How to Use Tangem with Jupiter DEX — Cold Storage Swaps on Solana
This article is available in the following languages:
Most people who hold Solana tokens face a quiet trade-off. Keep assets in a hot wallet to trade instantly, but your private keys stay on an internet-connected device. Move to cold storage, and you feel safer, but you assume you've locked yourself out of DeFi entirely. That assumption is wrong.
Through WalletConnect, Tangem can connect to Jupiter on jup.ag while your private key stays inside the card's secure element. This guide walks you through exactly how the connection works, what each feature looks like in practice, and what to watch for before you tap to sign.
What Jupiter Is and Why It Matters for Cold Storage
Solana launched in 2020 as a high-performance Layer 1 blockchain for decentralized applications and crypto-assets. Its token standard, SPL tokens (defined by the Solana Program Library), covers both fungible tokens and NFTs. The Solana ecosystem includes multiple decentralized exchanges, and Jupiter is the aggregator that sits atop them.
Here's what that means in practice. When you want to swap, say, SOL for USDC, Jupiter queries multiple DEXs simultaneously. It can split the order if needed and return the best combination of price and slippage it can find. You see one transaction; Jupiter handled the routing.
Jupiter's feature set goes beyond simple swaps. Its documented advanced trading tools include limit orders (execute at a target price rather than the current market rate), dollar-cost averaging (schedule recurring purchases), and perpetual contracts. The JUP token itself is a governance token; holders vote on decisions about Jupiter's development and future direction.
None of this requires a hot wallet. That's the relevant fact for Tangem users. The common assumption is that DeFi and cold storage are incompatible. Hot wallets keep private keys accessible for on-demand transactions, which is why they're the default for DEX users, but that convenience increases exposure to cyber threats. Cold storage has traditionally meant sitting out DeFi entirely. WalletConnect changes that equation.
How to Use Tangem with Jupiter DEX: Cold Storage Swaps on Solana
The connection relies on WalletConnect, a protocol that lets a hardware wallet authorize transactions on a web-based dApp without the private key ever leaving the device. Tangem supports Solana and more than 40 EVM networks through its WalletConnect integration.
One important note before you start: Jupiter Mobile (the mobile app) does not support Tangem connections. You need to use jup.ag in a browser, where the QR-based WalletConnect option is available.
Step 1: Open the Tangem App and Navigate to WalletConnect
Open the Tangem Mobile Wallet app on your iOS or Android phone. The app is the required interface for your Tangem cold-wallet card; it communicates with the card via NFC. Find the WalletConnect section in the app. Starting with app version 5.36, you can also scan a QR code directly from the main screen.
Keep the Tangem app updated if you want to scan a QR code from the main screen. That option arrived in version 5.36. WalletConnect's security protections began with version 5.27, so an older app may follow a different flow than the one described here.
Step 2: Connect to jup.ag
On your phone's browser (or a desktop browser if you prefer), go to jup.ag. Click "Connect Wallet" and select the WalletConnect / QR option. A QR code appears on screen. Back in the Tangem app, scan that QR code. The app will prompt you to approve the connection, tap your Tangem card to the phone to confirm. The NFC channel between the card and phone uses AES-256 encryption and works at a range of 0-5 cm, so hold the card close.
Treat the QR code as a connection request. Check that it came from jup.ag before scanning it, then review the approval screen in the Tangem app. KYDA runs before the connection and can display a warning for a suspicious dApp.
Once approved, Jupiter recognizes your Solana address and displays your balances. When Jupiter displays your balances, confirm that you've connected the intended Solana address. The page can display account information while your private key remains on the card.
Step 3: Understand What Happens When You Trade
Cold-storage signing separates transaction preparation from approval. That split gives you a useful review point. Read the transaction details on the phone, then decide whether the request matches the swap you intend to make.
In Tangem's signing flow, the app prepares an unsigned transaction; you tap the card to the phone; the secure element inside the card signs the transaction internally; and the app broadcasts the signed result. The private key never touches an internet-connected device at any point. This is the technical architecture. With a Tangem Cold Wallet, WalletConnect transactions require confirmation with the hardware card.
Connection approval and transaction approval are separate moments. Approving the QR session lets Jupiter request transactions. Signing a transaction requires another tap of the card. A browser connection by itself cannot move assets. Jupiter can request a transaction after the browser session is connected. Tangem's hardware confirmation stays part of the process for every WalletConnect transaction. Keep your card close to the phone when you are ready to approve.
