Unlisted: not indexed, not in the sitemap, not in the nav or the footer. Shared directly in capital conversations.
Kerne Protocol: Diligence Dossier
Version 1.9, issued August 14, 2026. Live figures on this page are read from the public endpoints at render time and refresh continuously; they are not hand-entered. Dated claims carry their as-of date inline.
This page consolidates everything a capital allocator, anchor, or accelerator reviewer needs to diligence Kerne on one URL, and it leads with the numbers most teams would bury: the protocol is at genesis scale, with a single-digit holder count, and while its first external audit is complete and published, all ten of that report’s findings are still live on the deployed vault bytecode. Every claim below links to a surface you can verify without trusting us.
Audit status. Kerne has completed its first external audit. The Hexens final report published on July 31, 2026 and you can read it in full, with our response to every finding here. That is a review of five contracts at one commit, not a guarantee of safety. Minting is open: the patched Peg Stability Module completed its cutover on July 10 and is live. The separate WETH vault runs earlier bytecode than the reviewed commit, which is why deposits into that WETH vault are closed. If you would rather lock the current Opal multiplier now, without moving any funds, register your intended mint in the commit queue.
Live backing, stated as three PSM legs plus legacy collateral
Outstanding kUSD is backed 1:1 by USDC held across the three PSM contracts the proof of reserves enumerates: the original redeem reserve, the retired mint PSM whose reserve is retained until migration, and the live mint PSM. New mints flow through the live mint PSM at a published on-chain fee. The legacy v1 vault and the Hyperliquid hedge equity sit above that stable backing as additional collateral. All rows below are live reads from /api/por at Base block 50500041.
| Surface | Role | Live value |
|---|---|---|
kUSD outstanding 0x5C2EfdF0D8D286959b42308966bc2B97f5680AA3 | The liability every row below backs. This is user-held kUSD, which is what the backing ratio is computed against. It is lower than the ERC-20 totalSupply a block explorer shows, because the PSM contracts keep the kUSD they take in on a redemption instead of burning it, and kUSD sitting inside the protocol's own PSM is not a claim anyone can present | 1,109.707154 kUSD totalSupply 1,144.707154 less 35 held inside the PSMs |
PSM v1 (redeem reserve) 0xFf3025ec18e301855aB0f36Ec6ECa115a29A5Fbc | The original PSM, now a redemption reserve; MINTER revoked 2026-06-16 | $85.89 USDC |
PSM (retired mint) 0x07eBb486e11BD217e6085eb5ab663e4517595993 | Mint path from 2026-06-16 to 2026-07-10, MINTER revoked; its USDC reserve is retained and keeps backing the kUSD minted through it until migration | $995.00 USDC |
PSM (live mint path) 0xaBDE1138aa1Ce88d1dF06422C0c3b05D70569803 | Where new mints enter: USDC in, kUSD out, published tiered fee, hard cap | $30.00 USDC minting live, base fee 0.10% stepping down to 0.05%, new-mint exposure 30 of 10,000,000 USDC cap |
Legacy v1 vault + hedge equity 0x8005bc7A86AD904C20fd62788ABED7546c1cF2AC | Additional collateral above the 1:1 stable backing; excluded from headline TVL while the v1 vault is in its documented degraded state. Read the value as two labeled parts: WETH physically held by the vault contract, verifiable from any Base RPC, and a Hyperliquid bridge and venue balance that is ledger-claimed, attested by the protocol's own telemetry rather than independently readable on Base | $37.20 ($15.40 on-chain WETH + $21.80 ledger-claimed venue equity) |
| Combined PSM reserves | The three PSM legs above, summed; this is the 1:1 stable backing figure. No single contract holds this amount, so do not read it against one address | $1,110.89 USDC (100.11% of outstanding kUSD) |
| Aggregate | Total collateral over outstanding kUSD | $1,148.09 (103.46%) |
Dated snapshot for readers checking a printed copy. As of July 20, 2026 at Base block 48895544 the three legs read: redeem-reserve PSM 0xFf3025ec, 117.85 USDC; retired-mint PSM 0x07eBb486, 998.00 USDC; live-mint PSM 0xaBDE1138, 0.00 USDC. Combined that is 1,115.85 USDC of stable backing against 1,114.74 kUSD outstanding, or 100.10 percent. Those are per-contract figures, not one balance repeated: the combined number is not held at any single address. At that block the PSMs held no kUSD inventory, so outstanding and the ERC-20 totalSupply were the same number; they have since diverged by the redemption inventory noted in the table above, which is why a printed copy of this snapshot will not reconcile against a totalSupply read taken today. The snapshot is dated on purpose and will go stale. The live number is at kerne.fi/api/por under reserves.psmRedeemReserve, reserves.psmRetiredMint and reserves.psmMint, and the table above reads those same fields at render time.
