The depeg gate
Every mint and redeem on the PSM reads the Chainlink USDC/USD feed first. A stale feed or a moved peg reverts the transaction.
- Staleness window
- 48 hours
- Unset oracle
- Fails closed
- USDC mint cap
- 10,000,000
kUSD is backed one for one by USDC on Base. Exit in one transaction, with no lockup and no cooldown. Every limit below is read from chain.
USDC, one for one, held in three PSMs
54 of 130 minutes used at the 12 Sep read
Stale or off peg, the mint reverts
Read from paused() on the PSM
The gate checks the peg before every mint and redeem. The proof shows the backing every hour, signed and reproducible from chain.
Every mint and redeem on the PSM reads the Chainlink USDC/USD feed first. A stale feed or a moved peg reverts the transaction.
The USDC behind every kUSD sits in three PSM contracts on Base. Every hour a signed statement reads it from chain and sets it against kUSD outstanding.
Read every minute, signed every hour, and acted on by the contract itself, with nobody in the loop. The emergency pause is the one exception: the Safe can pull it at once.
Every wired threshold is read and checked against its limit.
GET /api/risk-statusBacking is signed and verified. A stale signature is a trigger of its own.
GET /api/por/signedA breached gate reverts the mint or redeem inside the PSM. No signer needed.
revertThe PSM fee falls as the ticket grows, and the same ladder applies on the way out. Read live from getFee. Each exit is limited to the USDC held in the PSM you redeem from (read live).
Four reads against Base mainnet reproduce the load bearing claims on this page. Paste them into any terminal with Foundry.
# Base mainnet, no key and no signature needed export ETH_RPC_URL=https://mainnet.base.org export PSM=0xaBDE1138aa1Ce88d1dF06422C0c3b05D70569803 export KUSD=0x5C2EfdF0D8D286959b42308966bc2B97f5680AA3 export USDC=0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 # 1. the depeg gate is enforced cast call $PSM "depegCheckDisabled()(bool)" false # 2. its staleness window for USDC, in seconds cast call $PSM "maxOracleDelay(address)(uint256)" $USDC 172800 # 3. the USDC mint cap, six decimals: 10,000,000 USDC cast call $PSM "stableCaps(address)(uint256)" $USDC 10000000000000 # 4. mint authority on kUSD sits with the live PSM cast call $KUSD "hasRole(bytes32,address)(bool)" \ $(cast keccak "MINTER_ROLE") $PSM true
The core contracts behind kUSD
0xaBDE1138aa1Ce88d1dF06422C0c3b05D705698030x5C2EfdF0D8D286959b42308966bc2B97f5680AA30x96F5102C15b839757f811A98CEc3725Ac21DfA14
Or fetch the JSON this page reads
await fetch( "https://kerne.fi/api/risk-status" ).then(r => r.json())
# 5. the prior mint PSM no longer holds MINTER_ROLE cast call $KUSD "hasRole(bytes32,address)(bool)" \ $(cast keccak "MINTER_ROLE") 0x07eBb486e11BD217e6085eb5ab663e4517595993 false # 6. the mint surface is open cast call $PSM "mintingEnabled()(bool)" true # 7. the fee ladder, read from getFee at 25,000 and 50,000 USDC cast call $PSM "getFee(address,uint256)(uint256)" $USDC 25000000000 25000000 cast call $PSM "getFee(address,uint256)(uint256)" $USDC 50000000000 40000000 # 8. the arb bot’s admin is the 2 of 3 Safe, and no Kerne key can drive it export BOT=0x57e73919Efc8a70B40a0bFc562C4DC9e58c4D76F cast call $BOT "hasRole(bytes32,address)(bool)" \ $(cast call $BOT "DEFAULT_ADMIN_ROLE()(bytes32)") 0x52d3E450bA6c299B1B07298F1E87DD74732D4877 true cast call $BOT "hasRole(bytes32,address)(bool)" \ $(cast keccak "EXECUTOR_ROLE") 0x09a2780ac8Be6D5d2d1F85A8D92b09D40C9CA37e false
It reads the risk status endpoint, the signed reserve statement and the PSM’s own status every sixty seconds. The risk status endpoint lists every wired threshold, its current value on Base, the limit, and the Solidity identifier that enforces it, read by eth_call through a four RPC fallback chain.
The chain wins. If a value on this page disagrees with what is on Base, the on chain value is right and this page is wrong. Every read is a plain cast call anyone can reproduce.
The flag couples the PSM to the vault book, and those are separate books. kUSD minted through the PSM is backed one for one by the USDC in that same PSM, so a vault reading could block a mint whose backing it says nothing about. What protects a minter: the depeg gate is enforced, backing is signed hourly, the caps revert, and the prior mint PSM cannot mint.
No. Its kUSD MINTER_ROLE was revoked in the 10 July 2026 redeploy, so its mint side is inert. Its redeem side is live: its pause flag, depeg gate and 26 hour oracle window still govern redemptions from the reserve it holds.
Only the holder of DEFAULT_ADMIN on that contract, which on the PSM is a 48 hour timelock that only the 2 of 3 Safe can propose to. The timelock records each scheduled and executed call, so the full history of a flag can be rebuilt from the logs, and an admin transaction lands on chain in public.
Every kUSD is backed by one real dollar, and every limit on it is readable from chain.