
Kerne publishes a modeled APY. Next to it, across our own surfaces, we have been publishing a sentence that caps our own number: our feasibility analysis puts the sustainable through-cycle rate for this design near 8 to 9.4 percent. It appears on the home page, on the stake page, in the dataroom, in the diligence dossier, on the transparency dashboard, on a token comparison page, and inside the JSON that /api/apy serves to machines.
On six of those surfaces the sentence called it our published feasibility analysis. It was not published. The work was real, the band was real, and the conclusion had been adversarially reviewed, but the document itself sat in an internal repository with no public URL. A protocol that sells a Disclosure Integrity Audit for exactly this failure mode, a public claim that does not resolve to the thing it claims, should not be the one making it. So here is the analysis. Nothing below is new work; it is the June 2026 review written out, re-run against today's live inputs, and left where anyone can check it.
First, what the headline number actually is
The APY on our surfaces is a formula, not a record. It has been published in full at /api/apy since the endpoint existed, and the response carries its own methodology string. As of the read behind this post it says:
| Term | Live input | Where it comes from |
|---|---|---|
| Leverage multiplier | 3.0x | Target leverage for the strategy design, not the size currently deployed |
| Staking baseline | 2.20% | Lido 7 day simple moving average |
| Perpetual funding | 3.99% | Hyperliquid ETH funding, 180 day trailing mean |
| Strategy costs | 22.32% | Haircut on gross carry: execution, slippage, venue and gas |
| Insurance allocation | 10% | Skimmed off the top before anything reaches a staker |
| Protocol fee | 0% | Genesis phase, below $100k TVL |
Multiply it out: 3.0 times the sum of 2.20 and 3.99 percent, times 0.7768, times 0.90, is 12.98 percent. That is the number on the marketing page. It is arithmetic on six inputs. Two of them, the staking baseline and the funding rate, are read live from public sources; three more are fixed protocol parameters; and the sixth, the leverage multiplier, is the one this whole post is about. You can redo the whole line from the endpoint.
Where the 9.4 comes from
The top of the band is the same formula with an honest leverage assumption substituted in. In June 2026 we ran an adversarial review of the question "can this design honestly print a high number", with each yield lever quantified and then independently attacked. The reviewable conclusion was that 2.0x is the highest leverage this strategy can carry and still be describable as prudent for a peg-bearing dollar without a pre-funded insurance buffer sitting behind it.
Put 2.0x into the formula with the inputs that prevailed at the time, a 180 day mean funding of 4.39 percent and a staking baseline near 2.33 percent: 2.0 times 6.72 percent, times 0.7768, times 0.90, is 9.40 percent. That is the entire derivation of the upper bound. It is not a forecast and it is not a target. It is the ceiling the arithmetic permits under an assumption we can defend in a room with an auditor in it.
Re-run the same 2.0x ceiling against today's live inputs, funding at 3.99 percent and staking at 2.20 percent, and it gives 8.66 percent. The band still contains the honest ceiling a month of funding drift later, which is the modest test a through-cycle number has to keep passing.
Where the 8 comes from
The lower bound was produced by a different exercise and it is the more useful of the two. Rather than asking what the current strategy can print, it asked what a peg-safe basis dollar can sustainably earn across a full funding cycle using every lever available to it, with each lever priced separately and then risk-gated. The answer came out near 8 percent, and it came out there because every individual lever is capped by something structural.
| Lever | Through-cycle contribution | What caps it |
|---|---|---|
| Diversified multi-asset basis | around 7.5% | The alt-asset funding premium over ETH is thin, and some legs run negative. Diversification smooths the mean, it does not remove the common-mode venue tail. |
| Reserve yield on idle stables | around 3.25% | On-chain stablecoin lending on Base currently clears below short-term Treasuries. It is a stabilizer, not a lift. |
| Tokenized bills and fixed-rate paper | around 5% | Real and dependable, and it dilutes whatever basis leg it replaces. A floor, by construction. |
| Insured leverage at 1.25x | around 8.5% | Only available once an insurance buffer is pre-funded. Past roughly 2.5x this is the failure class that ended Stream and Elixir. |
| Capped curated lending | around 5.5% | Correlated tail. The curated-vault losses of the last year arrived together, not one at a time. |
A sane blend of those, weighted toward insured basis at 1.0x to 1.25x with a bill floor underneath it and small buffered allocations to reserve and curated lending, lands near 8 percent. That is the number, and the reason it is a floor for the band rather than a headline is that it is what the design can hold across a cycle rather than what it can print in a good month.
The leverage assumption is the whole gap
Take the two derivations together and the arithmetic says something plain. Evaluate the published formula at today's inputs both ways and the only thing separating the 12.98 percent headline from the 8.66 percent honest ceiling is the leverage term, 3.0x against 2.0x; the same market inputs, the same cost haircuts, one substitution. The 9.40 percent is that identical 2.0x ceiling read against the slightly stronger funding of a month ago, which is why it sits a little higher. Every point of distance between the headline and the honest ceiling is leverage the deployed strategy does not currently run.
