Kerne Logo

Bug Bounty Program

Last updated: August 1, 2026

You found something in Kerne

Report it to kerne.systems@protonmail.com. Acknowledgement within three business days, a technical verdict within ten, and public credit under whatever handle you choose if you want it. The scope, the severity bands and the safe-harbor terms are the policy below.

Read what Kerne can actually pay before you spend hours on it. Kerne cannot pay a reward today and none is offered or implied for a report submitted now. The researchers who have already disclosed are credited by handle with their consent.

What Kerne can pay for is commissioned review. When a Whitehat Desk sweep is booked, the researcher who does the work takes $1,750 on a focused pass and $3,500 on an extended one, in USDC within 72 hours of delivery. No sweep has ever been booked and nobody has ever been paid through it, so this is an option on future work rather than a job.

To join that roster, write to kerne.systems@protonmail.com with the subject "Whitehat Desk: roster" and say what you review and where your work is visible. Nobody is listed without writing back, and the supply side is counted in public, including the number who have said yes.

You want someone to find something in yours

The Whitehat Desk is a fixed-price pre-audit adversarial sweep of your own contracts, run by independent researchers and coordinated by Kerne. $2,500 focused, report within 5 business days of scope confirmation, or $5,000 extended, within 10. Seventy percent of the fee goes to the researcher who does the work.

Need something bigger? Where to take a security budget routes a full private audit, a contest or a standing bounty and states what we are paid on each. Every fixed price and delivery window is on one page.

The two doors do not mix. Nothing on the right changes the bounty program below, which covers findings in Kerne's own contracts, is not a paid service, and is not what any paid engagement buys you.

Looking for the audit and security posture page? View internal audit results, security sprints, and verification status.

Live disclosure on the staked-kUSD wrapper: skUSD admin status (live vault redeployed 2026-07-03; Safe co-admin and bot strategist granted 2026-07-08, Trezor renounced both roles 2026-08-02; prior vault rotated 2026-05-18).

What is queued against the governance timelock right now: The governance queue (recomputed from Base on every request, with the heartbeat of the daemon that pages on a scheduled call; 503 rather than an empty queue when it cannot be read).

Everything on this site is Kerne describing Kerne. Here is the part that is not: Independent verification (every check on Kerne performed by somebody who is not Kerne, with the primary source for each one and what each of them left open, including a twenty-day public technical review on the Euler governance forum that nobody paid for). It lists what those reviewers still have open at the same weight as what they concluded, because a page carrying only the flattering half would be the same self-vouching it exists to answer.

The researchers who have responsibly disclosed to Kerne: Researcher acknowledgments (findings, dates, and status, credited by handle with each researcher's consent).

Want a sweep of your own contracts? The Whitehat Desk (a fixed-price pre-audit adversarial sweep: $2,500 for a focused pass, report within 5 business days of scope confirmation, or $5,000 extended, within 10, run by independent researchers and coordinated by Kerne). That is a paid service for other teams, separate from the bounty program below, which is about findings in Kerne's own contracts.

Need something bigger than a sweep? Where to take a security budget: a full private audit, a competitive contest, a standing bug bounty, or a pre-audit pass, with what we are paid on each stated up front. Hexens pays Kerne if an introduction turns into a paying engagement, you pay us nothing for it, and we add nothing to what they quote you. Sherlock publishes a referral programme we may be able to claim under, though they have never paid us anything and we have not confirmed we qualify.

Want to issue your own dollar rather than verify someone else's? Deploy the Kerne stack (the private test suite, the deployment order, the parameter design, and the reserve attestation rails we run in production, scoped in writing per engagement from $25,000). The contracts themselves are MIT and already public, so a fork costs nothing; that is engineering, not assurance, and it is separate from both the bounty program and the security services above.

