Everything here was written by somebody who is not us.
Everything on this page was produced by somebody who is not Kerne. Each entry states who produced it, when, what they actually concluded, where the primary source is, and what they left open. The open items are published at the same weight as the conclusions, because a page that only carried the flattering half would be the same self-vouching it exists to answer.
6 entries. 5 of them were not paid for by Kerne and 1 was. Between them they leave 14 items open, and one reviewer caught 4 separate things Kerne had published wrong. All of that is listed below at the same size as the rest.
How to read this page
Entries are ordered by how hard they are to dismiss, strongest first. For each one: who produced it, whether Kerne paid for it, a direct link to the primary source, what they actually concluded, and what they left open. Nothing here is a verdict on whether kUSD is safe to hold. Nobody on this page said that, and this page does not say it for them.
The open items are not a disclaimer at the bottom. They sit inside each entry at the same size as the conclusions, because a page that carried only the flattering half would be the same self-vouching it exists to answer.
Quotes are verbatim, including lowercase sentence starts and original punctuation. The only changes are character-level: Unicode minus, curly quotes, en dashes and ellipses are rendered as ASCII, because these surfaces are ASCII only. No word is altered and no elision is unmarked.
1. individual reviewer, not paid for by Kerne
A public technical review on the Euler governance forum
Oleg_Aleksandrov, a member of the Euler governance forum. 2026-07-20 to 2026-08-09.
Kerne opened topic 1849 on 2026-07-03 to propose a kUSD market. Oleg_Aleksandrov arrived on 2026-07-20 and spent the next twenty days taking the design apart in public. He posted nine times. He closed on 2026-08-09 with a summary of what the thread had established and a list of what remained open.
He was not commissioned, paid, selected or briefed by Kerne, and he did not take Kerne's word for anything he could read himself. Most of what he asserts, he re-derived from chain or from source before asserting it, which means a reader can re-derive it too.
What they checked for themselves rather than taking from Kerne
Re-read the live mint PSM source on BaseScan and got an exact match: KUSDPSM, v0.8.24+commit.e11b9ed9, optimizer 1000 runs, cancun, both read and write tabs present. (post 21, 2026-08-09)
Recovered both account-registry membership signatures himself, rather than trusting the registry: the messages recover to the two enumerated EOAs. (post 9, 2026-07-29)
Rebuilt the backing ratio from chain instead of reading it off Kerne's endpoint, and got 1,113.885006 USDC against 1,112.707154 kUSD outstanding. (post 11, 2026-07-31)
Tested Kerne's negative-funding threshold against 4,320 hourly Hyperliquid settlements over 180 days and found it unreachable. (post 11, 2026-07-31)
Read the operator Safe directly: guard slot zero, no modules, 2 of 3, all owners EOA, DEFAULT_ADMIN on kUSD at the Safe, getRoleAdmin(MINTER_ROLE) = 0x00. (post 15, 2026-08-02)
Replayed the timelock deploy transaction and the thirteen-call handover call by call, and disassembled the Pause Guardian: 1012 bytes of runtime, six externals, no execute, no unpause, no grantRole, no privileged PSM selectors. (post 19, 2026-08-07)
Confirmed the staking wrapper is outside the handover on chain rather than taking it from Kerne: hasRole(0x00, timelock) = false on skUSD. (post 19, 2026-08-07)
In their own words
His closing summary of what the thread established
stepping back, since this thread has reached a natural boundary. what it established: the canonical solvency read is the PSM ratio, excluding off-chain assets; the hyperliquid balance is publicly readable and signed by the account itself, but completeness of the account set is not provable on-chain. negative funding is absorbed by venue margin with no insurance fund and no automatic close; the minter set was narrowed to one. mint and psm admin moved behind a 48h timelock with an instant scoped pause guardian.
48 hours is a notification only if someone receives it. Today, nothing monitors CallScheduled on this timelock: no subscriber, no alert, no public page. The queue is recoverable from logs, but no one is recovering it. A canceller learning of an operation at hour 47 is decoration, whoever holds the seat.
On catching Kerne changing a definition it had said it would not change
On July 24 you wrote: the warning stays until the hedge runs against collateral that actually backs kUSD. On July 25 the warning is gone. schema v6 now counts the founder wallet in the hedge base, which still backs no kUSD. That looks like exactly the change you said you wouldn't make. What am I missing?