And the deployed strategy currently runs neither. At genesis size the hedge is sized one for one: the short notional the engine targets is the vault's own exposed assets, which is what delta neutrality means and is the correct thing to run at this size. Leverage on the venue reduces the margin that has to be posted; it does not multiply the carry earned on the underlying. So the realized carry today is unlevered, and the modeled number assumes a multiplier the current deployment does not apply. We already say a version of this on the dossier. It belongs in the same document as the band.
You can see the consequence without taking our word for it. The realized figure on our own Honesty Index, read from skUSD share-price growth on chain, is about 0.21 percent annualized, and its entire provenance is one 0.10 kUSD strategist test transfer that the deployment registry records as a plumbing check rather than strategy carry. It decays toward zero until real distributions land. Our modeled number is a model. Our realized number is a record. The index publishes them side by side, with us in first place and worst, on purpose.
What the rest of the field actually realizes
A ceiling is easier to believe when it is checked against what comparable dollars are paying. These are not advertised rates. Each one is recomputed by us from the vault's own ERC-4626 share price over a trailing 30 day window, on the read behind this post:
| Token | Realized, annualized, 30 days |
|---|---|
| Falcon sUSDf | about 5.46% |
| Cap stcUSD | about 5.25% |
| Neutrl sNUSD | about 4.24% |
| Ethena sUSDe | about 3.84% |
| Sky sUSDS | about 3.60% |
| Resolv wstUSR | about 0% |
| Elixir sdeUSD | about 0% |
| Kerne skUSD | about 0.21% (17 day window, one test distribution) |
The largest delta-neutral dollar in the market realizes under 4 percent on more than a billion and a half dollars staked. The best comparable performer in this set is under 5.5 percent. Against that field, a through-cycle ceiling of 8 to 9.4 percent is not a modest claim; it is an ambitious one that requires leverage and a funded insurance buffer to reach. Anyone quoting our 12.98 percent as an expected return should read this table first, and so should we.
What would have to be true to earn the top of the band
The gap between an unlevered genesis deployment and a defensible 2.0x is not a code change. It is a sequence, and each step is checkable from outside:
Capital. A basis strategy at four figures of TVL cannot express any of this. Fixed costs dominate and fills are noise. This one is binding and it is first.
A pre-funded insurance buffer. Leverage without a loss-absorbing layer in front of the peg is the structure that killed the dollars in the row above with zeroes next to them. The buffer has to exist and be sized before the multiplier moves, not after.
A de-levering governor. When funding turns negative the position has to shrink toward 1.0x automatically, and it must never step out of the hedge into naked exposure to chase a positive-funding hour. Stepping out is where a delta-neutral dollar stops being delta neutral.
Then actually running the levered carry, with the model reading the deployed leverage rather than a target, so the published number rises because the strategy changed and not because a constant did.
Until those are done, the honest description of the top of the band is that it is reachable, not reached. We would rather write that down than have someone else derive it.
Where 14 percent actually lives
The review that produced this band started from a harder question, whether a genuinely sustainable 14 percent was reachable for a dollar like this. The answer was no, and the reason is worth stating because a lot of the category is still implying otherwise. Every path to the teens on a peg-bearing dollar runs through leverage that a peg cannot safely carry. In the market as it exists, the teens are only earned in explicitly labelled first-loss junior tranches, instruments whose holders are told plainly that they absorb the losses first. That is a legitimate product. It is not a stablecoin, and it is not what kUSD is. A dollar that promises the peg and the junior-tranche yield at the same time is promising something the structure cannot deliver, and the last two years have a list of names that demonstrate it.
How to check every number here
The modeled APY, its six inputs and its methodology string are at /api/apy. The realized figures for Kerne and every comparable in the table above, with the from-block and to-block for each read, are at /api/honesty-index and rendered at /honesty-index; the method is to read decimals and convertToAssets at both blocks and annualize over the real elapsed time, which is the same procedure you can run against us. The reserve side is at /api/por, signed hourly at /api/por/signed. All of it is collected in one machine-readable document at /facts.json. The formula behind the model is written out at /docs/yield-methodology.