Responsible for a treasury rather than a codebase? The treasury health check (a $5,000 fixed-scope read of your own stablecoin balances, venue and custody risk, same-day liquidity and idle-cash leakage, delivered as a one-page memo within 5 business days). That is treasury work, not security work: it reviews what you hold and where, never your contracts. It is also the one engagement here that is scoped, priced and paid up front, and it is refundable in full until scope is confirmed.

All of the paid work above is priced in public. Every fixed price, scope bound and delivery window sits on one page, with the order the security items are meant to run in: every Kerne service in one place, with what each engagement covers and what it does not. The cheapest way in is the Disclosure Integrity Audit ($499, delivered within 72 hours of scope confirmation): a read of whether what a protocol publishes about itself matches its own chain. That one is disclosure review, not a security audit, and it does not test contracts for vulnerabilities. None of this changes the bounty program below, which covers findings in Kerne's own contracts, is not a paid service, and is not what any of the above buys you.

Audit posture at a glance

Internal adversarial review

201 findings

Catalogued and triaged across 80 contracts

External audit

10 findings

Hexens, published in full on July 31, 2026

Source verification

14 of 18

Verified on both BaseScan and Sourcify

Kerne ran two internal adversarial passes before any external review: a Solidity-focused pass on May 8, 2026 that catalogued 201 findings across 80 contracts (36 critical, 51 high, 51 medium, 37 low and 26 informational), and an operational and infrastructure pass on May 11, 2026. A finding count is not a status, so every one of them carries a live disposition and, where it is not closed, the exact compensating control, on the Findings Tracker. These were our own passes, not someone else's: they are diligence, and we publish the number because a protocol that looked and found nothing is the one worth worrying about.

The 4 that are not verified on both explorers are KUSDPSM (live) (Sourcify verified, BaseScan pending), KerneStaking, KerneFlashArbBot and KerneTreasury v3 (live fee sink). One of them is the live mint path, and we would rather say so here than let you find it. The reason for each, and the per-contract table, are on the audit and security posture page. The full write-up of both internal passes and the external report live on that same page.

Kerne Protocol ("Kerne," "we," "us," or "our") is committed to the security of our smart contracts, infrastructure, and users. We welcome responsible security researchers to help identify and report potential vulnerabilities in our protocol.

One reason this program exists: most of Kerne's code is written with AI under the founders' direction, and the commit trailers record it. We say so plainly, because code written that way earns more outside scrutiny. The same reasoning sent the contracts to Hexens for a paid external audit. This page stays the canonical bug bounty program and the one we are bound by. A mirror listing on Remedy, the disclosure platform Hexens operates, is prepared and is not yet live; section 3.5 states what it will pay, in what, and what it does not change. The two contracts whose deployed bytecode cannot be reproduced from any source we still hold are named on the live risk surface, with what each one can and cannot do. The same disclosure habit runs the other way as well: what we looked at, measured and then refused to ship is written down, dated and never edited afterwards, in the refusal log, and the one-page summary of the protocol a reviewer usually wants first is the tear sheet.

That audit is finished. Hexens delivered its final report on July 31, 2026, and it is published in full and unedited in our public contract registry: read the report. It records 10 findings against five contracts at commit 0912c870 (kUSD, skUSD, KUSDPSM, KerneVault and esKERNE): none critical, 2 high, 2 medium, 4 low and 2 informational, of which 8 are fixed and 2 are acknowledged without a code change. Our response to every one of them is at every finding and our response, and the finding table itself, each id with its severity, disposition and our answer beside it, is at /security/hexens-2026.

An audit reviews a commit, not a chain, so read that alongside one more fact we publish rather than bury: the live KerneVault does not run the reviewed commit. It was deployed from earlier source, the report's vault findings are open on it, it holds no user funds and has never issued a share, and no deposit opens into it until the remediated build is live and verified. The full map, with the commands to check every claim yourself, is on the deployed versus source page. We will not describe this code as passed, clean or secure, now or after any future audit.

Kerne may, at its sole discretion, offer rewards to individuals who report valid, previously unknown vulnerabilities in accordance with this policy.

