applications, APIs, and supporting infrastructure
Reporting a vulnerability
- Email security@jup.ag with reproduction steps and an impact assessment.
- Do not disclose the vulnerability publicly until the report is resolved.