Figures are as of July 21, 2026 and nothing here is investment advice. The modeled APY, its inputs (Lido 7 day SMA 2.20 percent, Hyperliquid 180 day trailing funding 3.99 percent, 22.32 percent strategy costs, 10 percent insurance allocation, 0 percent Genesis protocol fee, 3.0x target leverage) and the resulting 12.98 percent are the live values served by kerne.fi/api/apy on that date and move with market inputs. The 9.40 percent upper bound is the same published formula evaluated at 2.0x leverage with the 4.39 percent trailing funding mean and roughly 2.33 percent staking baseline recorded by the June 20, 2026 internal review; evaluated at today's inputs the same 2.0x ceiling gives 8.66 percent. The 8 percent lower bound is the risk-gated blend described above and is a judgement about sustainable structure, not a measured rate. Realized figures for every token in the comparison table are recomputed by Kerne from each vault's own ERC-4626 share price over a trailing 30 day window and are republished hourly at kerne.fi/api/honesty-index, each row carrying the from-block and to-block needed to recompute it; Kerne's own realized figure covers a shorter 17 day window because the vault was redeployed on July 3, 2026, and derives from a single 0.10 kUSD distribution recorded as a plumbing test rather than strategy carry. Kerne is pre-audit: on its first external audit (Hexens), fieldwork ran from July 13, 2026 and the initial report landed on July 20, 2026, with remediation underway. The code is not yet through a completed external audit.
Addendum, July 21, 2026
Published later the same day, after an internal review flagged a tension this post should name rather than carry. The upper-bound section derives the top of the band by multiplying the combined carry by 2.0x. Two sections later, the post correctly states that venue leverage reduces posted margin and does not multiply the carry earned on the underlying. Both sentences cannot describe the same deployed structure. The reconciliation: a leverage multiplier on carry is only coherent for a strategy that levers the underlying spot exposure itself, holding more yield-bearing collateral per dollar of capital than an unlevered book. The deployed engine does not do that. It sizes its short one for one against the vault's exposed assets, and under that structure the correct multiplier on carry is L divided by L plus 1, which is below one, not above it.
So the honest reading of every levered figure in this post is: the 12.98 percent headline and the 8.66 to 9.40 percent upper bound are both targets at scale for a levered structure that is not currently deployed. At today's inputs, the structure that is deployed supports roughly 3.2 percent on an LST spot leg, about 2.1 percent if the spot leg is unstaked WETH, net of the same cost haircuts the formula already applies. The realized record, about 0.21 percent annualized from a single test distribution, is on the Honesty Index. The lower bound of the band, near 8 percent, is a multi-lever blend that does not depend on the leverage term and survives this correction unchanged.
What changes on our surfaces as of today: every surface that presents the modeled figure now labels it a target at scale and states that the deployed engine runs unlevered, and the yield methodology chapter no longer asserts a levered-carry mechanic the deployed strategy does not run, or cites a backtest artifact that does not exist. A corrected model that reads deployed leverage live, rather than a target constant, is queued behind the external audit's final report. This addendum is the dated correction; the text above it is unchanged.
Addendum, July 24, 2026
The corrected model the addendum above said was queued has shipped, ahead of the audit's final report rather than behind it, so this note records what the surfaces now say. The published headline is no longer the levered figure. Every Kerne surface that renders an APY now renders the deployed basis: the venue leverage L the hedge engine itself targets from the funding rate, applied to the combined carry as L divided by L plus 1. That multiplier is below one for every finite L, which is the whole of the correction in a line. At the inputs read on July 24, 2026, L is about 1.92, the multiplier about 0.66, and the deployed figure lands near 2.93 percent after the same cost, insurance and fee haircuts the formula above already applies.
As of this addendum the 3.0x figure had not been deleted and had not been quietly promoted either. It was published beside the headline under its own label, a modeled target at scale, worth about 13.38 percent at the same inputs, and it stayed a target because reaching it needed a levered spot leg the protocol does not run and a borrowing facility it does not operate, with no borrow cost charged against it. On July 28, 2026 that target was withdrawn entirely and it will not return, so the deployed figure is now the only forward rate Kerne publishes.
Two sentences in the July 21 addendum are now out of date, and dating them is better than deleting them. Our surfaces no longer label the headline a target at scale, because the headline is no longer the levered number. And the roughly 3.2 percent quoted there for a deployed staked spot leg was arithmetic done by hand at that day's inputs; the shipped model recomputes it from live funding on every read, which is why today's figure prints lower. Everything else stands. The lower bound of the band, near 8 percent, carries no leverage term and survives this correction as it survived the last one. The 8.66 to 9.40 percent upper bound is still a ceiling for a levered structure that is not deployed. The realized rate on the Honesty Index is still the only record rather than a model, and still the smallest of the three numbers. This addendum is the dated correction; the text above it, including the July 21 addendum, is unchanged.
Addendum, July 25, 2026
The July 24 addendum describes a model that reads the venue leverage the hedge engine targets. It does read it. What we found the next day is that the engine never sent that leverage anywhere. It computed L from the funding rate every cycle, passed it to the APY model, wrote it to two log lines, and dropped it. There was no code path to transmit it: the exchange adapters carried no leverage method at all, and the base class that defines the adapter interface did not declare one, while the Hyperliquid SDK had exposed the call the whole time. The venue therefore ran at its own default. On July 25, 2026 the hedge account showed 20x cross on ETH, which is Hyperliquid's default for an account that has never set it, against a published L of 1.92. The venue state is itself the evidence it was never set.