Why three PSM contracts: the v1 contract holds the original USDC reserve and remains a redemption surface; the retired mint PSM carried mints from 2026-06-16 to 2026-07-10 and keeps its reserve until migration; the current mint PSM is the hardened mint path with tiered fees and a cap, redeployed 2026-07-10. All three are verified on chain and appear in the contract registry below. The solvency status string in the raw feed says this plainly: the PSM is solvent and the legacy v1 vault degradation is a known, labeled issue, not a hidden one.
Redemption capacity, stated before you have to derive it
The first question any six figure check asks is: if I mint at size, how do I get out? Here is the honest answer, including the part that reads worse when a counterparty derives it themselves.
- Today, the reserve covers today's holders and nothing more. The PSM contracts hold $1,110.89 of USDC combined against 1,109.71 kUSD outstanding, so every current holder can exit at par at the published fee. Exit capacity at six or seven figures does not exist yet, because nothing at that size has ever been minted.
- The mechanism: a mint at size creates its own exit capacity. The PSM is fully reserved and does not deploy its backing. USDC that enters at mint stays in the contract until it leaves through a redemption; the only other outflow in the deployed mint PSM is a fee skim strictly bounded to fee surplus above 1:1 backing, restricted to the admin Safe and the published treasury address, and emitted on chain when it happens. So a $100k mint adds $100k of USDC to the reserve, and that same USDC is what funds the exit, both directions at the published tiered fee.
- The circularity, named plainly. For the first large minter, the reserve that funds your exit is overwhelmingly the reserve you brought. There is no fractional trick hiding in either direction: you can always get out because the system cannot lend, stake, or spend what backs you, and the hourly signed attestation plus the live backing table above let you watch that stay true. What you cannot do is exit into a reserve someone else built, because at this scale nobody else has built one yet.
- Raised capital follows the same rule, plus a cap. If a raise is parked in the PSM as protocol-owned float, it adds reserve exactly 1:1 with the kUSD it mints and is labeled under the float disclosure below, and the prudence cap in that section commits the majority of any raise to stay out of protocol contracts entirely. That cap was originally written to expire when the external audit report published, which happened on July 31, 2026; it was deliberately kept in force, for the reason given in that section.
Proof of reserves, signed hourly, verifiable in three lines
Every hour the protocol publishes a signed attestation of reserves at kerne.fi/api/por/signed. The signature is EIP-191 personal_sign over the attestation hash by the named strategist key 0x09a2780ac8Be6D5d2d1F85A8D92b09D40C9CA37e. Recovering the signer and rehashing the payload takes about three lines in ethers, eth_account, or foundry cast; the recipes ship inside the response under _meta.verify and in the browser at kerne.fi/verify.
Latest attestation at render time: generated 2026-08-26T22:56:39.000Z, solvent true, delta neutral false, PSM backing ratio 1.001064, Hyperliquid venue equity $21.94.
The attestation stack itself is published as an open standard (signed-por) and the same machinery is sold as a service; the protocol eats its own cooking hourly.
The same strategist key also signs a dated commitment the protocol made to itself. The Opal Genesis Season 1 fragment standings were recorded and committed to the repository on the exact date published in advance, 2026-07-10, machine-signed over the canonical standings by that key (attestation hash 0x908e187f385326b17a6b16d92c9e6a5831d42d5ab4c326c8834a28da6f4b79db). The underlying fragment count is monotonic, so a recorded standing can only be equal to or higher than the value at the exact instant, never lower, and the signed artifact states its own read timing. The promised date was met and the record verifies against the signer, not asserted.
