- Lightspeed
- Posts
- 🗺️ Different world
🗺️ Different world
Jupiter’s vault is unlikely to face a Hyperliquid-style attack

Howdy!
Today marks the end of Q1 2025, and DogWifHat is still yet to grace the Las Vegas Sphere. Sad!
Today, we’ve got Jupiter’s risk vault, Sol Fi’s ascendance, and white label Solana validators:
Jupiter’s risk vault unlikely to face Hyperliquid-style attack
Following Hyperliquid's $13 million brush with disaster, some in Solana's orbit are wondering: Could Jupiter's JLP vault — a similar product to Hyperliquid’s vulnerable vault — face a similar exploit?
Nope.
That's my short but genuinely confident answer. Let's unpack why.
To recap briefly: Last week, some unknown trader thought they'd get cute by manipulating the price of thinly-traded Jelly-my-Jelly (JELLY) memecoin on decentralized perp exchange Hyperliquid. The presumed goal was to mobilize a massive short squeeze, allowing them to profit from leveraged long positions while forcing the protocol to absorb the loss from their short.
The attacker’s leveraged long positions quickly created over $13 million in unrealized losses to Hyperliquid’s HLP risk vault and an emergency shutdown that forcibly closed all JELLY positions at a price favorable to Hyperliquid's balance sheet.
Now, we can argue whether it was a bailout, anathema to a decentralized ethos, or just pragmatic damage control another time. The point is, it worked.
By forcibly settling all JELLY positions at the exploiter’s short entry of $0.0095, the protocol basically reversed the attack. Which is to say that Hyperliquid actually, hilariously, ended up posting a profit of around $700,000 while the attacker walked away with less than they deposited. The Hyperliquid team promptly assured users they would be made whole through the Hyper Foundation, and everyone lived happily ever after.
Hooray.
But if perps DEXs can be attacked, that raises questions about Jupiter, Solana's biggest DEX aggregator and perps exchange. Like Hyperliquid, Jupiter's platform is powered by a vault that acts as the counterparty to all trades. This would be the very creatively named (/s) Jupiter Liquidity Provider pool, or JLP. The JLP collects trading fees and earns big when traders lose but takes a hit when they win.
HLP. JLP. It sounds pretty same-same. So with that in mind, could this vault be squeezed in a similar way? In theory, yes. Anything's possible. I'm not going to call the Titanic unsinkable. But Jupiter's architecture makes it an improbable outcome in practice.
First, consider its asset list. No offense to JELLY, but the token had very little liquidity, making price manipulation easier. Hyperliquid listed it because it prioritized volume, novelty, and a wide-open asset strategy to attract degens.
Jupiter doesn't do that. Its perpetuals are limited to major assets like SOL, ETH, and wrapped BTC. That decision alone eliminates the kind of thin-market vulnerability that made JELLY so exploitable. A Jupiter representative said the platform’s maximum order size is much smaller than Hyperliquid’s as well.
Second, price execution. Hyperliquid relies on its internal orderbook to match traders directly against each other. Users submit their own limit orders, giving them more flexible, dynamic pricing. However, that also leads to a plethora of exploitable scenarios. A motivated attacker can influence the price displayed on the platform, setting up artificial moves that trigger cascading liquidations and/or dislocations. No bueno, compadres.
Jupiter's perp markets operate in a totally different way, choosing instead to execute at oracle prices from external sources like Pyth. Even if a trader tried to pump the spot price of SOL on another exchange, they'd still be trading against the median on-chain price, not a manipulated in-platform quote.
Frankly, it's just harder to game the house when the pricing comes from outside the casino.
Third, Jupiter handles risk with guardrails, not emergency exits. JLP is always the counterparty. If a trade gets liquidated, the levers for that would pull automatically at the set Oracle price. So far as we know, there's no handoff to a second vault, no delay that a bad actor can game, and no pause for a team call or validator vote. Losses go straight to the pool.
Again, one could argue this makes the system blunt or unforgiving, but it's something LPs accept as part and parcel (and the reasons why should now be pretty clear).
That's not to say that JLP is immune to risk, because it's not. It regularly takes losses in the case of a one-sided market where most traders win, for instance. But Jupiter bakes in defenses for that, too. Traders pay borrow fees to open leveraged positions, which go straight to the pool. If everyone piles into longs, funding rates rise to balance the associated risks.
Could some unforeseen scenario force Jupiter to intervene someday in a way that its users find questionable? Yes. Every protocol has an edge case. But in this specific scenario, Jupiter seems to have designed JLP to absorb such hazards. While Hyperliquid had to delist a token to save its vault, Jupiter has taken the opposite approach: limit risk at the door.
So, with that in mind, rest easy Lightspeeders. Jupiter isn’t playing the same game Hyperliquid nearly lost.
— Jeff Albus
P.S. Fill out our short audience survey and help us build a better Lightspeed. Thank you!
If You’re Shipping, You Belong Here.
This isn’t a conference for think pieces and panels that go nowhere. It’s where devs roll up with code that works, founders with product in motion, and teams with real traction.
Infra, DeFi, gaming, whatever — you’re not early, you’re already in it.
Apply to speak. Build at the hackathon.
Your next cycle starts in Brooklyn.
Build fast. Touch grass. Ship in Brooklyn.
June 22-26 | Brooklyn, NY

Here are Solana’s SOL-USD volume numbers. Check out that magenta bar at the bottom:
PumpSwap got lots of attention, but the Solana AMM that’s really taken off for SOL-USD swappers is Sol Fi.
The platform has little online footprint, and all I have heard is anecdotally that it gets good swap prices. Dark horse DEX or fake volume favorite? It’s hard to tell for now.
— Jack Kubinec

Be looking out for white-label Solana validators.
Running Solana validator nodes is not immensely complex, and making money as a validator comes down to how much stake it can attract. With this in mind, one business line that seems to make sense is white label validators, where operators run validator services on behalf of larger brands who can use their distribution to attract stake.
Consider a Venmo validator, for instance. Under the hood it could be Figment or Kiln running the nodes, and Venmo could leverage its huge userbase to market and draw stake to the product. Think further down the chaos curve, too. A Formula 1 team validator. A Wyoming state government validator. A Hawk Tuah girl validator.
In the broader business world, celebrity-branded products have become a lucrative trend. Why can’t the same be true for Solana validators?
— Jack Kubinec

A message from Katherine Ross, author of the Empire Newsletter:
