Kerne Logo

Security

Researcher Acknowledgments

The independent security researchers who have responsibly disclosed findings to Kerne, credited by the handle of their choosing and with their consent. Finding class, report date, and current status for each, with no exploit detail.

Researchers who disclosed

7

Publicly credited

7

Awaiting consent to list

0

Nearly every outside party that has looked closely at Kerne so far has been a security researcher. That is just where we are this early, and we would rather be upfront about it. Each report below got a real technical response from someone who read the proof of concept and worked the fix.

We do not run a paid bounty and we do not guarantee payment. What we do is read every good-faith report and respond seriously, and give safe harbor for that work. When a researcher wants public credit, we list them here by the handle they choose. Where the treasury allows, we send discretionary thank-you rewards, and we prioritize critical findings.

We list a researcher only after they tell us they want public credit, so this list is shorter than the full set who have helped. And we describe a finding by its class and current status only, never the exploit path, and only once it is no longer exploitable on the live contracts, whether because the fix has shipped or because the surface was never reachable. Enough detail to verify a bug is also enough to use it, so we hold that detail until then. This is the same coordinated-disclosure posture described on the findings-response page.

Credited researchers

Dmitriy Filatov

Treasury buyback · reported July 14, 2026

Buyback slippage floor derived from a same-transaction pool quote, without an independent price reference.

Status: Accepted. No live impact: the buyback flywheel is disarmed (no keeper, no inventory, no live venue). Recorded as a mandatory pre-arming gate and included in the external audit scope. Supplied a working proof-of-concept harness, which is being folded into the buyback regression suite.

@Olamdeen

Yield oracle · reported July 4, 2026

Denial-of-service in the yield oracle's multi-party consensus path.

Status: Fixed in source. No live impact, because the live oracle does not run the multi-party consensus path; the fix ships with the next oracle deployment.

Kor_HaeTae

Insurance Fund · reported July 4, 2026

Insurance-fund accounting gap on untracked injections.

Status: Fixed in source, pending redeploy.

Ekankaar

Mint routing · reported June 25, 2026

Stale routing-quote handling in the mint flow.

Status: Fixed and live.

Jay

Staking (escrowed KERNE) · reported June 24, 2026

Vesting-accounting review of the escrowed-KERNE path.

Status: Fixed in source; ships with the esKERNE redeploy.

SpokoDev

Staking (escrowed KERNE) · reported June 23, 2026

Forfeiture-on-exit could be bypassed on the escrowed-KERNE vesting path.

Status: Fixed in source. Latent on-chain (the escrow is unfunded); ships with the esKERNE redeploy. Has offered to re-test the fix after deployment.

Gaurang Maheta

Yield oracle and APY · reported June 16, 2026

Yield-oracle-to-vault linkage and the honesty of the displayed APY.

Status: Addressed. The APY methodology and its public presentation were hardened, including an independent-yield comparator.

Report something

Found an issue? The scope, severity guidance, and safe-harbor terms are on the Bug Bounty Program page. Report to kerne.systems@protonmail.com. How findings from the in-progress external audit are triaged and disclosed is pre-committed on the findings-response protocol page, and the internal-audit remediation status is on the findings tracker.