Jupiter Yield Store Review
Smart contract case study
Overview
In July and August 2026 Guardian reviewed Yield Store for Jupiter: the curated-vault program that lets a curator run a strategy across Jupiter Lend, Jupiter Swap and Offerbook on behalf of its depositors. At 5,694 source lines across 72 files it is the largest Jupiter scope Guardian has reviewed, and it returned more findings than any other Jupiter engagement.
Guardian
Guardian provides institutional-grade security for digital asset teams, onchain and off. Every engagement runs two independent teams, backed by Helix, Guardian's AI auditor, and only human-verified findings reach the client.
Jupiter
Jupiter is the leading trading and DeFi platform on Solana, with more than $3T in lifetime volume. Guardian has run nine engagements for Jupiter in ten months, across JupUSD, Offerbook, Jupiter Lend and Yield Store.
Why a vault program is hard to get right
A curated vault holds depositors' funds while a curator, and the delegates it appoints, move those funds into other protocols. Its safety rests on accounting that has to stay true while the assets sit in positions the vault does not directly control: net asset value, share pricing on every subscribe and redeem, fee crystallisation, and the permissions that bound what each delegate can do in each protocol.
Every one of those is a place where a small rounding choice, a stale price or a missing check turns into value moving between depositors, or out of the vault.
Scope
The jup-ag/yield-store Solana program and its interface crate:
- Vault initialisation, configuration and curator hand-over
- Subscribe and redeem flows, both direct and queued, with fulfilment, claims and cancellation
- NAV calculation, AUM validation and oracle pricing
- Fee crystallisation
- Delegate permissions and the CPI adapters into Jupiter Lend, Jupiter Swap and Offerbook
- Transfer-hook integration and escrow handling
How Guardian approached it
- Two independent teams. Each team reviewed the whole program separately, and their findings were merged and cross-checked.
- A fuzzing engineer alongside them. The accounting a vault depends on was pressure-tested beyond what line-by-line review reaches.
- Both sides of every adapter. Guardian had reviewed Offerbook only weeks earlier, so the integrations were read by researchers who knew the protocol on the other side of each call.
- Accounting as properties. NAV, share pricing and fees were checked against what must hold for every depositor at once, not only against what each instruction intends.
Results
The review returned 47 findings, including one Critical and six High severity issues: the most of any Guardian engagement for Jupiter. Most were logic and validation issues in exactly the areas above, where the vault's accounting and permissions meet the protocols it routes into. Guardian's final report was published on August 12, 2026.
- Critical: 1
- High: 6
- Medium: 16
- Low: 12
- Informational: 12
Jupiter brought the next round of Yield Store changes straight back to Guardian, and that review is under way now. Finding details are in the public report.
Impact
- A Critical and six Highs surfaced in a program built to hold depositor funds
- Integrations into Lend, Swap and Offerbook reviewed with knowledge of both sides
- A continuing review cycle: Jupiter returned with the next set of Yield Store changes
Read the full relationship in the Jupiter client story.
Building vaults or strategies that route across protocols? Guardian's two-team audits are built for exactly this kind of accounting.