The intuitive reading of that is wrong, and it is worth being precise because the correction cuts the other way. On Hyperliquid cross margin the configured leverage sets the initial margin requirement, notional divided by L. It does not multiply the carry, and it does not change the liquidation price of an open cross position, which is governed by maintenance margin at the asset's maximum leverage instead. At 20x the venue required 0.74 dollars of margin against a 14.80 dollar short while the account held 26.70 dollars. The setting was never the binding constraint, so transmitting the modelled 1.92x moves no money and raises no yield. Anyone reconciling our published carry against the venue would have found a divergence, and it would have been a risk divergence rather than the yield explanation it looks like.
What does cost the yield is margin sitting at the venue earning nothing, and the numbers are worse than the headline multiplier implies. The published multiplier is L divided by L plus 1, about 0.66. The book earns carry on its spot leg over spot plus margin, which on the same signed attestation was 11.53 dollars of tracked on chain ETH against 26.67 dollars of venue equity, a multiplier of 0.30. No code path sized venue margin to the modelled split or recalled the excess, and none does now. That gap is measured every cycle and published, but moving the capital is still a human decision, because at this book size a Hyperliquid withdrawal fee alone is a material fraction of the principal being moved and the transfer costs more than the carry it would buy.
The larger term is not the leverage or the margin. It is how little of the protocol is in the strategy at all. On the same read, the strategy sleeve was 38.20 dollars against 1,011.58 kUSD of staked claim and 1,113.89 dollars of USDC sitting in the peg module earning nothing. One percent of protocol capital was in the spot leg earning the carry the published rate describes. That, and not the venue configuration, is the bulk of the distance between a modelled 2.93 percent and a realized figure near 0.17 percent. The staked vault is entirely founder owned at present, so no outside holder has been paid against that gap, and we would rather state the ratio than let it be inferred later.
What shipped with this note. The engine now transmits its computed leverage before any order, and re-asserts it every cycle rather than remembering what it last sent, because the CoW solver writes leverage on the same account and a remembered value would have hidden that. The solver is now raise only and can no longer lower what the engine set. The transmitted value is floored at whatever keeps the hedge postable: on cross margin a lower leverage is a smaller maximum hedgeable notional, so naively sending 2x would have cut headroom on this account from about 534 dollars to about 53 dollars and left the vault unhedged above that, which is a worse outcome than a venue that does not match the model. A regression test asserts the transmitted order carries the computed target, and the margin gap has its own tests including the refusal to recall when the move cannot pay for itself.
What did not change is the headline. It is still the engine rule rather than the measured ratio, because at this book size the measured ratio moves on rounding rather than on the market, and the measured figure is already published beside it in the measuredVenue block of /api/apy, where it reads below the headline. That endpoint now also carries a venueLeverage block stating what the model asks for, what the engine transmits, what the venue defaulted to before any of this existed, and that no code path yet sizes venue margin to the modelled split. To check the venue directly, post {"type":"clearinghouseState","user":"0x09a2780ac8Be6D5d2d1F85A8D92b09D40C9CA37e"} to api.hyperliquid.xyz/info and read the position's leverage value against what we publish, and its positionValue against accountValue for the multiplier the book is actually earning. This addendum is the dated correction; the text above it, including both earlier addenda, is unchanged.
Shipped and confirmed at 01:31 UTC on July 26, 2026. The first hedge cycle after the restart logged the venue leverage being asserted at 3x against an engine target of 2.60x, funding having moved since the figures above were taken, and the account went from Hyperliquid's 20x default to 3x. The rest of the venue reading is the part worth checking, because it is what the correction above predicts: the position size did not change, no capital moved, and the liquidation price is identical at 5150.1001489203. Only the margin reservation moved, from 0.741968 to 4.949086 dollars, which reduced withdrawable from 25.176211 to 21.703161. That is the whole effect of transmitting the leverage, and it is why we said it closes a risk gap rather than a yield one. The same cycle measured the book's carry multiplier at 0.3578 against a modelled 0.75 and declined to recall the idle margin on its own economics, logging that recalling 20.47 dollars would earn about 1.86 dollars a year against a 60 dollar hurdle. That gap stays open and stays published.
Verify it yourself
Run the same check on any reserve, or have it run for you.
Paste any issuer's signed attestation into the free verify tool and recover the signer, rehash the figures, and check freshness in your own browser. If you would rather have it run for you, there is a machine-signed instant read of an address you name, a human-reviewed version of the same read, a commissioned teardown like this one on any target, and an independent read of a counterparty you hold or allocate to. Rates are on each page. Attestation tooling, not an audit, and not a solvency opinion.