Kerne Logo

Data Room

Last updated: August 14, 2026. Live numbers update themselves.

Changed since the July 24 stamp: the external audit section records the Hexens final report published July 31, 2026; the governance section records the August 6, 2026 handover of kUSD and the three PSM modules to a 48 hour timelock; the audit pipeline now links the checks on Kerne that Kerne did not pay for; and Kerne seeded an isolated Euler v2 Edge lending market on August 14, 2026 with its own capital, which is a market existing rather than anyone else using it.

Every diligence question about Kerne, answered on one URL, with each answer linked to a surface you can verify without trusting us. Kerne is small and one audit old. This page leads with those facts rather than burying them, because every number here is already public on chain; the only thing a data room changes is who narrates.

Live protocol state

Read in your browser from the same public endpoints anyone can call. Nothing on this page is hand-entered, so it cannot silently drift from reality.

kUSD outstanding

1,109.707

On-chain supply net of PSM inventory

/api/stats

TVL

$1,110.89

PSM USDC reserves backing outstanding kUSD

/api/stats

skUSD APY, modeled

6.03%0.00%realized

Deployed basis, variable, not yield paid. Realized is annualized skUSD share-price growth over 30 days, which is what has been paid.

/api/apy

PSM backing ratio

100.11%

From the hourly signed PoR (verified)

/api/por/signed

Composition: wallets outside Kerne hold under 1 percent of outstanding kUSD. The rest is founder-owned, most of it staked. Read TVL as the reserve backing the unit, not as third-party demand.

The published APY is a modeled, deployed-basis figure whenever no incentive is being DISTRIBUTED, and a total of that carry plus a disclosed, escrow-funded subsidy whenever one is; the live response labels which, in its basis field, and decomposes the total. Distributed, not merely funded, is the load-bearing word: an incentive was escrowed on 30 July 2026 and counted in the headline until 1 August 2026, when we established it had never reached a holder and withdrew it from the rate. It is live and variable, computed from public Lido and Hyperliquid data with the methodology open at /docs/yield-methodology. It models the book we actually run: the hedge is sized one for one against spot, so the carry is multiplied by L/(L+1), which is below one, never by the venue leverage itself. A separate 3x target at scale was published beside it, labelled, until 28 July 2026, at /api/apy; it was withdrawn because it assumed a levered spot leg the protocol does not run and charged no borrow cost against it, so it was never a rate anyone could earn. The formula's 180-day funding window has also been decaying mechanically since June as strong late-2025 funding months roll out, exactly as this page disclosed in advance, and the published figure moves down with it. Two more honest sentences we volunteer: realized distributions have only just begun (the first genesis-scale skUSD distribution landed on July 8, 2026, and it is small; staking at scale is gated behind the external audit), and our own published feasibility analysis caps the sustainable through-cycle rate for this design near 8 to 9.4 percent at current market funding. That band is stated on the levered design basis, the same basis as the withdrawn 3x target, so it caps that target rather than the deployed headline; the deployed figure sits well under it, and the two are not a like for like comparison. The modeled number is an output to verify, not a promise. As a live reference point, sUSDe, the market's largest delta-neutral dollar, currently realizes 4.96 percent on $1.33 billion staked (staked total per DefiLlama), per DefiLlama's published data.

Independently listed on DefiLlama, which tracks the live TVL from the same on-chain contracts.

What kUSD is

kUSD is a USDC-collateralized synthetic dollar on Base, minted 1:1 through an on-chain Peg Stability Module at a published, tiered fee. Staked kUSD (skUSD) is an ERC-4626 wrapper designed to earn a delta-neutral yield: Ethereum staking rewards plus Hyperliquid perpetual funding, designed for net-zero directional exposure at scale. Both tokens live in the holder's own wallet.

Full mechanism: whitepaper v3.0, chapter-level detail in the documentation, machine-readable summary at /llms.txt. Kerne Protocol on Base is unrelated to Kernel Protocol or KernelDAO; disambiguation here.

Scale, stated plainly

Kerne is at genesis scale. The first PSM mint happened on 2026-05-14; supply and TVL are in the hundreds of dollars, and the holder count is whatever BaseScan says it is today. We lead with those numbers rather than hide them. The first millions of every synthetic dollar in this category have come from anchor capital, not organic retail; the protocol is structured for that sequence, and this page exists so that capital can diligence quickly.

What is already real at this scale: the full mint-stake-redeem loop is live on mainnet, the hedging engine runs a live pilot-scale short sized against its disclosed founder float, reserves are attested hourly with a recoverable signature, and the protocol publishes its failures (see the findings corpus below) with the same cadence as its wins.

