Skip to content
Risk surface

Risk status, read from Base every sixty seconds

kUSD is backed one for one by USDC on Base. Exit in one transaction, with no lockup and no cooldown. Every limit below is read from chain.

Snapshot, 12 Sep 2026block 51,232,414
kUSD backing100.1%

USDC, one for one, held in three PSMs

Signed reservesFresh

54 of 130 minutes used at the 12 Sep read

Depeg gateArmed

Stale or off peg, the mint reverts

PSM pausedNo

Read from paused() on the PSM

Read from Base and the signed statement, refreshed every 60 seconds. USDC1 : 1kUSDonBase

A gate and a proof stand behind your dollar.

The gate checks the peg before every mint and redeem. The proof shows the backing every hour, signed and reproducible from chain.

EnforceddepegCheckDisabled = false

The depeg gate

Every mint and redeem on the PSM reads the Chainlink USDC/USD feed first. A stale feed or a moved peg reverts the transaction.

Chainlink feedUSDC/USD, 48h window PSM checkfresh and on peg? yes Mint or redeemat one to one no Revertsnothing moves An unset oraclefails closed too. Chainlink feedUSDC/USD, 48h window PSM checkfresh and on peg? yes Mint or redeemat one to one no Revertsnothing moves An unset oracle fails closed too.
Staleness window
48 hours
Unset oracle
Fails closed
USDC mint cap
10,000,000
Signed hourlypsm_solvency_ratio 1.001064

The backing proof

The USDC behind every kUSD sits in three PSM contracts on Base. Every hour a signed statement reads it from chain and sets it against kUSD outstanding.

Signed
Every hour
Freshness limit
7,800 s
Signature
Verified
  • Gate changes pass through the 48 hour timelock, whose scheduled and executed events carry the full call
  • The prior mint PSM holds no mint role and cannot mint kUSD
  • Per stable caps revert inside the PSM

How a breach is handled.

Read every minute, signed every hour, and acted on by the contract itself, with nobody in the loop. The emergency pause is the one exception: the Safe can pull it at once.

01 / DETECT
Every 60 s

Every wired threshold is read and checked against its limit.

GET /api/risk-status
02 / SIGN
Every hour

Backing is signed and verified. A stale signature is a trigger of its own.

GET /api/por/signed
03 / ACT
Same transaction

A breached gate reverts the mint or redeem inside the PSM. No signer needed.

revert

Instant, by the contract

  • Depeg gate reverts on a stale or moved feed
  • Caps revert inside the PSM
  • Fails closed on an unset price oracle
  • A paused PSM rejects every mint and redeem

Signed by the 2 of 3 Safe

  • Changing a gate flag, after a 48 hour timelock
  • Granting or revoking MINTER_ROLE, after the same wait
  • Granting EXECUTOR_ROLE on the arb bot
  • Every flip rebuildable from the logs

Out in one transaction. No lockup, no cooldown.

The PSM fee falls as the ticket grows, and the same ladder applies on the way out. Read live from getFee. Each exit is limited to the USDC held in the PSM you redeem from (read live).

0 sCooldown on exit
1Transaction to exit
SameFee ladder in and out
See the full fee schedule

Check it yourself. No signature needed.

Four reads against Base mainnet reproduce the load bearing claims on this page. Paste them into any terminal with Foundry.

cast, Base mainnet
# Base mainnet, no key and no signature needed
export ETH_RPC_URL=https://mainnet.base.org
export PSM=0xaBDE1138aa1Ce88d1dF06422C0c3b05D70569803
export KUSD=0x5C2EfdF0D8D286959b42308966bc2B97f5680AA3
export USDC=0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

# 1. the depeg gate is enforced
cast call $PSM "depegCheckDisabled()(bool)"
false
# 2. its staleness window for USDC, in seconds
cast call $PSM "maxOracleDelay(address)(uint256)" $USDC
172800
# 3. the USDC mint cap, six decimals: 10,000,000 USDC
cast call $PSM "stableCaps(address)(uint256)" $USDC
10000000000000
# 4. mint authority on kUSD sits with the live PSM
cast call $KUSD "hasRole(bytes32,address)(bool)" \
  $(cast keccak "MINTER_ROLE") $PSM
true

The core contracts behind kUSD

PSM0xaBDE1138aa1Ce88d1dF06422C0c3b05D70569803kUSD0x5C2EfdF0D8D286959b42308966bc2B97f5680AA3skUSD0x96F5102C15b839757f811A98CEc3725Ac21DfA14

Or fetch the JSON this page reads

await fetch(
  "https://kerne.fi/api/risk-status"
).then(r => r.json())
HexensZero findings on the mint PSM
SourcifySource verified, all three
HourlyReserves signed from chain
Read the audits
Four more reads: the prior mint PSM, the mint switch, the fee ladder and the Safe
# 5. the prior mint PSM no longer holds MINTER_ROLE
cast call $KUSD "hasRole(bytes32,address)(bool)" \
  $(cast keccak "MINTER_ROLE") 0x07eBb486e11BD217e6085eb5ab663e4517595993
false
# 6. the mint surface is open
cast call $PSM "mintingEnabled()(bool)"
true
# 7. the fee ladder, read from getFee at 25,000 and 50,000 USDC
cast call $PSM "getFee(address,uint256)(uint256)" $USDC 25000000000
25000000
cast call $PSM "getFee(address,uint256)(uint256)" $USDC 50000000000
40000000
# 8. the arb bot’s admin is the 2 of 3 Safe, and no Kerne key can drive it
export BOT=0x57e73919Efc8a70B40a0bFc562C4DC9e58c4D76F
cast call $BOT "hasRole(bytes32,address)(bool)" \
  $(cast call $BOT "DEFAULT_ADMIN_ROLE()(bytes32)") 0x52d3E450bA6c299B1B07298F1E87DD74732D4877
true
cast call $BOT "hasRole(bytes32,address)(bool)" \
  $(cast keccak "EXECUTOR_ROLE") 0x09a2780ac8Be6D5d2d1F85A8D92b09D40C9CA37e
false

Questions, answered from chain.

What does this page read, and from where?

It reads the risk status endpoint, the signed reserve statement and the PSM’s own status every sixty seconds. The risk status endpoint lists every wired threshold, its current value on Base, the limit, and the Solidity identifier that enforces it, read by eth_call through a four RPC fallback chain.

What happens if a value here is wrong?

The chain wins. If a value on this page disagrees with what is on Base, the on chain value is right and this page is wrong. Every read is a plain cast call anyone can reproduce.

Why is the vault solvency flag off on the PSM, and what protects a minter instead?

The flag couples the PSM to the vault book, and those are separate books. kUSD minted through the PSM is backed one for one by the USDC in that same PSM, so a vault reading could block a mint whose backing it says nothing about. What protects a minter: the depeg gate is enforced, backing is signed hourly, the caps revert, and the prior mint PSM cannot mint.

Can the prior mint PSM still mint kUSD?

No. Its kUSD MINTER_ROLE was revoked in the 10 July 2026 redeploy, so its mint side is inert. Its redeem side is live: its pause flag, depeg gate and 26 hour oracle window still govern redemptions from the reserve it holds.

Who can flip a safety flag, and is the flip public?

Only the holder of DEFAULT_ADMIN on that contract, which on the PSM is a 48 hour timelock that only the 2 of 3 Safe can propose to. The timelock records each scheduled and executed call, so the full history of a flag can be rebuilt from the logs, and an admin transaction lands on chain in public.

Every kUSD is backed by one real dollar, and every limit on it is readable from chain.