Kerne Logo
Kerne Verification Services

Everything Kerne sells, priced, in one place.

Kerne turns the reserve-verification stack it runs over its own kUSD into products anyone can buy. The ladder runs from a free self-serve checker to a signed counterparty read, and every rung is the same idea: a proof you verify yourself, not a number you take on trust. Fixed prices, payable in USDC on Base. Attestation and objective-data tooling, not audits.

Free, self-serve

Run these right now, no signup and no payment. They are the top of the funnel and they are genuinely free.

Paste any Base or Ethereum stablecoin address and see, live, which part of its backing you can verify yourself on-chain and which part rests on an attestor.

Recover the signer and rehash any signed reserve attestation in your own browser. Proves an attestation is authentic and fresh.

Paste any Base or Ethereum ERC-4626 vault address and read its live total assets, total supply, and price per share, with the exact commands to reproduce the read yourself.

An embeddable badge for your own site that fails closed: verified only when the signature checks and the read is fresh.

Self-serve signed reads

A cryptographic artifact you buy in one click with USDC on Base. The fastest paid yes on the site.

A machine-signed, on-chain read of any single address's live supply, decimals, and symbol at a block, delivered on the page in about two minutes.

A one-time, human-reviewed, EIP-191 signed read of any single public address you name, verifiable by anyone in three lines.

Read the full page first

Commissioned reports

Fixed-scope work delivered by people, priced before it starts. Some of it points at a target you name, a deep reserve teardown or a review of a protocol's disclosures against its chain. The rest points at you: your contracts before an audit, or your own treasury.

A 72-hour review of whether a yield protocol's public claims match its chain: advertised versus realized yield, document and address consistency, and oracle and attestation posture, with a signed findings summary you can publish. Disclosure review, not a security audit.

Read the full page first

A reserve teardown of any stablecoin you name: trust boundary mapped, every on-chain figure reproducible, edges stated plainly. $499 delivered privately, $999 published with a permanent public URL.

Read the full page first

You are holding a findings list from a scanner, an AI audit tool, a contest or a reviewer, and every row arrives at the same weight. We adjudicate it: each finding comes back with a verdict, and either a command that reproduces a public on-chain read or a test that runs on a clean checkout of your repo, plus a stated order of what to fix first. Up to 25 findings, delivered within 3 business days of scope confirmation, refundable in full until that confirmation. It reviews the report you were given, not your protocol: not a security audit, not a certification, and it cannot tell you what neither report found.

Whitehat Desk sweep$2,500 or $5,000

The adversarial pre-mortem you run before committing $40,000 to $100,000 to a full audit, so you learn what it is going to surface while the code is still cheap to change. Focused is up to 12 hours of researcher time, delivered within 5 business days of scope confirmation; extended is up to 24 hours, within 10. Run by the independent researchers who have disclosed to Kerne and coordinated by us, and 70 percent of the fee goes to the researcher who does the work. A sweep, not an audit, and not a guarantee.

A fixed-scope read of your own treasury rather than someone else's: your stablecoin balances mapped, your venue, custody, bridge and concentration risk stated plainly, your same-day liquidity ladder, and what the idle cash is costing you. You get a one-page memo and a recommended allocation, plus one round of written follow-up. Up to 15 hours, delivered within 5 business days of scope confirmation. The fixed tier covers one entity on up to two chains; anything larger is quoted inside the published $5,000 to $15,000 band before work starts. It stands alone: you are under no obligation to deploy a dollar afterward. Not an audit, and not investment, legal, or tax advice.

Signed attestation SKUs

A signed statement of reserves that a counterparty verifies themselves, without trusting you or us.

A single, cryptographically signed, point-in-time statement of your own reserves that any counterparty verifies in about three lines. Delivered in 3 to 5 business days.

Read the full page first

An independent, signed read of a counterparty's public on-chain reserves, commissioned by you the allocator. A proof you control, not the issuer's verifier. Scoped reviews from $5,000 to $15,000 for portfolios.