Contract registry and verification

14 of 18 deployed contracts are source-verified on both BaseScan and Sourcify. The two pending rows are disclosed with reasons and resolution paths. The verified source bundles are mirrored per address in the public contract registry, with a step-by-step independent verification guide in HOW_TO_VERIFY_KERNE.md.

ContractBaseScanSourcify

KerneVault v2 (live)

0x8ccc56B5624e2FDB592F6609d81F4c3798e3292B
VerifiedVerified

KUSDPSM (live)

0xaBDE1138aa1Ce88d1dF06422C0c3b05D70569803
PendingVerified

KUSDPSM v3 (retired 2026-07-10)

0x07eBb486e11BD217e6085eb5ab663e4517595993
VerifiedVerified

kUSD v2

0x5C2EfdF0D8D286959b42308966bc2B97f5680AA3
VerifiedVerified

skUSD

0x96F5102C15b839757f811A98CEc3725Ac21DfA14
VerifiedVerified

KerneVault (v1, superseded)

0x8005bc7A86AD904C20fd62788ABED7546c1cF2AC
VerifiedVerified

KUSDPSM (v1, redeem-legacy)

0xFf3025ec18e301855aB0f36Ec6ECa115a29A5Fbc
VerifiedVerified

KERNE (v2)

0x230f3a63E8413D42bEe9103b98a204030206186c
VerifiedVerified

KerneToken (v1, retired)

0xfEA3D217F5f2304C8551dc9F5B5169F2c2d87340
VerifiedVerified

KerneYieldOracle

0x8DE2d5ac5aBc7331a6E1d450a5c021db18599CdB
VerifiedVerified

KerneYieldDistributor

0x096e38a04B632D28E017f86836225E0956CaD878
VerifiedVerified

esKERNE

0x29c1d396A35aB75a8Bb8dC3949f98edFa5f25b34
VerifiedVerified

KerneReferral

0x1A04AF62baFc84b08b19d2aF7285eD5f8dAe4D9f
VerifiedVerified

KerneStaking

0x032Af1631671126A689614c0c957De774b45D582
PendingPending

KerneInsuranceFund

0xE8799FCF327C6D2f78103a3c9308C93592A30403
VerifiedVerified

KerneFlashArbBot

0x57e73919Efc8a70B40a0bFc562C4DC9e58c4D76F
PendingPending

KerneTreasury v3 (live fee sink)

0x5343C41d4FF2B61DAacA9cbC050550C40605B075
PendingPending

KerneTreasury v2 (superseded)

0x7c07517ABcc4BD674CC74B76D2Ab0d95A41560d5
VerifiedVerified

Per-row notes, the retired-contract history, and the verification timeline live on /security/audits. Where deployed bytecode differs from current source, the divergence is disclosed with an operating rule at /security/deployed-vs-source.

Proof of reserves, signed hourly

Every hour the protocol publishes a signed attestation of reserves at /api/por/signed. The signature is EIP-191 personal_sign over the attestation hash; the canonical signer is the strategist EOA 0x09a2780ac8Be6D5d2d1F85A8D92b09D40C9CA37e. Recovering the signer takes three lines of code in JavaScript, Python, or foundry cast; the recipes are embedded in the response itself under _meta.verify and rendered on /transparency.

Since schema v4 the headline aggregate_solvency_ratio is the PSM stablecoin backing ratio (USDC reserve versus user-held kUSD). The legacy v1 vault's alarming share-basis figures remain published, demoted to a labeled known_issue_vault_v1 block, because hiding them would be worse than explaining them.

Delta neutrality, signed

Signed
Outside the 5% tolerance

The hedge's deviation from a perfect hedge, as a fraction of the declared hedge base (the ETH-exposed vault leg plus the disclosed watch-only float the engine shorts against), read from the signed hourly attestation (the same value the delta_neutral flag is computed from, tolerance 5 percent). The engine rebalances on drift above 0.005 ETH; the attestation flags non-neutral beyond 5 percent of that base.

100.00%of the hedge base unhedged right now (hedge base 0 ETH, short 0.0079 ETH on Hyperliquid)

Reading this hour: the hedge base is zero, so the residual 0.0079 ETH short registers as fully unhedged by construction. kUSD backing itself is USDC held in the PSM with no ETH exposure; the deviation shown concerns the hedge book, not the stablecoin backing. The attestation flags this state as WARNING_DELTA rather than smoothing it away.

0%5% tolerance10%

Verify all of it yourself: /api/por/signed (current, EIP-191 signed), /api/por/delta-history (series + methodology), raw hourly archive at the attestation host.

Realized funding ledger

What the hedge account has actually earned and paid, month by month, read from Hyperliquid's public ledger: funding received (negative-funding periods subtract), trading fees, closed price PnL on the hedge leg, net. These are genesis-scale dollars, published deliberately; the replay recipe is embedded in app.kerne.fi/api/funding-attribution.

