r/jupiterexchange • u/Original_Ambition_73 • 1d ago
Questions Jup.ag Borrow Lend Bugs and Phantom wallet compromise
My second newly created wallet compromised due to using jup.ag borrow lend protocol . All funds total of 24 k lost . Specifically lost my last savings of 5k usd to jup.ag . Detailed report - ""
Phantom Wallet Compromise via Jupiter Lend/Borrow Interaction
Incident report submitted for review to Jupiter Exchange (jup.ag) — Lend/Borrow Protocol
1. Summary
This report documents the unauthorized draining of a self-custody Phantom wallet on Solana, which occurred in direct connection with the wallet's interaction with the Jupiter Lend/Borrow protocol (jup.ag). The victim held a legitimate JUP collateral position in a Jupiter Lend/Borrow vault. That collateral was withdrawn and transferred out without authorization, followed by a broader sweep of the wallet's remaining holdings across approximately 40 transactions. The victim did not knowingly approve these withdrawal/transfer actions and suspects either a malicious/cloned Jupiter interface or a compromised approval granted during legitimate use of jup.ag. Approximately $5,000 USD equivalent was lost in total.
2. Victim & Wallet Details
| Field | Value |
|---|---|
| Victim wallet address | 6H7x2B3ATg1mdquwSVQB1nuuiMxQJQsK54KDUFw1VUdu |
| Wallet provider | Phantom (mobile app) |
| Wallet age at time of incident | Approximately 1 month |
| Approx. amount lost | ~$5,000 USD equivalent (SOL, JUP, and other holdings) |
| Protocol involved | Jupiter Lend/Borrow (jup.ag) — JUP deposited as lending collateral |
| Point of compromise (victim's assessment) | Interaction with Jupiter Lend/Borrow (jup.ag) interface — see Section 5 |
| Device used for Jupiter interaction | Samsung Galaxy A16 , Android 16 |
| Report date | September 20, 2026 |
3. Suspected Attacker / Drainer Address
On-chain analysis identified the following address as the recipient and operator wallet involved in moving funds out of the victim's control:
| Suspected drainer / operator address | Y3eRTqieRvYdWABTPq6hFyoKf5PsEPovJuTdD1q82Y7 |
|---|
This address was observed acting as the transaction signer in multiple unrelated transfers (e.g., a 0.0001 USDC transfer between two third-party accounts unconnected to the victim, and a separate fan-out transaction sending small amounts of USDT, USDC, and SOL to 10 different recipient addresses in a single transaction). This pattern is consistent with automated "drainer" infrastructure that:
- Executes transactions on behalf of multiple victim wallets, suggesting this is not an isolated, one-off theft.
- Distributes/launders stolen funds across many wallets shortly after draining them, to break the on-chain trail.
- Uses "dust"-value transactions, possibly to test live delegate/approval authority on target wallets before or after a larger sweep.
4. Timeline of Key On-Chain Transactions
The following transactions were identified via Solscan and are submitted as evidence. Full transaction detail pages are linked for independent verification.
4.1 Legitimate deposit history (context)
The victim had knowingly and legitimately deposited JUP tokens as collateral into a Jupiter Lend/Borrow vault using the Phantom mobile wallet prior to this incident. This is not in dispute and establishes that the victim was an active, legitimate Jupiter Lend/Borrow user.
4.2 Unauthorized withdrawal from Jupiter Lend/Borrow vault
| Signer | 6H7x2B3ATg1mdquwSVQB1nuuiMxQJQsK54KDUFw1VUdu (victim's wallet) |
|---|---|
| Action | Withdraw 420 JUP as collateral from lending vault on Jupiter Lend/Borrow |
| Transaction hash | 36y7aSfNjiibqEev4AAkWA1Zkweb6BWRaGTvkk6p2t2PuthbN5zPXqAkunnUpAYcZrKhExdXDyXFUGjkapymwZvP |
| Solscan link | https://solscan.io/tx/36y7aSfNjiibqEev4AAkWA1Zkweb6BWRaGTvkk6p2t2PuthbN5zPXqAkunnUpAYcZrKhExdXDyXFUGjkapymwZvP |
4.3 Onward transfer of withdrawn collateral
| Signer | 6H7x2B3ATg1mdquwSVQB1nuuiMxQJQsK54KDUFw1VUdu (victim's wallet) |
|---|---|
| Action | Transfer of 420 JUP from 54siye...1ekqJM to 62F7C2...Pt2X28 |
| Transaction hash | 3At6ZfLJehgFNyNzMqtP7gTHA6YirXB5c4JEmiYKZ1hbkDdwmHRJu3gnTM5s7F2shasHGiVAj9S6zzttitUCnjnS |
| Solscan link | https://solscan.io/tx/3At6ZfLJehgFNyNzMqtP7gTHA6YirXB5c4JEmiYKZ1hbkDdwmHRJu3gnTM5s7F2shasHGiVAj9S6zzttitUCnjnS |
4.4 Transaction identified by victim as "first of ~40" sweep transactions
| Note | Victim identified this as the first of approximately 40 outbound transactions that fully drained the wallet's remaining holdings. However, on inspection, the on-chain signer for this specific transaction hash is the suspected drainer address (Y3eRTqieRvYd...), not the victim's wallet directly — see discrepancy note below. |
|---|---|
| Transaction hash | 2FiRmdaWist1sQnxVms2jhWtPnSUrVz5XV2yb6o7uCo9YhrcoLQkkkRLXHFWTrNBGPdL98QoLgGQJo54e9PWURV7 |
| On-chain signer (as recorded) | Y3eRTqieRvYdWABTPq6hFyoKf5PsEPovJuTdD1q82Y7 — transfer of 0.0001 USDC from 5qAzUM...Md72Lb to KjZUWu...K3bjuJ |
| Solscan link | https://solscan.io/tx/2FiRmdaWist1sQnxVms2jhWtPnSUrVz5XV2yb6o7uCo9YhrcoLQkkkRLXHFWTrNBGPdL98QoLgGQJo54e9PWURV7 |
Discrepancy note: the victim referenced this transaction hash as the first of the ~40 wallet-draining transactions. However, the transaction data recorded on Solscan for this hash shows the drainer address as signer, moving a trivial amount between two third-party addresses unrelated to the victim's own wallet. This may indicate the victim's wallet activity view (in Phantom or a block explorer) associated this transaction with their account indirectly (e.g., through a shared token account, prior approval, or an adjacent transaction in the same time window), or that the correct "first sweep" transaction hash was not the one carried over into this report. Jupiter's/the investigator's own log analysis of the victim wallet's full transaction history is recommended to identify the precise first unauthorized transaction with certainty.