The yield number, stated the way we would want it stated to us
- The published APY is a modeled, deployed-basis figure, currently 5.77%. It models the book we actually run: the hedge is sized one for one against spot, so the carry is multiplied by L/(L+1), which is below one, never by the venue leverage itself. It is computed from public Lido staking and Hyperliquid funding data with the full methodology in the response itself at /api/apy, and it moves with the market. It is still a model, not a realized rate: an output to verify, not a promise. Until July 28, 2026 that response also carried a modeled target at scale, a labelled figure near thirteen percent that multiplied the same carry by three. It has been withdrawn. It was reachable only with a spot leg levered through a borrowing facility the protocol does not operate, it charged no borrow cost against itself, and no holder could ever have been paid it, so publishing it bought us nothing and handed a critic a number to quote. The deployed figure is now the only forward figure Kerne publishes.
- Realized distributions have only just begun. The first genesis-scale skUSD distribution landed on July 8, 2026, and it is small; the staking receipt (skUSD) has appreciated only marginally since. Realized protocol carry history is short, and realized-cost telemetry accumulates daily so the realized story is reported from data, not asserted. Institutional-scale staking is gated behind external review, and the anchor terms encode that gate explicitly. The report half of that gate was met on July 31, 2026; the half still outstanding is the remediated build being deployed and verified, so staking at scale has not opened.
- Our own analysis puts a ceiling on this design, and it caps the target rather than the deployed figure. The published feasibility work concludes that a peg-safe, through-cycle rate for this design at current market funding sits around 8 to 9.4 percent. The top of that band is the same formula run at a leverage assumption the deployed book does not carry; that post carries a dated addendum saying exactly this. So the deployed figure does sit well under the band, but the two are not stated on the same basis and the distance between them should not be read as headroom. We publish that ceiling ourselves rather than waiting for a diligent analyst to derive it. Yield methodology: /docs/yield-methodology.
- Sector context: the whole category prints mid single digits right now on realized terms. The difference at Kerne is not a bigger number, it is that the formula, its inputs, and its known decay are published, so the number can be checked rather than believed.
Scale and holder concentration, led with rather than buried
Kerne is at genesis scale. kUSD outstanding is 1,109.71 kUSD and the holder count is single digits: 5 addresses at the July 2, 2026 read, of which four are the protocol's own surfaces (the founder-seeded liquidity pool, the staking wrapper, a founder wallet, and the operational wallet) and one is an external third-party buyer. The list is public on BaseScan, with one caveat we found the hard way: explorer holder tables can lag the chain, so we count by summing live per-address balance reads, which reconcile to total supply exactly. The majority of circulating supply sits inside the staking wrapper, and every share of that is held by a founder wallet. The founder-seeded Aerodrome position was withdrawn on August 1, 2026, so a holder list read before that date apportions the same kUSD differently. We state this because it is true and checkable, and because the first millions of every synthetic dollar in this category have come from anchor capital rather than organic retail. The protocol is structured for that sequence, and the protocol-owned float disclosure below exists so that when anchor capital arrives, the displayed TVL it creates is labeled for what it is.
What is already real at this scale: the mint-redeem loop is live on Base mainnet, the hedging engine runs a live pilot-scale short sized against its disclosed founder float, reserves are attested hourly with a recoverable signature, and the protocol publishes its own failures with the same cadence as its wins.
Protocol-owned float: the disclosure, in advance
This section is a standing commitment about how Kerne will report its own capital, published before that capital arrives.
- What protocol-owned float is. If Kerne raises operating capital (for example through a SAFE) or receives founder or treasury capital, some of it may be parked in the PSM as USDC, minting kUSD held by the protocol or its founders. That capital is real, fully reserved, and redeemable like any other kUSD; what it is not is third-party demand.
- The commitment. Any kUSD position that is protocol-owned, founder-owned, or raised-capital float will be disclosed as such: identified in the public seed policy, distinguishable from external deposits, and never cited by us as organic traction. TVL that comes from our own balance sheet will always be labeled as coming from our own balance sheet.
