Kerne Security
Where to take a security budget
Several different things get called an audit, they cost very different amounts, and which one you need depends on what you are trying to settle. This page routes you to whichever fits: a full private audit with Hexens, a competitive contest or a standing bug bounty with Sherlock, or a fixed-price adversarial pass run in-house by our own Whitehat Desk.
Every route on this page can pay us, so here is that before the advice rather than after it. Hexens has a signed agreement with us and pays us if an introduction turns into a paying engagement. You pay us nothing for that and we add nothing to what Hexens quotes you. Sherlock publishes a referral programme we may be able to claim under, though we have never been their customer, have no agreement with them, and have not confirmed we qualify. The third route is our own paid service, so there the money is ours outright. A recommendation you find out later was paid for is worth less than no recommendation at all.
The disclosure, in one place
- Kerne has a signed referral agreement with Hexens Cyber Security Ltd. It is non-exclusive, and it does not stop us introducing you to anyone else or stop them working with anyone else. If an introduction we make becomes a paying engagement, Hexens pays Kerne. That is the conflict, and it is the reason this box exists.
- You pay us nothing for the introduction, and we add nothing to what Hexens quotes you. Whatever you agree with them is between you and them.
- We cannot publish what we are paid, how it is worked out, or any other term. The agreement keeps its commercial terms confidential and permits us to say that it exists, which is what this page does. Hexens confirmed in writing on 1 August 2026 that they want it kept to the existence alone, and we agreed.
- Sherlock is a weaker arrangement than that, and the difference matters. We have no agreement with Sherlock. They have never paid us anything. They publish a referral programme that anyone can submit through, we may be able to claim under it, and we have not yet confirmed that a referrer in our position qualifies at all. Read every sentence on this page about Sherlock as coming from someone who has never been their customer.
- The Whitehat Desk is ours. On that route we are not a referrer at all, we are the seller, and we keep the whole fee.
- Hexens is also the firm auditing Kerne. We are their client and their referrer at the same time, and you should read our opinion of them knowing both of those things.
- We do not perform any audit, price it, scope it, or see the findings unless you show them to us.
The three routes, and how to tell which is yours
These are not tiers of the same product and the expensive one is not the best one. They answer different questions, and buying the wrong one is the most common way a small team wastes a security budget.
Route one
A full private audit, with Hexens
Take this one if
- Your contracts are close to frozen and you need a report a counterparty, a listing venue or an allocator will accept.
- You have a budget in the tens of thousands and weeks of calendar.
- You want one team of named reviewers who will sit with your design and argue with you about it.
This is the expensive route and it is the one we know best, because Kerne bought exactly this from Hexens with its own money and went through the whole thing: scoping, the engagement, an initial report, remediation, and a final report that published on 31 July 2026. We can tell you how they scope, what their reports actually look like, how they handle a finding you disagree with, and what the calendar really was rather than what the proposal said. A full audit is generally $40,000 to $100,000 for a DeFi protocol.
What we get out of it
Kerne has a signed, non-exclusive referral agreement with Hexens Cyber Security Ltd, and if an introduction we make becomes a paying engagement, Hexens pays Kerne. You pay us nothing for the introduction and we add nothing to what Hexens quotes you. We cannot publish what we are paid, how it is worked out, or any other term of the arrangement: the agreement keeps its commercial terms confidential and permits us to say that it exists, and Hexens confirmed in writing on 1 August 2026 that they want it kept to the existence alone.
What runs against it
We know one firm well and that is a limit of ours, not a ranking. If your system is a Solana program, a zk circuit or anything else outside what we watched them do, we will say so rather than route you anyway.
Route two
A competitive contest or a standing bug bounty, with Sherlock
Take this one if
- You want many independent reviewers looking for the same class of bug at once, rather than one firm.
- Your code is already live and you want continuous coverage on it rather than a snapshot.
- A full private audit is more than you can spend right now, or more than the change in front of you justifies.