Loading the venue ledger...

Audit pipeline

One external audit is complete and published in full; the deployed vault is not the build it reviewed. We say both plainly rather than decorate either. The current state of the pipeline:

  • Internal, done and published: two adversarial campaigns in May 2026 (a 10-auditor red team across all 80 contracts, then an 8-agent multi-surface pass over contracts, bot, frontend, and infrastructure), 201 findings catalogued with severities and a triage order, full history at /security/audits.
  • External, complete and published (Hexens): Kerne completed its first external smart-contract audit. The MSA is executed, signed by the founder as a self-employed individual with no entity or novation; fieldwork ran from July 13, 2026 and the final report published on July 31, 2026. Ten findings, none critical, eight fixed and two acknowledged, all in KerneVault, published in full with a per finding response. The deployed vault runs earlier bytecode than the reviewed commit. The auditor-facing scope is public: audits/SCOPE.md. The report pins its scope to five contracts at commit 0912c870: kUSD, skUSD, KUSDPSM, KerneVault and esKERNE.
  • Reviewed commit versus deployed bytecode: these are separate facts and we publish both. The live peg stability module and the live skUSD run commit 0912c870 byte for byte, independently checkable on Sourcify. The live KerneVault does not: it was deployed on June 16, 2026 from earlier source, so the initial report's vault findings are open on that bytecode. That vault holds no user funds and has never issued a share, and no deposit opens into it until the remediated build is deployed and verified. The contract-by-contract map is at /security/deployed-vs-source.
  • Independent of Kerne, and mostly unpaid: everything about Kerne checked by somebody who is not Kerne, with what each party verified first-hand, what they left open, and which of them Kerne paid, is at /security/independent. 6 artifacts, 5 of them unpaid, 14 items left open and 4 corrections to Kerne's own published claims that an outside reviewer caught first. The Hexens engagement above is the paid one, and that page says so in its own header.
  • Sequencing: institutional-scale staking is gated on the published external report; the anchor terms encode that gate explicitly. The bug bounty at /security is the standing external channel in the interim.

The findings corpus: self-found, and what of it is public

Kerne has found, classified, and triaged over two hundred findings against its own code, including Critical ones, before any external auditor was engaged. Read one way, that is a long list of mistakes. Read the way auditors read it, it is the difference between a team that knows its own system and a team that is about to be surprised. Until July 28, 2026 this paragraph said those findings were published. They are not, and we are correcting that rather than deleting it: what is published is the named-findings tracker, which currently carries twenty-two rows, nine of them open. The two full internal reports are held in the internal security repository and are not public, because they contain working exploitation detail against contracts that are not yet remediated, along with infrastructure specifics. They go to counterparties on request under NDA, and the external Hexens report publishes in full when it lands. Every named finding in the tracker carries a live status (open, mitigated, partial, closed) with the closing commit cited at /security/findings-tracker.

The honest residue: three places where deployed bytecode still lags current source, each with a mitigation and an operating rule, disclosed at /security/deployed-vs-source. That page exists so a reviewer finds context from us, not surprises on their own.

Governance and signer policy

Protocol administration sits with a 2-of-3 Gnosis Safe on Base: 0x52d3E450bA6c299B1B07298F1E87DD74732D4877. Until 2026-08-06 the Safe held DEFAULT_ADMIN_ROLE across the deployed AccessControl contracts. It no longer holds it on kUSD or on any of the three PSM modules: those moved to a 48 hour TimelockController at 0x36A14976980B7Dd33136f6613545EB0A2C0a0D72 in the handover batch that executed at 17:00:07Z that day. The Safe still holds it directly on the staking vault skUSD and on both KerneVault contracts, and it still owns the treasury (verified in the April 2026 on-chain admin audit; timeline on /security/audits). On those contracts the first signer is hardware-backed and no single key can move protocol funds or grant roles. The one current exception is the skUSD vault, redeployed on 2026-07-03 to reset a distorted share price: on 2026-07-08 the Safe was granted DEFAULT_ADMIN and the bot strategist EOA was granted STRATEGIST, and on 2026-08-02, three days after the Hexens final report published, the deployer Trezor renounced both roles irreversibly, leaving the Safe as sole admin. Both transaction hashes and a replay of every role event since the creation block are at /security/skusd-admin-status. Day-to-day automation (hedging, attestation signing) runs on a separate operational EOA that holds no admin roles.

Token-level disclosures: KERNE token history and skUSD admin role status.

