Quantum Audit Logo
Solana · Smart Contract Security · Updated Jul 24, 2026

Is Jupiter Safe? JUP

On-chain security analysis — is it a scam or legit?

Contract JUPyiw…DvCN DexScreener ↗
Volume 24h
$577.9K
Liquidity
$1.09M
Price
$0.1939
Token Age
7mo
Top 10 Holders
66.8%

Security Checklist

Contract VerifiedFail
Ownership RenouncedUnknown
No Mint FunctionUnknown
Liquidity LockedFail
Not a ProxyPass

Audit History

Jul 2354

Every audit run adds a dated snapshot — history is append-only and cannot be edited.

Audit Summary

This audit of the Jupiter (JUP) SPL token mint identifies a low-severity risk related to mutable metadata, meaning the token's name, symbol, or image can be altered post-launch. Key authorities like mint and freeze are appropriately revoked, indicating a fixed supply and unfreezable accounts. Holder distribution data was unavailable, preventing an assessment of concentration risk.

Final Recommendation: Holders should verify the token's metadata against official sources to ensure branding consistency, especially given its mutability. Monitor for any changes to the token's name, symbol, or image that could indicate a change in project identity or intent. While key authorities are revoked, the absence of holder distribution data means investors should be aware of potential concentration risks that could impact price stability.

Category Ratings

TechnicalMedium
6/10

The Jupiter (JUP) token operates on the standard `spl-token` program (v3). Both the Mint Authority and Freeze Authority are revoked, ensuring no new tokens can be minted and no existing accounts can be frozen. The token does not utilize advanced Token-2022 extensions such as balance mutability, non-

GovernanceHigh
1/10

The token exhibits strong market health with over $216 million in DEX liquidity and $82 million in 24-hour trading volume. The Volume/Liquidity Ratio of 0.38 is normal, not indicating wash trading. The DEX pair has been active for 258 days, providing a sufficient track record. However, holder concen

UpgradesMedium
5/10

The token's core functionalities are immutable, as both the mint and freeze authorities have been revoked. There are no indications of upgradable transfer fees or transfer hooks. The only mutable aspect identified is the token's metadata, which allows for changes to its name, symbol, or im

What Raised This Score

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Security Findings

1 Low
L-01LowUnresolved

Mutable Metadata

The token's metadata is mutable, meaning its name, symbol, or image can be changed post-launch. This was identified by the `metadata_mutable: True` flag.

Recommendation: Verify metadata against off-chain expectations before trusting branding. Monitor for any changes to the token's branding elements.

Frequently Asked Questions

Is Jupiter a scam?

Characterizing Jupiter (JUP) as a "scam" requires direct evidence of malicious intent, which isn't provided by the data alone. However, significant red flags exist, including an unverified contract and high token centralization (top 10 holders owning 68.3% of supply). While ownership is renounced and no mint function exists, these risks contribute to its 58/100 "High Risk" score, indicating serious concerns.

Is Jupiter safe to buy?

Investing in Jupiter (JUP) carries notable risks, making it difficult to deem "safe" based on current data. The primary concerns include the unverified contract, which prevents public code scrutiny, and the lack of locked liquidity, raising potential rug pull scenarios. Furthermore, 68.3% of the supply is held by the top 10 wallets, indicating significant centralization risk. These factors contribute to its "High Risk" classification.

Has Jupiter been audited?

The provided data indicates the Jupiter (JUP) contract is "not verified." This means its code has not been publicly published on the blockchain explorer. Without verification, an independent audit of the contract's logic for security vulnerabilities or unintended functions is extremely difficult, if not impossible, for external parties. This lack of transparency is a significant risk.

Would You Like a More Detailed Audit of Jupiter?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, no signup required.

Get Detailed Audit
Run Free Audit →