Sherlock runs audit contests, bug bounties and a few other lifecycle products. A contest puts your code in front of a competing field for a fixed window and pays out on what they find. A standing bounty is the thing you leave running afterwards, so that the researcher who finds something in month seven has somewhere to take it that is not your DMs. The two answer different questions and Sherlock will tell you which of theirs fits better than we can.
What we get out of it
Sherlock publishes a referral programme and we may be able to claim under it. Its terms are published in full on their own page rather than summarised by us here, and the link is below. Nothing about that programme changes what you pay Sherlock.
What runs against it
Read this part before you weigh anything we say about them. Kerne has never been a Sherlock customer. We have not bought a contest or a bounty from them, we have no agreement with them, they have never paid us anything, and as of today we have not confirmed we even qualify as a referrer. So this is a pointer to a venue type, not a recommendation of a firm on the strength of experience we do not have. Sherlock also requires that a referred team is expecting the outreach, so we will not put your name in front of them without a yes from you in writing first.
Route three
A pre-audit adversarial pass, run in-house
Take this one if
- There is one mechanism you are genuinely unsure about and you want that question answered rather than the whole codebase reviewed.
- You are going to buy a full audit and you would rather the cheap findings were already fixed before you pay for the expensive review.
- You need something back in days.
The Whitehat Desk is a fixed-price adversarial sweep, $2,500 for a focused pass and $5,000 for an extended one, run by independent researchers and coordinated by us. It buys down risk on the way to a full audit rather than standing in for one, and it is the honest answer for a lot of the teams who arrive here asking for an audit they do not need yet.
What we get out of it
This route is ours, and that makes it the largest conflict of interest on the page. We are not introducing you to anybody here. We are selling you our own service and keeping all of it. Weigh what we say about it accordingly.
What runs against it
A sweep is not an audit and a clean sweep is not a guarantee. It is a time boxed, best effort review, and no result from the Desk should be presented to anybody as proof that a protocol is safe.
Why we would introduce you at all
Kerne bought an audit with its own money and went through the whole process. That is the entire basis of what we can tell you about Hexens, and it does not extend to anybody else on this page. Most of the useful information about a firm before you commit $40,000 to $100,000 is held by people who already paid it. We are one of those people for exactly one firm, and we will answer specific questions about that experience, including the parts that were annoying.
Kerne has been through exactly one external audit, and we will not describe our code as passed, clean, or secure on the strength of it. Our own audit status, findings and remediation are at kerne.fi/security, so you can judge the recommendation against how we handled our own findings.
When we will tell you not to
We are paid on two of the three routes above, so the incentive runs one way. The only useful answer to that is a specific list of the cases where we say no, written down before the situation comes up.
- Your contracts are still changing week to week. An audit of a moving target is an expensive snapshot of code you are about to replace, and a contest on one is worse, because you will pay a field of researchers to find bugs in a version you have already rewritten.
- What you actually need is cheaper than what you asked for. If the question is whether a single mechanism holds up, a focused adversarial pass costs a fraction of an audit and answers it sooner.
- You want a standing bounty on code nobody has reviewed yet. A bounty prices the bugs somebody else finds first. On unreviewed code that is usually the most expensive order to do things in, and the cheaper sequence is a review, then the bounty.
- You are pre-product and the budget would be better spent getting to a design worth reviewing at all.
- You are already talking to one of these firms. Tell us on the form and we will say so plainly rather than trying to get in front of it.
- Another firm is a better fit for your stack, including firms we have no arrangement with and get nothing from. We know one firm well. That is a limit of ours, not a ranking, and if your system is a Solana program or a zk circuit we will say so rather than route you anyway.
- You want the audit for a marketing line rather than for the findings. Every firm can tell, and it wastes your money.
What actually happens
1. You tell us what you are trying to settle
The form asks which of the routes above you think you want, and it is fine to say you do not know. It also asks for the things a firm needs in order to answer at all: what the contracts do, roughly what you can spend, who signs off, and when. If you cannot answer some of those yet, send it anyway and say so.