This policy does not create any contractual obligation, employment relationship, or guarantee of compensation. Participation in this program is voluntary and at the researcher's own risk and expense.

We aim to respond quickly and seriously to every good-faith report, and we offer safe harbor for that research. Researchers who ask to be credited publicly are listed on our acknowledgments page, by the handle they choose; others who have helped are not listed, by their choice. We prioritize critical findings.

Before you spend hours on a report, read what Kerne can actually pay right now. Short version, read on chain at Base block 50,059,445: the total dollar balance across every account Kerne controls is $106.00, there are already 1,250 USDC of unpaid reward commitments ahead of you, and no reward is offered or implied for a report submitted today. The work is genuinely wanted. The money is not there yet, and you should know that first.

1. Scope

Smart Contracts

The following contracts deployed on Base (Chain ID 8453) are in scope. Only the deployed versions of these contracts are eligible for consideration:

  • KerneVault
  • kUSD
  • KUSDPSM
  • KerneToken
  • KerneStaking
  • KerneInsuranceFund
  • KerneTreasury
  • KerneFlashArbBot
  • esKERNE
  • KerneReferral
  • KerneYieldDistributor
  • KerneYieldOracle

Web Applications

The kerne.fi and app.kerne.fi web interfaces are in scope, but only for vulnerabilities that could directly result in loss of user funds or compromise of the protocol's integrity.

2. Severity Classification

Reported vulnerabilities are assessed based on their potential impact and exploitability. The following classifications serve as general guidance:

Critical

Vulnerabilities that could lead to direct loss or theft of user funds, permanent freezing of funds, or protocol insolvency. Examples include unauthorized token minting, bypassing withdrawal restrictions, or oracle manipulation leading to fund extraction.

High

Vulnerabilities that could lead to temporary freezing of funds, significant governance manipulation, or compromise of protocol access controls. Examples include privilege escalation or yield calculation errors leading to material loss.

Medium

Vulnerabilities that could lead to griefing attacks, minor yield leakage, or degradation of protocol functionality without direct fund loss. Examples include denial of service to specific functions or minor accounting errors.

Low

Vulnerabilities with minimal impact, informational findings, or best-practice deviations. Examples include gas optimization issues, non-critical view function errors, or events not emitted correctly.

3. Rewards

Rewards for valid vulnerability reports are granted at the sole discretion of Kerne. Reward amounts, if any, are determined on a case-by-case basis considering:

  • The severity and potential impact of the vulnerability.
  • The quality and completeness of the report.
  • The potential impact on user funds and protocol operations.
  • The exploitability of the vulnerability under realistic conditions.

Severity drives the amount, and a critical finding against live user funds is the first thing we look at. Severity does not change what is in the account, so read 3.1 before deciding whether a report here is worth your hours. It states what Kerne can actually pay, with the figure and the date on it.

Kerne reserves the right to determine whether a reported issue qualifies for a reward and to determine the appropriate reward amount. All reward decisions are final and not subject to appeal.

This program does not constitute an offer, contract, or guarantee of payment. Submission of a report does not entitle the reporter to any compensation.

Rewards, if granted, may be paid in USDC, ETH, or other digital assets at the discretion of Kerne. Reporters are solely responsible for any tax obligations arising from rewards received.

3.1 What Kerne can pay today, as of August 16, 2026

Most programs stop at the word discretionary. Here is the figure, and it is read off the chain when this page is served rather than typed in by hand.

Kerne is unfunded and pre-revenue. The total dollar balance across every account Kerne controls is $106.00, read first-hand at Base block 50,059,445 on 2026-08-16 19:23 UTC. Exactly, 105.995508. It is three legs:

  • 76.421602 USDC on Base, founder hardware wallet 0x14f04cE02f35B29Af564A98544dD7e2393993946.
  • 7.874404 USDC on Base, operator account 0x09a2780ac8Be6D5d2d1F85A8D92b09D40C9CA37e.
  • 21.699502 withdrawable on Hyperliquid, hedge venue 0x09a2780ac8Be6D5d2d1F85A8D92b09D40C9CA37e.