Post 3, 2026-07-20. Kerne's proposal described a live Morpho market as a precedent to underwrite against and a public data series. He opened the market and found $0 supplied, $0 borrowed, no transaction history and Morpho's own not-listed warning. The claim was withdrawn.
Post 7, 2026-07-25. A schema change had quietly started counting the founder wallet in the hedge base, one day after Kerne wrote that the warning would stay until the hedge ran against collateral that actually backs kUSD. He was right. It was corrected, and Kerne refused the easy fix of widening the hedge base to clear the warning.
Post 11, 2026-07-31. Kerne's loss breakers set a $50,000 daily limit against a book of about $1,140, so no threshold in the design protected anyone at genesis size.
Post 19, 2026-08-07. Kerne had described the custody handover as one atomic batch. He replayed it and found the DEFAULT_ADMIN grants had landed earlier in separate transactions, so the Safe and the timelock both held admin for a window in which the delay did not bind. His reconstruction was tighter than ours and the correction was published.
How independent this actually is
He is not Euler staff. He holds no moderator, admin or group role on that forum, and his account was created on 2026-07-17. Kerne can tell you nothing else about who he is, because the forum does not say.
He is one person working from public data, not a firm. He wrote no report and ran no fork tests. The thread is the artifact, and it is the whole artifact.
The thread was opened by Kerne to propose a market, so the agenda was ours even though the questions were not.
He issued no opinion on whether kUSD is safe to hold, and no Kerne surface may imply that he did. His closing line is a condition, not a verdict: nothing further from him until there is new on-chain state to verify.
Two post numbers, 13 and 14, are absent from the public thread. Post 15 opens by apologising for one of them as a draft from another thread pasted by mistake. Kerne has never edited or deleted a post in that thread and has no power to.
What they left open
The canceller seat [open]. Proposer, executor and canceller on the governance timelock are all the same 2-of-3 Safe. The only party who can cancel a scheduled operation is the party who scheduled it. Unchanged as of 2026-08-11.
Queue monitoring [half closed]. Kerne shipped kerne.fi/timelock and kerne.fi/api/timelock on 2026-08-10, which recompute the queue from chain and publish it. That closes the observation half only. It does not create a canceller outside the operator set, and the alert it raises pages Kerne rather than a holder.
The exposure floor [open]. A contract-level cap on how much of the backing may be deployed into the hedge strategy. Not built. It does not bind today because the strategy holds none of the backing, and that is the reason it has not been built, not an argument that it is unnecessary.
The pending-operations check on the mint path [open]. His design: a counter of queued privileged operations that the mint path reverts on, so a pending mint-authority change automatically closes entry while leaving exit open, without a keeper. Not built.
Exit-open as a property [open]. That redemption stays available by construction rather than by operator choice. Not built.
A watchdog registry that re-derives Kerne's corrections before recording them
TokenBrice, maintainer of the pharos-watch stablecoin registry. 2026-06-29 to 2026-08-11.
pharos.watch is an independent stablecoin registry. Kerne has filed six items against its own record there since 2026-06-29, disclosing the affiliation each time, using the maintainer's own data-correction template. Five landed. The sixth landed in half.
The maintainer does not merge Kerne's pull requests. He re-derives the facts himself and lands his own commit, then closes ours as superseded, and he has declined to carry characterizations of ours he did not agree with. That is a functioning error-correction loop with a party who is not us, evidenced by commits in a repository Kerne cannot write to.
We independently reconstructed the transition, landed the revised record in 5eca224823e717d9603d21b895f6439441b78a85 via #825, and verified that commit in production.
Two characterizations of Kerne's he declined to carry, in the same comment
did not carry over the blanket redemption/non-burn methodology claim: the live PSM burns kUSD on redemption, while the two legacy PSMs retain the remaining protocol inventory ... treated skUSD's direct Safe administration as a separate non-upgradeable wrapper surface. Its verified powers do not mint kUSD or change PSM parameters, so we did not describe it as a timelock bypass.