- Why we publish this in advance. The synthetic-dollar category has a wash-TVL problem, and Kerne sells verifiability. A protocol that markets signed proof of reserves cannot carry an asterisk on its own headline number. Publishing the labeling rule before the capital exists means no reader ever has to wonder which regime a given dollar arrived under.
- The first exercised case (added 2026-07-21). The hedge engine sizes its pilot-scale Hyperliquid short against a founder-custodied watch-only float (a hardware wallet holding a small amount of ETH and WETH on Base). That float is not protocol custody, backs no kUSD, and enters no solvency ratio; it exists so the delta-neutral loop runs against a real position before external capital arrives. It is disclosed, with live balances and verify commands, at /api/por under reserves.protocolOwnedReserves.components.founderWatchOnlyFloat.
- The prudence cap (added in v1.1, still in force). The condition this cap was written against has now been met: the first external audit report published on July 31, 2026. The cap stays anyway, and this is the dated, disclosed note recording that. The reason is that the audit reviewed commit 0912c870 while the deployed vault runs earlier bytecode, so the thing the cap protects against has not actually changed yet. It is reconsidered when the remediated build is deployed and verified, not before, and lifting it will be its own dated edit here. While it is in force, no more than 25 percent of the proceeds of any raise will be parked in protocol contracts, the PSM float included. The remainder is held as USDC in the disclosed 2-of-3 treasury Safe, where it is visible on chain and counted as treasury, not as TVL. An unaudited system should not hold the bulk of investor proceeds, and our displayed TVL must never be a function of how much of our own raise we chose to park. This is a self-imposed policy; amending it requires a dated, disclosed edit to this page.
- The mechanics already exist. The public seed policy at SEED_TVL_POLICY.md governs seed capital labeling today, the hourly signed PoR shows the reserve composition, and the holder list is public on chain. This disclosure extends the same rule to any future raised capital parked in the PSM.
Security posture and process
- Source verification: 14 of 18 deployed contracts are source-verified on both BaseScan and Sourcify, with the pending rows disclosed with reasons at /security/audits. Where deployed bytecode differs from current source, the divergence and its operating rule are published at /security/deployed-vs-source.
- Internal corpus: over two hundred self-found findings, classified and triaged. The named ones, open items included, are published with live statuses and closing commits at /security/findings-tracker, which carries twenty-two rows today. The two full internal reports behind that corpus are not published: they contain working exploitation detail against contracts that are not yet remediated, so they go to counterparties on request under NDA instead, and the external audit report was published in full on July 31, 2026. Inbound researcher disclosures are triaged and acknowledged; a standing bug bounty runs at /security.
- External audit: completed, and published in full. Hexens ran the first external smart-contract audit; the MSA is executed with the founder signing as a self-employed individual (no entity or novation). Fieldwork ran from July 13, 2026 and the final report published on July 31, 2026: ten findings, none critical, eight fixed and two acknowledged, every one of them in KerneVault. Kerne published the report unedited alongside its response to each finding. One audit of five contracts at one commit is not a track record, and the deployed vault runs earlier bytecode than the reviewed commit, so its findings are open on chain and deposits are closed. The auditor-facing scope is also public at audits/SCOPE.md. The published report clears one gate for institutional-scale staking; the remaining gate is the remediated build being deployed and verified, and that has not happened yet.
- Governance: protocol administration sits with a 2-of-3 Gnosis Safe on Base, 0x52d3E450bA6c299B1B07298F1E87DD74732D4877, with the first signer hardware-backed. Day-to-day automation runs on a separate operational key that holds no admin roles.
Entity and instrument status, as of August 14, 2026
- Entity: Kerne operates pre-incorporation, by decision. On July 2, 2026 the founders paused the BVI formation this page previously described as under way: company names were approved with a corporate services agent, no company was formed, and no filing is in progress. Execution moved to personal signature instead. On August 14, 2026 the question was decided rather than deferred again: Kerne is not incorporating, and the offshore plan this section previously carried as a standing novation target is withdrawn, because a Cayman foundation company cannot issue the equity or SAFE an investor buys. The audit engagement above is executed by the founder as a self-employed individual with no entity and no novation (a plain service contract, countersigned July 7, 2026). The SAFE below is the instrument that carries a contractual commitment to novate to a Kerne entity if one is ever incorporated; no incorporation is scheduled and the instrument does not depend on one.
