O
O
O
sec
O
O
O
sec
Programs
Pulse
Leaderboard
Pulse
Latest vulnerability disclosures and bounty awards
Bounties Paid
$145,000
Active Programs
2,630
Researchers
5,039
All
Bounties
Disclosed
Resolved
Closed
Recent
Most Kudos
#0x6F
Jupiter
ruled a report not applicable
about 16 hrs ago
Information Disclosure
@
lau90
#0x6E
Jupiter
noted a report as informative
yesterday
Improper Access Control
@
fcc
#0x6C
Jupiter
ruled a report not applicable
2 days ago
Business Logic Flaw
@
easytrend
#0x69
Jupiter
ruled a report not applicable
5 days ago
Price Oracle Manipulation
@
saturnbash
#0x4F
1
Jupiter
awarded
$300
6 days ago
Information Disclosure
·
1d
@
fcc
#0x68
Jupiter
noted a report as informative
1 week ago
Missing Authorization
@
saturnbash
#0x67
Jupiter
ruled a report not applicable
1 week ago
Business Logic Flaw
@
pjus
#0x66
Jupiter
noted a report as informative
1 week ago
Denial of Service
@
satyam
#0x65
Jupiter
ruled a report not applicable
1 week ago
Improper Access Control
@
karm
#0x64
Jupiter
noted a report as informative
1 week ago
Insufficient Session Expiration
@
cybeida
#0x63
Jupiter
noted a report as informative
1 week ago
Improper Access Control
@
karm
#0x5E
Jupiter
noted a report as informative
1 week ago
Incorrect Authorization
@
cybeida
#0x5D
Jupiter
ruled a report not applicable
1 week ago
Cross-Site Request Forgery (CSRF)
@
cybeida
#0x61
Jupiter
noted a report as informative
1 week ago
Insufficient Session Expiration
@
cybeida
#0x59
Meteora
noted a report as informative
1 week ago
Security Misconfiguration
@
bruda
#0x5F
TOCTOU Attack Allows Wallet Drain via Transaction Simulation Spoofing
Jupiter
noted a report as informative
1 week ago
Time-of-Check to Time-of-Use (TOCTOU)
@
purge
#0x54
Jupiter
noted a report as informative
2 weeks ago
JWT Algorithm Confusion
@
cybeida
#0x5C
systemic Inadequate CPI Target Program and Owner/Signer Validation Across Multiple Jupiter Programs
Jupiter
ruled a report not applicable
2 weeks ago
Insecure Direct Object Reference (IDOR)
@
bruda
#0x5A
flawed CSRF implementation
Jupiter
noted a report as informative
2 weeks ago
Cross-Site Request Forgery (CSRF)
@
cybeida
#0x55
Jupiter
noted a report as informative
2 weeks ago
Security Misconfiguration
@
bruda
#0x57
Public Swagger / OpenAPI documentation on 5 Jupiter production APIs reveals every internal route, including the 1000-JUP token-verify payment flow
Jupiter
noted a report as informative
2 weeks ago
Security Misconfiguration
@
bruda
#0x56
Subdomain takeover candidate at admin.verify.jup.ag — dangling Vercel CNAME (DEPLOYMENT_NOT_FOUND)
Jupiter
noted a report as informative
2 weeks ago
Security Misconfiguration
@
bruda
#0x52
Jupiter
noted a report as informative
3 weeks ago
Information Disclosure
@
cybeida
#0x51
Jupiter
noted a report as informative
3 weeks ago
Information Disclosure
@
cybeida
#0x53
Jupiter
flagged a report as a duplicate
3 weeks ago
Session Fixation
@
cybeida