The Oracle program has been audited by Zenith and Offside Labs. All Jupiter Lend audits are listed on the Security page.
Oracle Program Address:
jupnw4B6Eqs7ft6rxpzYLJZYSnrpRgPcr589n5Kv4ocHop-Based Oracle System
The system computes exchange rates by processing prices from up to four sources in a sequential chain. Each source contributes to the final rate through multiplication or division, with the option to invert values as needed. The Oracle program integrates price data from Chainlink, Pyth, and Redstone. For example, the JupSOL / USDC vault multiplies the JupSOL/SOL rate read from the JupSOL stake pool by the SOL/USD price from Chainlink. This design enables the system to:- Combine rates from several sources, for example a stake pool rate and a SOL/USD price.
- Adjust for varying units or scales using predefined multipliers and divisors.
- Validate data integrity at each step.
Freshness Enforcement
To ensure prices reflect current market conditions, the system enforces strict time-based validity checks:- User operations: Prices must be no older than 600 seconds (10 minutes) to be considered valid for actions like borrowing or supplying assets.
- Liquidations: Prices can be up to 7,200 seconds (2 hours) old. The requirement is deliberately looser so that liquidations can proceed during temporary oracle delays and keep the protocol safe.
Confidence Interval Validation
The system evaluates the confidence interval provided by Pyth price feeds to ensure data reliability:- User operations: The confidence interval must be within 2% of the reported price.
- Liquidations: The confidence interval must be within 4% of the reported price.
Providers
The Oracle program supports three market data providers:- Chainlink: primary provider for most vaults. xStocks are priced with Chainlink Data Streams.
- Pyth Network: used for a few vaults: the SOL/USD leg of the mSOL / USDC and mSOL / USDG vaults, and both legs (SOL/USD and BTC/USD) of the SOL / xBTC vault. A migration of these to the new Pyth Core is planned.
- Redstone: supported by the Oracle program as a provider.
Contract-Based Pricing
Pegged and yield-bearing assets are priced on a rate that tracks what the token is worth in its underlying asset, rather than on a market price. Some of these rates are read directly from the asset’s own contract; others come from a rate feed published by an oracle provider. Read from the asset’s contract:- JupSOL, JitoSOL, dfdvSOL, fwdSOL, japanSOL: the SPL stake pool’s accounting rate, SOL under management divided by the tokens outstanding. The rate is rejected if the pool has not been updated during the current epoch or if a deposit or withdrawal fee exceeds 0.5%.
- mSOL: Marinade’s accounting rate, the SOL backing the pool divided by the mSOL supply.
- PST: the PST pool’s accounting rate, the USD value of the pool’s assets divided by the PST supply.
- INF: the Sanctum Infinity pool’s rate, read from the pool state and the INF supply.
- JUICED: Jupiter Lend’s own exchange rate between JUICED and JupUSD.
- Native staked tokens (nsJUPITER and the other Native Staked Vaults): the SPL Single Pool rate.
- syrupUSDC: Chainlink’s syrupUSDC-to-USDC exchange rate feed.
- sUSDai: Chainlink’s sUSDai-to-USDai exchange rate feed, updated about every 8 minutes with an 11-minute staleness check.
Stablecoin Pegs
When a vault’s debt is a dollar stablecoin (USDC, USDT, USDG, USDS, JupUSD, or PYUSD in the Sentora Market), the Oracle values that stablecoin at exactly 1 USD: no price feed is read for it. The collateral’s USD price is compared to the debt at par, so the same collateral has the same price against every dollar stablecoin. As a result, a stablecoin depeg does not change your debt-to-collateral ratio: it neither triggers nor prevents a liquidation. EURC debt is the exception: it is converted with a EUR/USD feed.Oracle Interaction with Liquidations
Oracle prices are directly used to evaluate and determine liquidation events. Each vault has predefined thresholds:- Liquidation Threshold (LT): When the debt-to-collateral ratio exceeds this value, the vault becomes eligible for partial liquidation through the tick-based system.
- Liquidation Max Limit (LML): If the ratio surpasses this limit, the position exits the tick system and is fully liquidated.
See how a vault is priced
Every vault in the Borrow, Multiply and Smart Vaults lists has a globe button, on its row or its card, that opens the vault’s Oracle details. The first view shows the vault’s price, as one unit of collateral in the debt asset (for example1 PST = 1.13 USDC), the oracle address with an explorer link and a copy button, and a one-line description of how the price is built, including whether a fallback oracle is used.
Show More adds:
- The Operate Price, used for deposits, withdrawals, borrows and repayments, and the Liquidation Price, used to check whether a position can be liquidated. They can differ, because user operations and liquidations accept different price ages and confidence intervals (see above).
- The type of each source: Market price, Redemption rate, or Exchange price.
- The Price Route: the sources multiplied together, or divided for an inverted leg, to reach the price.
- One card per leg, with its provider, its current value, its oracle address, and an explanation of what it measures and when it was last updated.
1 PST = 0.56 debt shares. See the Smart Vaults walkthrough.