The live mint PSM had moved and MINTER_ROLE on the old one was revoked
423509e6 2026-07-23, update kUSD live PSM authority
2026-07-25
#650
The recorded skUSD address was the retired v1 vault
5a719f49 2026-07-25, record the live Kerne skUSD vault
2026-08-02
#773
The no-third-party-audit notice was stale, and the recorded jurisdiction is unsupportable
5c45e502 2026-08-05, audit notice replaced. The jurisdiction half did NOT land, see below.
2026-08-08
#797
Custody moved behind a 48 hour timelock on 2026-08-06
5eca2248 2026-08-10, record reviewed Kerne timelock handover
Read the right-hand column carefully. Not one of those is a merge of a Kerne pull request. The maintainer re-derived each correction and landed his own commit, then closed ours as superseded.
How independent this actually is
A registry record is a data check, not a security review. Nothing here says anything about whether the contracts are sound.
Kerne initiated every one of these corrections. The independence is in the verification and the disposition, not in the discovery.
He keeps kUSD at pre-launch and not-active by his own criteria, and has not moved it.
What they left open
pharos.watch still records a jurisdiction Kerne does not have [open]. The record carries British Virgin Islands. Kerne has no legal entity, in the British Virgin Islands or anywhere else. That value came from Kerne's own coverage submission in July 2026, where it described an intended structure rather than an existing one, which makes it our error before it is anyone's. We asked for it to be set to null on 2026-08-02 in issue #773. The issue was closed as completed on 2026-08-11 and the field is unchanged as of 2026-08-11.
The correction is filed but not marked verified [open]. Issue #773 still carries his verified: pending label. Kerne does not control that label and is not asking for it to move.
3. audit firm, paid for by Kerne
One completed external audit, paid for by Kerne
Hexens. 2026-07-13 to 2026-07-31.
Fieldwork ran from 2026-07-13. The final report published on 2026-07-31 and covers five contracts pinned to commit 0912c870: kUSD, skUSD, KUSDPSM, KerneVault and esKERNE. Ten findings: none critical, two high, two medium, four low, two informational. Eight fixed, two acknowledged without a code change. All ten are in KerneVault.
Hexens publishes it on hexens.io and lists Kerne on its public report index, so the counts and the scope can be read from a domain Kerne does not control. That is what turns an audit claim into a checkable fact.
Kerne chose this firm and paid the invoice. That is the normal arrangement for an audit and it is worth saying out loud on a page about independence, because it is the one entry here that Kerne bought.
An audit reviews a commit, not a chain, and it is a point-in-time review of five files. Kerne does not describe this code as passed, clean, audited-safe or secure, and will not after any future audit.
What they left open
The live vault does not run the reviewed commit [open]. The live peg stability module and skUSD run commit 0912c870 exactly. The live KerneVault does not: it was deployed from earlier source, so the report's vault findings are open on that bytecode. It holds no user funds, has never issued a share, and takes no deposits until the remediated build is live and verified.
Two findings acknowledged rather than fixed [open]. Two of the ten were acknowledged without a code change. The reasoning on both is published rather than summarised.
The report's own scope links are broken [open]. The five scope links on the Hexens page point at a private repository and return 404 for the public, still true as of 2026-08-11. This is a defect on their page, not on ours. Kerne republished the exact reviewed source at contracts-public/audits/scope/ on 2026-08-03 and handed the auditor the working URLs.
SBSecurity approached Kerne, ran a review nobody asked for, and refused payment twice. They triaged an automated report that claimed 57 findings, including 2 critical and 15 high, down to zero critical, zero high and ten medium, each with a Foundry proof of concept that runs on a clean checkout. Every live figure in their report matched the chain to the cent when Kerne re-read them independently.
Nobody selected them, nobody paid them, and the most useful thing they did was kill 47 findings that a naive automated pass had asserted, including both claimed criticals. The relationship is not deferential in either direction: Kerne rejected one of their ten impact claims on evidence and told them so, because the published backing figure already nets out PSM-held kUSD and says so in prose on /api/por. The underlying mechanism they described is real and worth fixing; the impact they attached to it was not.
The report is not published and is not linked here, because it contains findings that are not fixed. That means a reader cannot check this entry against a primary source the way they can check every other entry here, and it should be weighed accordingly.
The link above is Kerne's public statement about them, not their statement about Kerne. It asserts no outcome: they asked for a testimonial saying the review hardened the code, and Kerne declined, because nothing from the review has shipped.