Read the full page first

Standing service

Always-on, for issuers who want a verifiable layer their holders can check any day, not just once.

Continuous monitoring of your pool price, reserve ratio, and attestation freshness on public data, with alerts to your Discord or Telegram on deviation.

Read the full page first
GENIUS-readiness kit$999 setup + $99/mo

A hosted verify page for your token, scheduled machine-signed reserve reads, and an embeddable freshness badge. The verify-it-yourself layer above the attestation floor.

Read the full page first

Engineering

The other direction: rather than verifying someone else's dollar, issue your own. Scoped in writing per engagement, never a wallet checkout.

Our synthetic-dollar contracts are MIT and already public, so fork them for free. We sell the part a fork does not give you: the private test suite, the deployment order, the parameter design, and the reserve attestation rails we run in production. Engineering, not assurance.

The order these happen in

The four security items above answer different questions, and they are meant to run in an order. The order matters more than the price gaps between them. Teams usually get caught by reaching the right one only after the code has shipped.

  1. 1

    Answers: Do the things we have published about ourselves actually match our chain?

    The cheapest gap to close, and the one that costs nothing to fix. It reads your claims, your docs, and your addresses against public data. It does not test your contracts for vulnerabilities.

    Within 72 hours of scope confirmation

  2. 2
    Whitehat Desk sweep$2,500 or $5,000

    Answers: What is an audit going to find, and are we ready to pay for one?

    An adversarial pass over the contracts you are about to submit. You go into the engagement with the cheap findings already closed, or you find out the design is not ready before you have committed the budget.

    Within 5 or 10 business days of scope confirmation

  3. 3
    A full security audit~$40k to $100k

    Answers: Can an attacker take the funds?

    A firm reads your source line by line and models how it breaks. Kerne does not sell this and will introduce you to the firm running its own audit instead. A general market range for DeFi, not a quote.

    Weeks, plus a fix window and a re-review

  4. 4

    Answers: What changed since the audit read the code?

    An audit is a snapshot of one day. The retainer covers what ships afterwards: new deployments, upgrades, parameter and admin changes, and anything still open from the last report.

    A delta pass each month, scheduled with you

Steps 1 and 2 are the ones Kerne sells, and neither is a substitute for step 3. They exist so that when you get to step 3 you are spending the expensive weeks on the parts that genuinely need them. If you are already past all of this and just want the code watched while it changes, that is step 4.

Disclosure review versus a security audit

Worth stating plainly, because the cheapest item on this page with the word audit in its name reviews disclosures, not code. If what you need is someone reading your contracts line by line before you hold real user deposits, the $499 review is not that, and buying it in place of a real audit is a mistake we would rather flag now.

Disclosure Integrity Audit$499
  • Checks your published claims against your own chain: advertised versus realized yield, document and address consistency, oracle and attestation posture.
  • Reads public on-chain data and your own public source of record. It does not test your contracts for vulnerabilities.
  • Delivered within 72 hours of scope confirmation, with a signed findings summary you can publish.
  • Refunded if any on-chain figure does not reproduce, or if we miss the 72 hours.
  • Answers whether your published claims hold up against your own chain.
See the page
A full security audit~$40k to $100k

A general market range for DeFi audits, not a quote and not any particular firm's fee.

  • A security firm reads your source code, models how it can be attacked, and writes up exploitable findings with severities.
  • Weeks of engagement, usually with a fix window and a re-review before the final report.
  • Priced by the size and novelty of your code rather than as a flat SKU, and the range moves with both. Kerne does not sell this.
  • Answers whether an attacker can take the funds.

The $499 review does not substitute for a full security audit, and a clean result from it is not evidence that your code is safe. If a full audit is what you actually need, tell us and we will introduce you to the firm running Kerne's own audit. You pay us nothing for the introduction, and if it becomes an engagement Kerne is paid by the firm.

The step between the two is the Whitehat Desk sweep: an adversarial pass over your contracts by an independent researcher, hour-boxed and time-bound. Its job is to tell you what an audit is going to surface before you commit the budget and the weeks, which is why it runs before one rather than instead of one. It is priced and described that way on its own page.