- Instrument: a post-money SAFE with a token side letter remains drafted for counsel review, and following the July 2 decision it is being adapted from a BVI issuer to personal execution: the founder signs individually as promoter, with a mandatory novation of the instrument to the incorporated entity and the investor's advance consent to that novation in the instrument itself. A committed investor is therefore waiting on counsel finalization and signatures, not on an incorporation. Terms are discussed directly: liam@kerne.fi.
- Regulatory positioning: kUSD is a protocol-issued synthetic dollar, not a fiat-backed payment stablecoin, and kUSD itself pays no yield for holding it; yield exists only through the separate staking receipt. This is the structure the category has converged on under the US GENIUS Act framework and analogous perimeters elsewhere, with sUSDe and sUSDS as the worked public examples. Not legal advice; stated so a reviewer can test the reasoning.
Anchor terms
Documented terms exist for anchor mints of $1M to $5M: tranche-structured, with tranche 1 as mint-and-hold (PSM-only risk surface, fully reserved, no yield promised and none needed), staking tranches gated on external review, a points multiplier floor, a fee-share rider on staked tranches, a named transparency page, and full exit symmetry through the PSM at the published tiered fee (0.10% base, 0.08% from $50,000, 0.07% from $250,000, 0.05% at $1M or more per swap, both directions, set on chain where anyone can read it).
The points rule that the letter incorporates by reference is published separately at /opal/anchor-tier, including what the floor is, when it attaches, what happens to it on a full redemption, and what a fragment does and does not convert into. It is a points rule, not a yield term, and no token generation event is scheduled or guaranteed.
The terms are published in full at /dossier/anchor-terms: what the mint mechanically is, what the module can and cannot do with the reserve while it sits there, what the exit actually reaches today, and the fact that parked reserves earn zero. Every figure there is stamped to a block and carries the command that reproduces it. The binding anchor deposit letter that sits behind those terms is with counsel and is discussed directly: liam@kerne.fi.
How much the contract will actually take, and what happens the moment it does, is at /dossier/capacity: the headroom, the four calls that reproduce it, and a Foundry fork test that mints one million USDC through the deployed bytecode and asserts that one USDC past the published figure reverts. Capacity is not demand, and that page says so before it says anything else.
The kill questions, answered by us first
- Is the TVL real? It is small, fully reserved, and verifiable hourly; the holder list is public; and the float disclosure above commits to labeling any protocol-owned portion forever. Judge the machinery, not the odometer.
- Is the yield real? The published number is a model of the deployed book, not a realized rate, and this page says so; only a first, small genesis-scale distribution has landed (July 8, 2026); our own published ceiling for the sustainable rate is roughly 8 to 9.4 percent, stated on the levered basis so it caps the target at scale rather than the deployed figure; staking at scale waits for the remediated build to be deployed and verified, not for the report, which is published.
- Where is the audit? Done, and public. Engagement papered on a personal-execution basis so it did not wait on entity formation. Hexens published its final report on July 31, 2026 and Kerne published it in full, with a per finding response. Read it before you weight it: it is one review of five contracts at a single commit, two findings were acknowledged rather than fixed, and the deployed vault is not the reviewed build. The rest of the verification story is unchanged: verified source, the internal corpus, and the signed PoR.
- If I mint six figures, how do I get out? Through the same PSM your mint fills: the redemption capacity section above states this plainly, including the fact that today's reserve is only $1,110.89 across the three PSM contracts combined, and that the first large minter exits into the reserve they brought.
- What about the alarming legacy vault numbers? The v1 vault is in a documented degraded state, holds no user funds, is excluded from headline TVL, and its raw figures are published under a labeled known-issue block in the signed feed rather than hidden.
- Venue concentration? The funding leg currently runs on a single venue (Hyperliquid). Multi-venue routing exists in the engine and arms as venues are added; until then this is a real, disclosed concentration.