What they left open
One of their ten findings is a genuine unfixed design bug [open]. It sits in a contract that currently holds nothing, which is the only reason it is inert. It is not described here, because it is not fixed, and describing an unfixed bug in public is the one thing Kerne's disclosure policy forbids. It has to be fixed before that contract is ever funded.
Kerne owes them a written per-finding disposition and has not delivered it [open]. Promised on 2026-08-06, in writing, for early the following week. Not delivered as of 2026-08-11. Kerne's own disclosure policy says that a missed date entitles the person owed to say so publicly and that we will not dispute it, so it is stated here first.
Kerne's own pages on the same subject, which are not independent and are linked here only so the two can be compared: The researcher acknowledgments wall.
5. listing operator, not paid for by Kerne
A listing operator accepted the audit link
DefiLlama. 2026-08-03 to 2026-08-05.
On 2026-08-03 DefiLlama support moved the audits field on the Kerne protocol record from 0 to 2 and populated audit_links with the Hexens report. Their words in the thread: Thanks for the link to the audit. I've updated the listing to show this. Separately, a DefiLlama maintainer merged Kerne's pull request #886 on 2026-08-05, setting auditLinks on the kUSD stablecoin entry.
It counts less than anything else on this page, and it is here mainly so that a reader who sees the 2 knows exactly how it got there.
Kerne asked. This was not unprompted, and a listing operator accepting a link is not a review of anything.
The 2 is not a count of two audits. Kerne has one. It is DefiLlama's convention marker for a listing that carries published audit links: Aave v3, Morpho Blue, Sky and Ethena USDe all show the same 2 with one link each.
The listing does not restate the caveat that the deployed vault predates the reviewed commit, so it is a strictly less complete statement than Kerne's own.
What they left open
DefiLlama still reports no usable price for kUSD [open]. Which is correct, and it is why other registries keep kUSD in a pre-active state. Kerne is not asking any of them to change it.
6. independent researchers, not paid for by Kerne
A researcher-initiated review, published anonymized
A three-person security research team. 2026-06.
In June 2026 a three-person team reviewed Kerne's core contracts on their own initiative, not under any engagement, and sent eight written findings to the disclosure inbox. Kerne assessed every finding against the live source-verified bytecode rather than repository source, sent a full per-finding response, and published the summary.
It is the earliest outside look at the contracts, and one of its findings independently confirmed a real accounting item Kerne had already found itself.
This is the weakest entry on the page and the reason is structural: the published document is Kerne's write-up of somebody else's findings, and none of the three consented to be named, so there is no source outside Kerne's control to check it against. It is listed for completeness, not offered as evidence.
It was a researcher-initiated review, not a firm audit, and Kerne has never described it as one.
What they left open
The researchers are unnamed [open]. By their own silence rather than by Kerne's choice. Kerne asked for consent to name them on 2026-06-29 and would publish the named version if any of them replied.
Kerne's own pages on the same subject, which are not independent and are linked here only so the two can be compared: The audit posture page that carries it.
What is deliberately not on this page
A rating from Credora. One was requested through their public form on 2026-08-09. Nothing has been published, and nothing may be.
A place on the Hindenrank stablecoin board. Kerne emailed them on 2026-08-09. kUSD is not on it.
An audited-by or verified-by badge of any kind. Kerne does not have one, has not applied for one, and would not put one here if it did, because a badge is a summary somebody else wrote and this page is for the primary sources.
Offers to sell Kerne a third-party verification product. Kerne has received them. A quote is not a check, and buying one would not add anything to this page.
Check this page without us
Every entry above links its primary source, and the machine-readable form of this page is the independent_verification object on /facts.json, which carries the same open items rather than a trimmed version of them. The Euler thread is also readable as JSON without an account, which is the cheapest way to confirm that nothing quoted here has been shortened in a way that changes it.
# the whole thread, no account needed, quotes checkable against it
curl -s https://forum.euler.finance/t/1849.json | jq -r '.post_stream.posts[] | "\(.post_number) \(.username)"'
# what this page publishes as machine-readable, open items included
curl -s https://kerne.fi/facts.json | jq '.independent_verification'
If something on this page is wrong, that is a finding and Kerne would rather have it: the disclosure address is on the security page. Corrections to this page are published the same way every other correction is.