ETH held to pay gas is deliberately excluded, because spending it means losing the ability to transact at all. So is the kUSD in the founder wallet: it is a claim on protocol reserves rather than a protocol asset, and redeeming it moves reserves that back somebody else's kUSD. Protocol TVL is a separate number and is not available to pay rewards. Recompute any of this yourself at kerne.fi/api/reward-capacity, which serves these legs with a shell command per leg and is produced by the same code that renders this paragraph.

Against that balance, Kerne owes 1,250 USDC in reward commitments already made in writing to four researchers, three of whom have supplied payment addresses. The queue is about 11.8 times the balance.

A correction, since this page asks to be checked. Until August 3, 2026 this section published $29.52 at Base block 49281910 as a fixed figure dated July 29. It was read first-hand and it was correct on that date. It then went stale without anybody noticing, and by August 3 it understated the real balance by about four and a half times, because roughly 100 USDC came back into the founder wallet when an Aerodrome liquidity position was withdrawn on August 1. The number was wrong in the direction that made Kerne look poorer, which is not an excuse: a figure you are asked to rely on before working for free has to be right in both directions. It is now derived at render time and stamped with the block it was read at, so it cannot rot again.

So, plainly: Kerne cannot pay a reward today, and no reward is offered or implied for a report submitted now. Treat the amount as zero unless and until we write to you with a figure.

While this holds, cash amounts are set in the low hundreds of USDC. The largest cash commitment made to date is 500 USDC. Nothing on this page should be read as suggesting a four or five figure payout in cash. Two things would change that: the first paid engagement on the whitehat desk, or outside funding. Kerne has no funding commitment and no dated prospect of one, so neither of those has a date either.

The four and five figure numbers in 3.5 are the Remedy ladder. They are denominated in dollars and settled in the KERNE token, not in cash, and 3.5 states plainly what KERNE is worth today, which is nothing you can sell.

3.2 What a report does get

  • A technical verdict rather than a form reply. Every report is checked against current source and against the deployed bytecode, which on this protocol are not the same thing, and you get the reasoning with the file and the line.
  • An acknowledgement within three business days, and a technical verdict within ten business days. Those are the only response windows this program publishes.
  • Public credit on the acknowledgments wall under whatever handle you choose, or no credit at all if you would rather.
  • Where the finding is no longer reachable on a live contract, a named public regression test in the public contract mirror, headed with your name and the date you reported, in a repository that builds and runs its whole suite from a clean clone. Eight of those exist as of July 31, 2026. The same two rules gate it as gate the wall: your consent is required to be named, and nothing is described publicly while it is still exploitable live.
  • If a finding earns an amount, the amount is named in writing along with its place in the queue, and 3.3 says how the queue is ordered.
  • A status note on the first Monday of every month to everyone in the queue, until they are paid.

On volume, since it bears on those windows: in the 48 hours to July 29, 2026, ten reports arrived from four researchers. That is more than this program was built to absorb. If volume makes those windows impossible, this page will say so rather than let them quietly lapse.

A correction to this page, since a response window is a promise and not decoration. Until July 31, 2026 this page carried two different sets of windows: the three and ten business days above, and a separate 48 hours with an initial assessment within seven business days further down in section 5. They contradicted each other. The 48-hour one was also the one we had already missed, twice, in the week before this was written. The windows above are now the only ones published here, in the security policy of the public contract mirror, and in section 5 below. They are also the ones we have actually been meeting.

3.3 What is currently owed

  • 500 USDC, committed in writing on July 28, 2026. Address supplied. Unpaid.
  • 250 USDC, committed in writing on July 28, 2026. Address supplied. Unpaid.
  • 250 USDC, recorded internally on July 10, 2026 and communicated to the researcher on July 29, 2026. Unpaid.
  • 250 USDC, recorded internally on July 10, 2026 and communicated to the researcher on July 29, 2026. Unpaid.