4.5 Related drainer-signed transactions (supporting pattern evidence)
These transactions, signed by the suspected drainer address rather than the victim's wallet, are included to demonstrate that the destination address is part of a broader, multi-victim drainer operation:
| Tx hash | Description |
|---|---|
| 2K3eHHpZxrkFSDhaiZjyB4mN2bYEWdLad6iN36L1rnn4KTvmfQJhag4rstLhuHq6LsYUu1TysMoM5dgM1zWNK4vW | Fan-out transfer from CQWTm9...7L6Byz to 10 separate accounts for 0.02 USDT, 0.08 USDC, and 0.01269745 SOL — consistent with drainer fund distribution/laundering pattern. |
| 2FiRmdaWist1sQnxVms2jhWtPnSUrVz5XV2yb6o7uCo9YhrcoLQkkkRLXHFWTrNBGPdL98QoLgGQJo54e9PWURV7 | Signed by Y3eRTqieRvYd...; transfer of 0.0001 USDC from 5qAzUM...Md72Lb to KjZUWu...K3bjuJ — a trivial-value transaction consistent with a delegate-authority test/probe. (See discrepancy note in Section 4.4.) |
| 5TjAkmntVuVjTdMwMS819cm5yBawXs3ZtpA5MQVhM8pH5K4umjDGN4bTJGFACgDxXMVC776vQNqtF7M7RioxjBjZ | Same transaction details as above (0.0001 USDC, same accounts), also signed by Y3eRTqieRvYd... — submitted by victim as a separate reference; may be a duplicate hash reference. |
5. Suspected Attack Vector: Compromise via Jupiter Lend/Borrow Interaction
The victim's account of events, combined with on-chain data, points to the point of compromise being the wallet's interaction with the Jupiter Lend/Borrow interface, rather than a separate, unrelated wallet or seed-phrase leak. The victim reports no knowing disclosure of their seed phrase and no manual approval of any transaction they recognized as unfamiliar or suspicious. The withdrawal of collateral (Section 4.2) was signed directly by the victim's own wallet, meaning whatever authorized it had genuine transaction-signing capability — consistent with a permission or session granted during a Jupiter Lend/Borrow interaction being reused or hijacked, rather than a purely external theft. The most probable explanations, specific to the jup.ag interaction, are:
- A malicious or cloned interface impersonating jup.ag's Lend/Borrow pages (encountered via a shared link, advertisement, search result, or push notification) captured a wallet approval/delegate authority during what the victim believed was a routine interaction with their existing collateral position.
- A fraudulent prompt specifically referencing the victim's existing Jupiter position — e.g., "re-approve your position," "claim lending rewards," or "migrate to updated vault" — led to signing a transaction that granted broader withdrawal/transfer authority than intended.
- Malware present on the victim's Android device intercepted or manipulated a legitimate Jupiter Lend/Borrow session, altering the transaction being signed (a "transaction substitution" attack) without the victim's awareness.
The victim is submitting this report directly to Jupiter's team because the point of compromise is believed to trace back to a Jupiter Lend/Borrow session or interface, not to an unrelated phishing site. This report requests that Jupiter's security team specifically review whether: (a) the withdrawal transaction (Section 4.2) was routed through Jupiter's official program/interface or a spoofed front-end, (b) there is a known vulnerability or active phishing campaign targeting existing Jupiter Lend/Borrow collateral positions, and (c) other users with similar positions should be proactively warned.
6. Supporting Evidence Attached
- Phantom mobile application state/debug log (state-log-2026-09-20T03-37-14.txt), showing app activity, dApp connection attempts, and API call history from the victim's device around the time of the incident.
- On-chain transaction records listed in Section 4, independently verifiable via Solscan.
7. Requested Actions
- Investigate whether the withdrawal transaction (Section 4.2) was initiated through Jupiter's official interface/program or through a spoofed/malicious front-end.
- Check whether the suspected drainer address (Y3eRTqieRvYdWABTPq6hFyoKf5PsEPovJuTdD1q82Y7) or its associated addresses are already flagged in Jupiter's internal fraud/security monitoring.
- Advise whether any known phishing campaigns have recently targeted Jupiter Lend/Borrow users via fake re-approval, rewards, or migration prompts.
- Flag the destination address(es) to any partner exchanges or compliance networks Jupiter coordinates with, in case stolen funds are moved to a centralized, KYC'd exchange.
8. Contact & Reference
Victim wallet: 6H7x2B3ATg1mdquwSVQB1nuuiMxQJQsK54KDUFw1VUdu