Team

Kerne is built by three co-founders. The founder is named on who runs Kerne; the other two remain unnamed publicly at this stage. The protocol is deliberately structured so that nothing on this page requires trusting an identity: core admin roles sit with the 2-of-3 Safe, reserves are signed hourly by a key you can check, and the deployed source is verified. Identity disclosure to specific counterparties (an anchor, an audit firm) happens directly in those conversations. Two of those three signers have never sent a transaction of their own, which is what off-chain Safe signing looks like rather than an idle key: every signature they have made is recovered from chain at the Safe queue page, with the limits of that evidence stated alongside it.

Most of the code is written with AI under the founders' direction, and the commit trailers record it. We put that here rather than leave it to be found, because it explains why this dataroom is built the way it is. Code written this way earns more outside scrutiny, so the contracts went to Hexens for a paid external audit, a public bug bounty runs at kerne.fi/security, reserves are signed hourly against a key you can recover yourself, and every contract carries a verification status you can check on BaseScan and Sourcify without asking us. The two contracts whose deployed bytecode cannot be reproduced from any source we hold are named on the live risk surface.

Direct channels: liam@kerne.fi, @KerneProtocol, Discord.

Runway

Protocol operations (the hedging engine, the hourly attestation signer, on-chain automation) are funded with an operational gas runway measured in months at the current transaction cadence. The treasury and insurance fund both hold zero at genesis scale, verifiable on chain at the addresses in the registry above and published hourly as treasury_usd and insurance_fund_usd in the signed proof of reserves; the insurance fund is designed to capitalize from protocol revenue as it accrues, and we do not decorate either number.

Anchor terms

Documented terms exist for anchor mints of $1M to $5M: tranche-structured (mint and hold first, then stake, a sequence whose external-audit gate was met when Hexens published its final report on July 31, 2026), a points multiplier floor, a fee-share rider on staked tranches, a named transparency page, and full exit symmetry through the PSM.

The terms are published in full at /dossier/anchor-terms, including the parts that argue against us: parked reserves earn zero, the deepest single-transaction exit was $998.00 measured on August 1, 2026 and is a few dollars lower now, after a redemption executed against that module on 2026-08-03, and the 48 hour timelock that now covers kUSD and the three PSM modules does not cover the staking vault, which holds most of the kUSD in existence. Every figure is stamped to a block with the command that reproduces it. The binding letter behind those terms is with counsel and is discussed directly: liam@kerne.fi.

Regulatory positioning

kUSD is a protocol-issued synthetic dollar, not a fiat-backed payment stablecoin. kUSD itself pays no yield for holding it; yield exists only through the separate skUSD staking receipt. This is the structure the category has converged on under the US GENIUS Act framework and analogous legislation elsewhere, whose perimeters target fiat-backed payment stablecoins: protocol synthetic dollars with a separate staking receipt sit outside that perimeter, with sUSDe and sUSDS as the worked public examples. None of this is legal advice; it is stated so a reviewer knows how the protocol is positioned and can test the reasoning.

Known weaknesses, stated by us first

  • Scale. TVL and holder count are tiny. Everything above is real but small; judge the machinery, not the odometer.
  • One external audit, and the live vault is not the audited build. Hexens fieldwork ran from July 13, 2026 and the final report published on July 31, 2026, in full. Two of its ten findings were acknowledged rather than fixed, and the deployed vault predates the reviewed commit, so alongside the report the verification story still rests on the internal corpus, the verified source, and the signed PoR.
  • Hedge venue concentration. The funding leg currently runs on a single venue (Hyperliquid). Multi-venue routing exists in the engine and arms as additional venues are added.
  • Legacy v1 vault. The original WETH vault is in a documented degraded state, holds no user funds, and is excluded from backing math. Its raw share figures look alarming in isolation; the signed PoR labels them as a known issue rather than hiding them.
  • Deployed-versus-source divergences. Three, each with an operating rule, at /security/deployed-vs-source.
  • Short realized history. The published APY is a live formula output, not a realized track record; realized-cost telemetry accumulates daily and the realized story will be reported from data as the history lengthens.

Start verifying

The fastest path through diligence: pull the signed PoR and recover the signer, spot check one contract against its verified source, read the deployed-versus-source table, then read the findings tracker. That covers reserves, code, honesty, and process in about fifteen minutes.

When you have finished, minting is open through the Peg Stability Module. If your own process says wait for the final Hexens report first, register the size you intend in the commitment queue and your Opal multiplier is held from that moment rather than from the moment you mint. No funds move, nothing is signed on chain, and it is non-binding until you mint.

If you are reading this for a company rather than for yourself, the first step is usually not a mint either. The treasury health check is a $5,000 fixed-scope read of what your own treasury is holding, where the risk sits, and what the idle balance is costing you, delivered as a one-page memo within 5 business days of scope confirmation. It stands alone and carries no obligation to deploy a dollar into kUSD or anything else, which is the point: the diligence above is ours to prove, and that memo is yours to keep either way.