Hello Jupiter Team and DAO Members,
I’m not around much, but I have supported Jupiter since its early days and participated in various proposals. Today, I am writing to share a personal experience and propose a solution to protect our community.
What Happened:
Due to a malfunction in my computer, I temporarily switched to my Huawei tablet. I searched for “Jupiter AG” on the Huawei App Store and downloaded a fake app, which completely drained my wallet.
My stolen wallet:
12hEVLcPvCnbfQDLhNJvotkygBMGYVtHEzPz5A3mNFJB
Stupidity is also a bit about trust. Jupiter’s logo fooled me.
I admit that I am an idiot. I know that everyone is smart about something and for a while and always stupid about most things.
My assets were already down to $800. I had it all stolen, which may seem like a trivial amount to some people. I live in Turkey. This amount is about two month’s minimum wage for 1 person in Turkey.
You can review the transactions via this Solscan link:
The fraudster’s wallet.
I’ve detailed the incident in this tweet:
As expected, Huawei is responsible for the security of the app market, but I get no response from Huawei.
The Scale of the Issue:
As seen in the thief’s wallet transactions, this fake app has been active for at least a month. I estimate that dozens (possibly hundreds) of users have fallen victim during this period.
My Proposal: Proactive Fraud Prevention Program
I propose that Jupiter Exchange & DAO launch the “Community Based Anti-phishing Security Guardians” program:
- Early Detection System: Users report suspicious apps/sites to Jupiter.
- Rapid Response: Reported fraud attempts are swiftly investigated The fake and malicious application is quickly taken down through corporate-to-corporate communication before more people are affected. and shared publicly.
- Compensation Support: Verified victims receive partial reimbursement from DAO funds.
- Reward Mechanism: Users who first report fraud are rewarded with JUP tokens.
Why This Program Matters:
- Reputation Protection: Every fraud incident damages Jupiter’s credibility. Proactive measures enhance brand value.
- Community Solidarity: Users develop loyalty when they feel Jupiter’s support.
- Sustainability: Platforms prioritizing security become long-term leaders in the DeFi ecosystem.
How does the program work?
Form Interface at jup.ag:
- apps that they think are fake/Suspicious,
- URL
- Platform information,
- screenshots
- The notifier’s e-mail, etc.
- Stolen wallet information
- Thief’s wallet information
information, as well as note and wallet IDs, and sends them to a form on Jup.ag.
Early notification is evaluated and, if it is correct, the person informed is rewarded.
Individual users are less likely to be heard by companies like Huawei, Apple Google, etc. than a corporate structure like Jupiter.
I open this proposal for discussion. With your support, we can protect victims like me and strengthen Jupiter’s global impact.
Thanks in advance.
PS: If my proposal is approved, maybe I will be the first beneficiary of the program.
Murat.