Security & Audits
Security Policy
We treat security in layers, from the contracts to the hedge engine.
Non Custodial Design
The Kerne Protocol is non custodial at the smart contract level. On chain collateral is held by the protocol's source verified smart contracts on Base. A portion of vault assets is deployed to hedging venues such as Hyperliquid to maintain the delta neutral strategy. These off chain positions are tracked transparently via the vault's offChainAssets variable and reported through the Proof of Reserves system. You retain the cryptographic right to initiate withdrawals at any time via the requestWithdrawal function.
Smart Contract Security
Hexens audited five contracts. The live mint PSM runs byte for byte the source they reviewed and drew zero findings. All ten findings sit in KerneVault, which is closed to deposits: eight fixed in source, two acknowledged. The deployed vault predates those fixes. The final report was published 31 July 2026 and reissued 20 August 2026. The report is published at Security audits.
Our test suite includes hundreds of unit tests covering normal operations, edge cases, and adversarial scenarios. We use Foundry for testing, which allows us to simulate complex multi step interactions and verify the contracts across normal, edge and adversarial cases.
Multilayered Oracle System
The live mint path reads Chainlink's USDC/USD feed on every mint and redeem: the PSM carries its own Chainlink staleness check and depeg gate on its USDC oracle, and its current staleness window is published live as psm_chainlink_staleness_max at /api/risk-status. Separately, the KerneOracleRouter dual feed pricing system is deployed on Base at 0x5fAeaB501A33468775DDF929C714890eE7e984bc and administered by the 2 of 3 Safe. It is not yet cut over: the live mint path does not route through it, its only configured asset is WETH, and USDC has no feed on it. As deployed, Pyth Network is the primary price feed, providing subsecond latency and confidence intervals, and Chainlink AggregatorV3 is the validation and fallback layer. If the two sources disagree beyond the configured tolerance, minting through the router pauses until prices settle.
Automated Circuit Breakers
The protocol includes multiple layers of automated protection:
- Negative funding: the hourly and daily loss breakers cap losses; a staged hedge reduction for sustained negative funding is specified and not yet wired.
- Exchange concentration: the allocator caps any single venue at 60% of its weights once more than one venue is live. Today the hedge runs on one venue, Hyperliquid, at pilot scale.
- Rapid outflow protection: If net withdrawals exceed a defined threshold of total value locked within a set period, new deposits are temporarily paused while positions are proportionally reduced.
- Oracle anomaly circuit breaker: the live PSM reverts on a stale Chainlink price or a USDC depeg beyond 200 bps, and the deployed router reverts priced operations when its feeds diverge beyond 5%.
- Collateralization ratio monitoring: the design has warning and critical thresholds. On the deployed vault these flags have no getters; /api/risk-status reports their state as unknown.
Multi Venue Diversification
The hedging engine is designed to spread positions across multiple venues, with hard caps limiting maximum exposure to any single venue. Today the hedge uses a single venue (Hyperliquid) and runs at pilot scale, sized against a small disclosed founder custodied float (see kerne.fi/api/por); multi venue routing arms as venues are added. Onchain collateral held in KerneVault is not affected by any single venue failure. It remains in the smart contracts under the protocol's control.
Emergency Unwind Procedure
In a catastrophic scenario requiring full protocol shutdown, a formalized emergency unwind procedure protects depositors: the vault pauses, hedge positions are closed in an orderly manner, and once fully unwound, the vault reopens for withdrawals only.
A shortfall in an unwind is borne by depositors in proportion to what they hold, because the Insurance Fund holds a zero balance today. Anyone can read that balance from chain, and the protocol publishes it hourly as insurance_fund_usd in its signed attestation. Where a loss lands is set out under Loss Allocation in Risk Disclosures, and the fund in full at The Insurance Fund.
External Audits
Hexens completed Kerne's first external audit, with the final report published on 31 July 2026 and zero findings on the mint PSM. The report is published at Security audits, and we disclose findings and how they were addressed.