Skip to main content
AVOID.NET

Juicebox V3

avoid.net/juicebox-v340/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·ZpwEm5…a7YT

Summary

Juicebox is an Ethereum-based programmable treasury and crowdfunding protocol first launched in July 2021 by a pseudonymous developer known as Jango, enabling projects to raise ETH, issue contributor tokens, and manage on-chain treasuries without intermediaries. V3 is the third major iteration of the core contracts, deployed in September 2022, and subsequently patched through versions 3.1, 3.1.1, and 3.1.2 to address a series of high-severity and critical accounting vulnerabilities. A protocol logic exploit in April 2026 resulted in an alleged $52,000 loss via a borrowFrom spoof attack, and the platform's permissionless architecture has enabled misuse by bad actors operating fraudulent fundraising projects.

Connected Entities

6 entities · 60 linked investigations
Relationships
  • ZachXBTmentioned withEthereum(70%)
  • Juicebox V3mentioned withZachXBT(70%)
  • Juicebox V3mentioned withEthereum(80%)
  • Juicebox V3mentioned withBitget(60%)
  • Juicebox V3mentioned withUniswap(65%)
  • Uniswapmentioned withEthereum(80%)
  • Cointelegraphmentioned withZachXBT(70%)
  • Cointelegraphmentioned withEthereum(60%)
  • Juicebox V3mentioned withCointelegraph(60%)
  • Bitgetmentioned withZachXBT(70%)
Have evidence about Juicebox V3?

Timeline(16 events)

July 2021

Juicebox protocol V1 launched on Ethereum mainnet by pseudonymous developer Jango.

18 August 2021

Low-severity bug discovered in V1 affecting reserved rate calculations for projects that received payments with a reserved rate of 0% before later reconfiguring to a non-zero reserved rate.

18 November 2021

ConstitutionDAO raises approximately $46 million in ETH through Juicebox to bid on a copy of the U.S. Constitution at Sotheby's; bid is unsuccessful.

February 2022

AssangeDAO raises approximately 17,423 ETH (then roughly $53 million) via Juicebox, becoming the largest DAO fundraiser on the platform at the time.

9 April 2022

AssangeDAO multi-signature wallet transfers 583.755 ETH without community approval, triggering fraud allegations and calls for legal action against the founding team.

29 March 2022

Certik publishes security assessment of Juicebox V2 contracts, flagging project owner's ability to send ETH to arbitrary addresses and recommending multi-sig and timelock controls.

24 May 2022

Medium-severity bug in JBFundingCycleStore triggered by successive reconfigurations in rolled-over funding cycles; contracts redeployed May 25 and project migration completed by May 28.

July 2022

Code4rena V2 audit identifies honeypot vulnerability allowing project owners to trap contributor funds.

20 September 2022

Juicebox V3 deployed to Ethereum mainnet following audits by PeckShield, Certik, and Code4rena.

23 October 2022

Code4rena competitive audit of Juicebox V3 closes; 13 unique vulnerabilities identified including 5 HIGH severity findings covering fund loss, reserve token underflow, honeypot exploitability, and NFT redemption weight miscalculation.

17 February 2023

JuiceboxDAO approves JBP-341 to address high-severity bug discovered during V3 JBX migration contract deployment.

21 February 2023

Juicebox V3.1 deployed to Ethereum mainnet with JBETHPaymentTerminal3_1 and JBController3_1 to address the high-severity migration bug and additional security risks.

22 May 2023

Code4rena audit of Juicebox Buyback Delegate closes; 3 medium-severity issues found including partial Uniswap V3 swap execution and slippage protection gaps.

30 June 2023

Juicebox V3.1.1 deployed, fixing low-severity payout revert bug and adding gas optimizations.

15 August 2023

Juicebox V3.1.2 deployed, fixing critical fee accounting error where protocol miscalculated expected deposit amounts after payout returns, leaving projects financially underfunded.

20 April 2026

Juicebox V3 suffers alleged $52,000 loss via a borrowFrom spoof attack on Ethereum, classified by DeFiLlama as a Protocol Logic exploit.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 17 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:11 AM

last updated: 8/30/2026, 8:07:19 PM

5 views

avoid.net — verified advice for a post-truth world