Total outstanding: 1,250 USDC. Names are left off because public credit is the researcher's call and not ours. The ones who asked to be credited are on the acknowledgments wall.

Updated July 31, 2026: one of the two July 10 commitments supplied a payment address on July 30, so three of the four are now on file. The amount, the ordering and the total are unchanged.

How that queue is ordered: the four are treated as one batch and paid together. If only part of the amount is ever available, it goes to the oldest reported finding first. Nobody moves up for having written to us more recently, and nobody moves down because we were slow to put their number in writing.

Four further researchers were considered in July for smaller discretionary amounts. Those amounts were never decided and never communicated, so nobody was told to expect them and they are not counted above. They remain recorded internally.

3.4 If we miss a date

If a date on this page passes without either the payment or a written explanation to the person owed, they are free to say so publicly, and we will not dispute it.

3.5 The Remedy listing, and what it pays

Kerne has prepared a mirror listing of this program on Remedy, the disclosure platform operated by Hexens, who audited the contracts. The listing is not live yet. It is in draft, it has not been submitted, and until it is published this page is the only program Kerne runs. When it goes live, the reward ladder below is what it will carry, and we are publishing it here first so the two surfaces cannot say different things.

SeverityReward, denominated in USD
Critical5,000
High2,500
Medium1,000
Low250
InformationalCredit on the acknowledgments wall, no payout

Those amounts are denominated in US dollars and settled in KERNE, Kerne's own token, at the token's initial public price, claimable from distribution. KERNE does not trade today. There is no market, no listing, no pool and no price source, so we will not print a per token figure: doing that would be inventing a number, and a researcher could reasonably read an invented number as cash.

What that means in practice, stated so nobody has to infer it: if KERNE is never distributed, a reward settled in KERNE is worth nothing. We would rather write that sentence ourselves than have you derive it after doing the work. No token generation event has been scheduled, announced or dated.

The ladder applies to findings submitted through Remedy from the listing date forward. It is not retroactive, and it does not apply to reports sent to the address in section 12, which remain under the cash posture in 3.1.

3.6 What the ladder does not change, and what KERNE actually is

The 1,250 USDC in 3.3 is owed in cash and stays owed in cash. It is not re-denominated into KERNE, it is not settled by the ladder, and nothing in 3.5 reduces or replaces it. Anyone in that queue is owed dollars, and a pre launch token is not dollars.

Since the settlement asset is our own token, here is the token, read off Base rather than described. KERNE is deployed at 0x230f3a63E8413D42bEe9103b98a204030206186c and has been since June 7, 2026, block 47,035,509. Total supply is 1,000,000,000, fixed: the contract has no mint function and no minter role, so no more can ever exist. Read at Base block 49,503,016 on August 3, 2026, the 2 of 3 governance Safe at 0x52d3E450bA6c299B1B07298F1E87DD74732D4877 holds all 1,000,000,000 of it, which is 100 percent of supply. Across the token's entire history there is exactly one transfer event, the mint at deployment. It has never moved.

Check it rather than trust us: call totalSupply() and balanceOf() for the Safe address on any Base RPC and compare them. If a reward is ever settled in KERNE, the Safe stops holding 100 percent and this paragraph changes; if you find it stale, section 3.4 applies to it. The longer history, including the retired first token and why it was replaced, is on the KERNE token disclosure.

The honest summary: the ladder is a real commitment, made in writing to our auditor on August 3, 2026, and it is payable in an asset that has no market yet. That is better than the zero we could otherwise offer, and it is worse than cash. Both halves are true and you should price them yourself.

