Skip to main content
Sign in

Fake Jupiter CJUP Airdrop Phishing Campaign

avoid.net/fake-jupiter-cjup-airdrop-phishing-campaign0/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION]
anchored·9ApW8N…EKyn

Summary

An ongoing phishing campaign impersonates Jupiter Exchange (Solana DEX aggregator) by airdropping counterfeit tokens labeled '$CJUP' directly into Solana wallets, then directing recipients to wallet-draining websites that automatically empty connected wallets. First documented in early 2024 and still active as of May 2026, the campaign exploits the widespread recognition of Jupiter's legitimate annual 'Jupuary' airdrop program, which has distributed over $1 billion in real $JUP tokens since 2024.

Connected Entities

3 entities · 10 linked investigations
Wallets
JUPyiw…DvCNB8Y1dE…HA7h
Organizations
Fake Jupiter CJUP Airdrop Phishing Campaign
Relationships
  • JUPyiwrYJFskUPiHa7hkeR8VUtAeFoSYbKedZNsDvCNmentioned withFake Jupiter CJUP Airdrop Phishing Campaign(50%)
  • + 10 more
Have evidence about Fake Jupiter CJUP Airdrop Phishing Campaign?

Timeline(13 events)

2024-01-01

Jupiter Exchange completes first Jupuary airdrop, distributing 1 billion $JUP tokens to approximately 1 million Solana wallets, establishing the brand recognition that the phishing campaign subsequently exploits.

2024-02-01

Earliest variant phishing domains in the campaign family, including listed-jup[.]space and reg-jup[.]com, are documented by PCRisk malware researchers.

2025-01-01

Jupiter Exchange completes second Jupuary airdrop, distributing approximately 700 million $JUP tokens valued at roughly $616 million. The claimjupuary.pages[.]dev phishing domain is documented around this period.

2025-06-01

jupitersearns[.]com phishing domain variant documented.

2025-09-01

Cluster of claim.juplter[.*] variant domains documented, targeting users with wallet connection prompts.

2025-10-01

jupbox[.]net phishing domain variant documented.

2025-12-01

jupiterofficial-ag[.]com and jupiter.onspace variant domains documented.

2026-01-01

jup-airdrop.onspace phishing domain variant documented.

2026-02-01

Jupiter DAO opens governance vote on whether to cancel future Jupuary airdrop events, potentially eliminating the legitimate brand context that the phishing campaign exploits.

2026-03-25

PCRisk publishes updated removal guide for the Jupiter Airdrop Scam family, cataloguing over 30 malicious domains.

2026-05-22

Solana Floor issues prominent alert warning that scammers are distributing fake $CJUP tokens to Solana wallets and directing victims to drainer websites, triggering widespread coverage from crypto news outlets.

2026-05-23

WEEX Crypto News (citing rootdata) and Bitget News amplify the Solana Floor alert; Cryptopolitan, Coin Turk, and BigGo Finance publish detailed articles on the campaign mechanics.

2026-05-27

An X user documents a related NFT-based variant: 'Jupiter Airdrop Live' NFTs appearing in Phantom wallets containing embedded links or QR codes pointing to drainer infrastructure.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

model: claude-sonnet-4-6

generated: 5/28/2026, 3:54:02 AM

last updated: 5/28/2026, 5:24:02 AM

avoid.net — verified advice for a post-truth world