Skip to content
Security audit

Audited by Hexens. Zero findings on the mint PSM.

Hexens audited five contracts. The live mint PSM runs byte for byte the source they reviewed and drew zero findings. All ten findings sit in KerneVault, which is closed to deposits: eight fixed in source, two acknowledged.

HexensFinal audit report
0 findings on the PSM
10findings
8Fixed
2Acknowledged
0Critical
SHA-256 1f858d91…fb7298Open

Ten findings. None critical.

Two high, two medium, four low and two informational. All ten were in one contract, KerneVault, and each one has a published response.

CriticalNone0
High1 fixed, 1 acknowledged2
Medium2 fixed2
Low3 fixed, 1 acknowledged4
Informational2 fixed2
FixedAcknowledged
Scope
Five contractsAll ten findings in KerneVault.sol
Final report
31 July 2026reissued 20 August 2026
Status
8 fixed, 2 acknowledged

Acknowledged means we agreed the finding is valid and kept the code as it was, with our reasoning published in full.

Read every response
Deployed versus source

The contract on Base matches its source.

Sourcify reports an exact match for the peg stability module: the bytecode on Base compiles from the published source, metadata included. Check it yourself, no account needed.

  1. 01
    Open the contract on Basescanbasescan.org/address/0xaBDE…9803
  2. 02
    Ask Sourcify for the matchmatch: exact_match
  3. 03
    Read the findings against it0 findings on the PSM
BaseSourcifyBase, chain 8453exact_match
GET sourcify.dev/server/v2/contract/8453/0xaBDE…9803
{
  "match": "exact_match",
  "chainId": "8453",
  "address": "0xaBDE1138aa1Ce88d1dF06422C0c3b05D70569803"
}
USDCPeg stability module, USDC in, kUSD out0xaBDE1138aa1Ce88d1dF06422C0c3b05D70569803
Who audited Kerne?

Hexens audited five contracts. The live mint PSM runs byte for byte the source they reviewed and drew zero findings. All ten findings sit in KerneVault, which is closed to deposits: eight fixed in source, two acknowledged.

What does acknowledged mean?

We agreed the finding is valid and kept the code as it was, with the reasoning published in full. Eight findings were fixed and two were acknowledged.

Is the code on Base the code in the source?

For the peg stability module at 0xaBDE…9803, Sourcify reports an exact match: the deployed bytecode compiles from the published source. The vault that carries the ten findings takes no deposits. The three steps above let you check it without trusting us.

Where do I read the report?

The final PDF sits unedited in Kerne's public contract registry, with its SHA-256 beside it. Download it, hash it, and compare.

Every finding and every response, public.