What all of this is, stated plainly

Every paid item on this page except the Whitehat Desk sweep is attestation or objective-data tooling. It proves that specific public on-chain figures were read and signed at a specific time, so anyone can check them without trusting Kerne. The sweep is an adversarial security review by independent researchers, which is also not an audit and not a guarantee. None of it is an audit, a solvency opinion, a rating, or investment, legal, or accounting advice. Where a token's backing sits off-chain, the deliverable marks that as the boundary rather than vouching for it. Kerne is early: it has one completed external audit, published in full on July 31, 2026, and its deployed vault runs earlier bytecode than the reviewed commit, disclosed at kerne.fi/dataroom, and Kerne is independently listed on DefiLlama; the products stand on cryptography and public data you verify independently, not on our posture.

If you came here to allocate rather than to buy

Nothing above is a way into Kerne itself. Minting is open: USDC into kUSD, 1:1 through the Peg Stability Module, redeemable through the same module at any time. If you would rather read the final Hexens report before you move funds, the commitment queue holds your Opal multiplier from the moment you commit instead of the moment you mint, so the wait costs you nothing. It takes no money, it writes no chain state, and it is non-binding. Diligence first in the data room, where the known weaknesses are stated before the strengths.

Common questions

How much does Kerne charge to verify stablecoin reserves?

There is a free self-serve tool that grades any stablecoin's on-chain verifiability in seconds, and a paid ladder above it: a $29 instant machine-signed read, a $149 human-reviewed address read, a $499 Disclosure Integrity Audit, a commissioned reserve teardown from $499, a $1,500 signed Proof of Reserves snapshot, a $2,500 independent counterparty read, and peg and reserve monitoring from $99 a month. Separately, for teams securing their own contracts, the Whitehat Desk runs a pre-audit sweep at $2,500 or $5,000, and a standing sweep retainer at $3,500 a month per protocol for teams that want the code watched as it changes. Every paid item is a fixed price, and the reserve products are payable in USDC on Base.

How fast is a Whitehat Desk sweep?

A focused sweep ($2,500, up to 12 hours of researcher time) delivers a written report within 5 business days of scope confirmation; an extended sweep ($5,000, up to 24 hours) within 10. The clock starts at scope confirmation, when the scope and price are agreed in writing and a researcher has accepted the work, not when you send the form. If you need it faster, we will tell you what is possible and what it costs once a researcher can hold the shorter date. It is a sweep, not an audit, and not a guarantee.

What is the cheapest paid option?

The $29 instant signed read. You paste any address, pay in USDC on Base, and get a machine-signed, point-in-time read of its live on-chain supply delivered on the page in about two minutes, verifiable by anyone in three lines. Below that, the Verify Any Stablecoin tool is free.

Is any of this an audit?

Almost none of it. The signed reads and snapshots are attestation and objective-data tooling: a named key signs specific on-chain figures at a specific time, bound to that signature. They are not an audit, a solvency opinion, a rating, or financial advice. The one item that is a security review is the Whitehat Desk sweep, an adversarial pass over your contracts by an independent researcher, and even that is a sweep, not an audit and not a guarantee. The $499 Disclosure Integrity Audit is not a security audit either, despite the name: it checks your published claims against public data and your own public source of record, and it does not test your contracts for vulnerabilities. A full security audit is a firm reading your contracts line by line over weeks, typically $40,000 to $100,000 for a DeFi protocol and more once you budget the remediation re-review, and Kerne does not sell one. If that is what you need we will introduce you to the firm running Kerne's own audit; you pay us nothing for the introduction, and if it becomes an engagement Kerne is paid by the firm.

Do I have to trust Kerne to use the paid products?

No more than the cryptography requires. Every signed artifact is one you or any third party can verify independently: recover the signer from the hash and signature, rehash the payload, and read the on-chain figures directly from Base. The point of the product is that you check it rather than trust us.