4. Eligibility

To be eligible for consideration under this program, you must:

  • Be the first person to report the vulnerability to Kerne.
  • Not exploit the vulnerability beyond what is strictly necessary to demonstrate it (proof of concept only).
  • Not violate the privacy of other users, disrupt the protocol's operation, or destroy data.
  • Not be subject to sanctions or reside in a jurisdiction prohibited under our Terms of Service.
  • Not be a current or former employee or contractor of Kerne.
  • Comply with all applicable laws and regulations in your jurisdiction.
  • Comply with the responsible disclosure requirements outlined in this policy.

5. Reporting Process

To submit a vulnerability report, please email us at liam@kerne.fi with the subject line "Security Report: [Brief Description]." Your report should include:

  • A clear description of the vulnerability.
  • The affected contract(s) or component(s).
  • Step-by-step reproduction instructions.
  • A proof of concept (code, transaction hash, or screenshots).
  • Your assessment of the severity and potential impact.
  • Your wallet address for potential reward payment (optional at time of report).

We will acknowledge receipt within three business days and give you a technical verdict within ten business days. Those are the same windows published in section 3.2, and they are the only ones this program publishes. They are targets rather than guarantees and can move with report volume, but if one is going to be missed you will be told that it is being missed rather than left waiting.

Do not open public GitHub issues for security vulnerabilities.

6. Responsible Disclosure

We ask that you give us a reasonable amount of time to address the vulnerability before disclosing it publicly, a minimum of 90 days from the initial report, or until a fix has been deployed, whichever comes first.

You must not disclose the vulnerability to any third party before it has been resolved, unless mutually agreed upon in writing. Public disclosure after remediation should be coordinated with the Kerne team.

7. Safe Harbor

Kerne will not pursue legal action against security researchers who act in good faith and in compliance with this policy. "Good faith" means:

  • Making a genuine effort to avoid privacy violations, data destruction, and service disruption.
  • Only interacting with accounts you own or with explicit permission.
  • Not exploiting a vulnerability beyond what is necessary for a proof of concept.
  • Reporting the vulnerability promptly.

This safe harbor does not extend to violations of applicable law, activity that causes material harm to users or the protocol, or actions taken outside the scope of this policy.

8. Out of Scope

The following are not eligible for consideration under this program:

  • Vulnerabilities in third-party contracts, protocols, or services that Kerne integrates with (e.g., Base, Chainlink, Hyperliquid, Aerodrome).
  • Issues already known to the team or previously reported by another researcher.
  • Vulnerabilities in contracts deployed on networks other than Base (Chain ID 8453), unless specifically designated.
  • Frontend bugs that do not result in loss of funds or compromise of the protocol (cosmetic issues, typos, broken links, etc.).
  • Theoretical vulnerabilities without a working proof of concept.
  • Issues related to unsupported browsers or outdated software.

9. Exclusions

The following activities are explicitly excluded from this program and may result in disqualification and/or legal action:

  • Social engineering (phishing, vishing, etc.) targeting Kerne team members or users.
  • Denial-of-service (DoS/DDoS) attacks against Kerne infrastructure.
  • Physical attacks against Kerne facilities or team members.
  • Automated vulnerability scanning that generates excessive traffic.
  • Attacks against Kerne's internal infrastructure (email, CI/CD, cloud services).
  • Any activity that could cause harm to users, including front-running, sandwich attacks, or exploiting the vulnerability on mainnet for personal gain.

10. Limitation of Liability

To the maximum extent permitted by applicable law:

Kerne shall not be liable for any damages arising from participation in this program, including but not limited to any costs or expenses incurred in identifying or reporting vulnerabilities. Kerne makes no representations or warranties regarding the availability, continuity, or terms of this program.

11. Changes to This Policy

Kerne reserves the right to modify, suspend, or terminate this program at any time without notice. Changes are effective immediately upon posting to this page. Your continued participation in the program after any modifications constitutes your acceptance of the revised policy.

12. Contact Information

For security reports or questions about this program, please contact us:

Kerne Protocol

Email: liam@kerne.fi

Website: kerne.fi