Fake Jupiter CJUP Airdrop Phishing Campaign
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·9ApW8N…EKynSummary
An ongoing phishing campaign impersonates Jupiter Exchange (Solana DEX aggregator) by airdropping counterfeit tokens labeled '$CJUP' directly into Solana wallets, then directing recipients to wallet-draining websites that automatically empty connected wallets. First documented in early 2024 and still active as of May 2026, the campaign exploits the widespread recognition of Jupiter's legitimate annual 'Jupuary' airdrop program, which has distributed over $1 billion in real $JUP tokens since 2024.
Connected Entities
3 entities · 10 linked investigations- JUPyiwrYJFskUPiHa7hkeR8VUtAeFoSYbKedZNsDvCN→mentioned with→Fake Jupiter CJUP Airdrop Phishing Campaign(50%)
- + 10 more
Community submissions
- Under reviewincriminatingWayback pending6/2/2026, 7:36:58 PM
“Cryptopolitan January 2026 report confirming the fake CJUP Jupuary airdrop phishing campaign remains active on Solana with ongoing victim losses”
— avoid-scout
Timeline(13 events)
2024
Jupiter Exchange completes first Jupuary airdrop, distributing 1 billion $JUP tokens to approximately 1 million Solana wallets, establishing the brand recognition that the phishing campaign subsequently exploits.
February 2024
Earliest variant phishing domains in the campaign family, including listed-jup[.]space and reg-jup[.]com, are documented by PCRisk malware researchers.
2025
Jupiter Exchange completes second Jupuary airdrop, distributing approximately 700 million $JUP tokens valued at roughly $616 million. The claimjupuary.pages[.]dev phishing domain is documented around this period.
June 2025
jupitersearns[.]com phishing domain variant documented.
September 2025
Cluster of claim.juplter[.*] variant domains documented, targeting users with wallet connection prompts.
October 2025
jupbox[.]net phishing domain variant documented.
December 2025
jupiterofficial-ag[.]com and jupiter.onspace variant domains documented.
2026
jup-airdrop.onspace phishing domain variant documented.
February 2026
Jupiter DAO opens governance vote on whether to cancel future Jupuary airdrop events, potentially eliminating the legitimate brand context that the phishing campaign exploits.
25 March 2026
PCRisk publishes updated removal guide for the Jupiter Airdrop Scam family, cataloguing over 30 malicious domains.
22 May 2026
Solana Floor issues prominent alert warning that scammers are distributing fake $CJUP tokens to Solana wallets and directing victims to drainer websites, triggering widespread coverage from crypto news outlets.
23 May 2026
WEEX Crypto News (citing rootdata) and Bitget News amplify the Solana Floor alert; Cryptopolitan, Coin Turk, and BigGo Finance publish detailed articles on the campaign mechanics.
27 May 2026
An X user documents a related NFT-based variant: 'Jupiter Airdrop Live' NFTs appearing in Phantom wallets containing embedded links or QR codes pointing to drainer infrastructure.
Decision Log
- hash: 4tfiiCceeknHCbESgHSEd7rQdipkR9RGArAmxUhNbKuw
This investigation is cryptographically anchored to the Solana blockchain (1 event). 20 of 21 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/28/2026, 3:54:02 AM
last updated: 9/1/2026, 4:31:10 AM
avoid.net — verified advice for a post-truth world