2. We tell you which one we think fits, including when it is none of them
Sometimes the answer is that you should not spend anything yet, and we would rather say that than route you. If your design is still moving, or the thing you actually want is a cheaper pass first, we will say that instead.
3. We make the introduction, and the fee is disclosed inside it
If it is a fit, we send the firm your context and introduce you directly. The introduction itself states that we are paid if you engage them, so you and they are reading the same disclosure at the same time. For the Sherlock route nothing is submitted at all until you have said yes to it in writing, because their programme requires that you are expecting the contact.
4. You deal with them directly
Scope, price, timeline and contract are between you and the firm. We do not sit in the middle of it, we do not mark anything up, and we do not get a say in what they charge you. We ask for a yes or a no in writing and we pass their answer on either way, including a no.
If you found the bug, you are already in the room
This section used to ask you to bring us a protocol that needs an audit. That is prospecting, and prospecting is not what anybody reading this page is doing. The narrower version costs you nothing: a team you have just sent a finding to already knows, that week, that it has a security problem, and most teams at that moment have no idea what to buy or what it should cost. You are already in the conversation. Pointing them at the right venue is one sentence.
So here is the sentence, written out so that you do not have to write it. Paste it into the thread you are already in.
Before you spend anything on this, Kerne publishes a page that lays out what an audit, a contest and a bounty each actually settle, and what each one costs: kerne.fi/security/audit-referrals . They are paid if you go to one of the two firms they route to, they say so on the page before the advice, and you pay them nothing.
Copy us in when you send it. If you would rather not sit in the middle of it, send us the name instead, once the team has said that it wants the introduction. Either way, tell us through the form below, because that is what creates a record of who was first.
On the Sherlock route that record matters more than it sounds. Their programme treats an introduction made in a thread that includes them as a qualifying submission, so copying them in is enough and nobody has to fill in a form. They attribute to the first qualified submission on record and keep a referral eligible for 180 days from it, which is the reason to say something early rather than when the deal closes.
If it converts, Kerne splits what it is paid with you fifty fifty, whichever venue it lands at. That split is ours to state and it is not conditional on anything except the introduction actually converting. We will not publish the amount, yours or ours, and neither should you.
The disclosure is not negotiable, which is exactly why it sits inside the sentence above rather than being left to you to remember. If you write your own version, say in it that we are paid. We would rather lose the lead than have somebody find out afterwards that a recommendation was paid for.
Researchers who have disclosed to Kerne can also take paid work through the Whitehat Desk, which is a separate arrangement with its own terms.
A full audit may cost less than you expect
Hexens takes part in the Ethereum Foundation and Areta Audit Subsidy Program, which can cover up to 30 percent of an audit for teams it accepts into a cohort. We will point you at the application when we make the introduction. It lowers your cost rather than ours, and it does not change your terms with them. This one is specific to the full-audit route and does not apply to a contest, a bounty or a Desk sweep.
Limits, in plain language
- Kerne is not an auditor and does not audit anything on this page. On two of these routes we make an introduction and nothing else.
- We do not warrant either firm's work, their findings, their timelines, or their availability. No audit, contest or bounty is a guarantee that code is safe, and no clean report from anyone should be presented as one.
- We have no say in what they charge you, what they scope, or whether they accept you at all. They decline introductions and we pass that on unchanged.
- Your contract is with them. We are not a party to it, we do not hold your money, and we have no authority to agree anything on their behalf.
- Nothing you send through the form below obliges you to anything. No introduction is made, and nothing is submitted to anybody, until you tell us to make it.
- This page is not a survey of the security market. It carries the two firms we can say something specific about plus our own service, and there are good firms on none of those lists.
Ask for an introduction
The fields below are the ones a firm needs in order to answer. A request without them tends to sit unanswered, which helps nobody, so it is worth two minutes. If you do not know which route you want, say that: it is a normal answer and it is the reason the first question has that option.