Step 4: Use Jupiter's Features from Cold Storage
The available sources indicate that Tangem can connect to Jupiter via WalletConnect, but they do not specify which Jupiter-specific features are supported through that connection or the per-action signing behavior. Tangem's WalletConnect integration includes transaction simulation: before you sign, the app shows a human-readable preview and estimated balance changes, and detects hidden operations. This is powered by Blockaid's threat detection. You see what you're about to sign before the card tap commits it.
Before you tap, compare the token amounts and balance changes in that preview with the swap you expected to make. If the assets or amounts surprise you, stop and inspect the request before signing. The security tools help with connection and transaction review. Check the site you opened, the token you selected, and the transaction preview before tapping the card.
Step 5: Know the Security Layer You're Working With
Tangem's WalletConnect security model has three components worth knowing, all active from app version 5.27 onward.
KYDA (Know Your dApps) automatically verifies a dApp before connection, uses Blockaid behavioral analysis, and displays warnings for suspicious dApps. This runs before the connection is approved.
Transaction simulation performs an off-chain dry run before signing. It shows balance changes and flags hidden operations, the kind that a malicious frontend might try to slip into a transaction.
- VTX (Verified Transactions) uses cryptographically signed transaction bundles to verify that the preview you approved matches what actually executes. It prevents man-in-the-middle attacks between simulation and signing.
Together, the signing layer is hardware-backed, and the transaction preview is independently verified.
One Honest Limitation
Tangem is a mobile-only interface. There's no desktop app or web dashboard. If you prefer to manage positions on a large-screen laptop, you'll need to keep your phone nearby for every tap on a card. The NFC range is 0-5 cm, so the card has to physically touch the phone. For most use cases, this setup works well. It still requires your phone and card for every approval.
FAQ
-
No. According to Jupiter's own documentation, Tangem cannot be connected inside the Jupiter Mobile app. The connection works on jup.ag in a browser, where the QR-based WalletConnect option is available. Use jup.ag, not the mobile app.
-
The available sources do not document how Jupiter limit orders or DCA schedules behave after a Tangem WalletConnect session disconnects. WalletConnect sessions stay active until the user disconnects or the session expires; after expiry, start a new WalletConnect connection flow to reconnect.
-
A standard session has a default lifetime of 7 days. After expiry, the connection closes, and you need to reconnect. To do that: refresh the Jupiter page, click "Connect Wallet," select "WalletConnect" again, and re-scan the QR code in the Tangem app. Individual transaction requests within a session expire after 5 minutes if not approved, but the session itself persists until the 7-day window closes or you manually disconnect.
-
No. The private key is generated inside the Tangem card's secure element (a Samsung S3D350A chip certified at Common Criteria EAL6+) and never leaves it. When you tap the card to sign a Jupiter transaction, the signing happens inside the chip. The Tangem app and Jupiter's frontend only ever see the signed transaction output, not the key itself.
-
A stolen card alone is not enough to access funds. An attacker would also need your phone with the Tangem app installed, the app access code or biometric authentication, and physical NFC proximity (0-5 cm) to the card. All three factors together. That's a meaningful barrier compared to a hot wallet where a single compromised device can drain everything.
-
Your private keys stay on the card, not the phone. If your phone is lost or breaks, install the Tangem app on a new device and tap the card to restore access. Your balances and on-chain positions are unaffected, they exist on the Solana blockchain, not on the phone.
-
Yes, for straightforward token swaps. Tangem's swap feature aggregates rates from multiple providers, Jupiter is listed among them as a Solana DEX aggregator, and presents the best available option. Provider fees are typically 0.5-1.5% and shown before confirmation; network gas fees go to blockchain validators, not Tangem. Approximately 99.99% of Tangem swaps require no KYC, though third-party providers may have their own requirements. The difference is scope. Tangem's built-in swap covers token-to-token exchanges.
-
This is the critical caveat for Tangem's seedless setup. If you lose every card in your set and have no seed phrase backup, the funds are permanently inaccessible. Tangem sells cards in sets of two or three; the backup cards have identical access to the same private key. Keep at least one backup card in a separate, secure location. This applies regardless of what you're doing with Jupiter or any other dApp. Cold storage and DeFi used to be separate categories. WalletConnect lets Solana users connect Tangem to Jupiter on jup.ag while their private key stays hardware-locked. With a Tangem Cold Wallet, every WalletConnect transaction requires confirmation with the physical card.