- Who are you? Three co-founders. The founder is named on kerne.fi/team; the other two are unnamed publicly at this stage, with identity disclosure happening directly in counterparty conversations (anchor, auditor, accelerator). The system is deliberately structured so nothing on this page requires trusting an identity. What is checkable without an identity is whether the other two keys are real: every signature they have made is recovered from chain at the Safe queue page, which also states what a recovered signature does not prove.
Verify this dossier in about 15 minutes
Pull the signed PoR and recover the signer, re-read the three-PSM table straight from /api/por, spot check one contract against its verified source, then read the deployed-versus-source table and the findings tracker. That covers reserves, code, honesty, and process without trusting anything on this page.
Version history: v1.9 issued August 14, 2026; v1.8 issued July 28, 2026; v1.7 issued July 24, 2026; v1.6 issued July 20, 2026; v1.4 issued July 10, 2026; v1.3 issued July 10, 2026; v1.2 issued July 7, 2026; v1.1 issued July 2, 2026 (evening); v1.0 issued July 2, 2026 (midday). Change in v1.9, self-found: the entity section carried the offshore plan as a standing novation target that was "unchanged". The entity question was decided on August 14, 2026 and the decision is not to incorporate, and the specific plan that section named does not survive a raise in any case, because a Cayman foundation company's memorandum must by law prohibit distributions to members and it therefore cannot issue the equity or SAFE an investor buys. The section now states the decision, the SAFE's novation is stated as conditional on an incorporation that is not scheduled, and the section heading is re-dated because its bullets were re-checked rather than restamped. Changes in v1.8, both self-found: (1) the live backing table and the redemption paragraph read the kUSD ERC-20 totalSupply where the API publishes outstanding, which is totalSupply less the kUSD the PSM contracts custody from redemptions. The prose therefore stated a larger liability than the backing ratio printed directly above it was computed against, so a reader dividing the two numbers we gave them got a shortfall that does not exist. Both now read outstanding, and the table states the reconciliation to totalSupply inline so the figure can be checked against a block explorer. (2) The modeled target at scale was withdrawn from the public API rather than kept as a labelled figure. It was reachable only with a levered spot leg the protocol does not operate, it was never a rate anyone could earn, and a forward number that large sitting beside a delivered number that small is worth nothing to a reader and a great deal to a critic. Change in v1.7: the honest-yield section was rewritten after we corrected the basis of our own APY. Until July 24, 2026 the published figure multiplied the staking-plus-funding carry by a leverage of three; the deployed hedge is sized one for one against spot, so the correct multiplier is L/(L+1), which is below one, and the old figure overstated the deployed book by roughly four and a half times. The endpoint moved to the deployed figure as the headline. We found it in our own audit and record it here rather than editing the page quietly. Change in v1.4: the signed proof-of-reserves section now records that the Opal Genesis Season 1 fragment snapshot was taken and committed on its promised date, July 10, 2026, machine-signed by the same strategist key that signs the hourly PoR. Change in v1.3: the honest-yield section was updated to record the first genesis-scale skUSD yield distribution (July 8, 2026); the prior wording predated that event and stated that no yield had been distributed. Change in v1.2: the external-audit status was corrected to engaged (the Hexens MSA was countersigned July 7, 2026, fieldwork began July 13), and the entity section now states the audit engagement is a plain self-employed service contract with no novation, with novation reserved for the SAFE instrument only. Changes in v1.1, recorded here because silently editing an honesty page would defeat its purpose: (1) the holder count in the scale section was corrected from 4 to 5; the v1.0 figure came from an explorer holder table that lags the chain (it was already missing a holder at publication), and the corrected count sums live per-address balance reads that reconcile to total supply exactly. (2) The legacy vault row now labels its on-chain WETH and its ledger-claimed venue equity separately. (3) A redemption capacity section and a float prudence cap were added. (4) The entity and instrument section was rewritten after the founders paused BVI formation on July 2 in favor of personal execution with mandatory novation. A frozen PDF snapshot of this page, with every figure linked back to its live endpoint, is issued alongside each version; the live page supersedes any PDF. If a number on a PDF disagrees with the live endpoints, the endpoints are the truth.