Kerne Security
Whitehat Desk
The pre-mortem you run before you commit to an audit.
Before the sweep itself: there is no company here. An engagement is a services agreement with a named co-founder personally, and an established security firm has already contracted with him that way, with no entity anywhere in the document. Engaging Kerne as a subcontractor sets out the counterparty, the novation term and these delivery windows in one page.
DeFi has lost just over $1 billion to exploits in 2026 so far, across more separate incidents than in any full prior year, per DefiLlama's hacks data as of July. And since Code4rena wound down in May, a lot of teams that relied on it for contests and bounty coverage are between security venues while that coverage migrates. The Desk is built to cover that gap.
The Desk is an adversarial pre-mortem on your contracts, run before you commit to a full audit. An audit is a real budget item, generally $40,000 to $100,000 for a DeFi protocol, plus several weeks of calendar you do not get back. Walking into that engagement without knowing what it is going to find is how teams end up paying audit rates to be told about an access-control gap they could have closed in an afternoon.
So this runs first. An independent researcher spends a fixed, agreed number of hours trying to break the contracts you are about to submit, and you get a written report on what an auditor is likely to raise, while the code is still cheap to change. Some teams read it and book the audit with more confidence. Some read it and postpone, because the design is not ready. We would rather tell you the second one before you have paid for the engagement.
To be direct about what this is: an adversarial review, not an audit and not a guarantee. The terms below say exactly what you are and are not getting.
Who it is for
Two kinds of team. The first has an audit booked or budgeted, somewhere in the $40,000 to $100,000 range a DeFi engagement generally runs, and wants to know what it will surface before the clock starts. The second is months away from affording one and does not want to ship blind in the meantime.
The work is the same either way: a researcher spends the agreed hours attacking the contracts you name and writes up what they find. What changes is what you do with the report. A team with an audit booked walks into it having already closed the cheap findings, so the expensive weeks go on the parts that genuinely need them. A team without one gets a written picture of its worst exposure at a price a pre-revenue protocol can clear. In both cases this buys down risk on the way to a full audit rather than standing in for one.
Where the researchers come from
Kerne runs its own bug bounty in public. 13 independent researchers have responsibly disclosed findings to us, and 12 of them are publicly credited by name on our acknowledgments wall, with the finding class, the date, and the current status of each report. That wall is the evidence that this group exists and that we handle disclosure properly. It is the same wall, and the same standard of write-up, that a sweep report is delivered against.
To be precise about what that does and does not mean: being credited on the wall is recognition for a disclosure to Kerne. It is not a statement that the person is on staff, on retainer, or available for your sweep. Researchers are engaged per sweep, with their consent, and each one is free to pass on any piece of work. We do not keep a bench sitting idle, and we will not pretend otherwise to make this page look bigger.
Rather than ask you to take that on trust, the count is published: the Desk's supply side, measured sets out how many researchers have disclosed, what came of their findings, how fast we answered including the windows we missed, and how many have actually agreed to take paid work.
If you are a researcher weighing whether to spend time here, two things you should know before you do.
Desk work pays seventy percent of the client fee in USDC within 72 hours of delivery, and that term is real. What it is not yet is proven: no sweep has been booked through this page, so it has paid a researcher nothing so far. The first booking is the thing that changes that, and we are not going to imply it has already happened.
Kerne's own bug bounty is a separate thing, and it cannot pay a reward today. There are 1,250 USDC of reward commitments already unpaid ahead of any new report, against a balance in the low hundreds of dollars that is read on chain and published live rather than quoted from memory. The figure, the queue, and the dates we hold ourselves to are on the bounty page. Disclosures are still genuinely wanted. Submit one knowing the reward is zero unless we write to you with a figure.
“SpokoDev reviewed Kerne's escrowed-KERNE (esKERNE) exit path and reported a forfeiture-on-exit bypass, which the team fixed in commit 8193babd.”
In the researcher's own words, this "was a focused review of specific paths, not a full audit, and a single finding is never a clean bill of health." An external researcher reviewed this area and we fixed what they reported. It is not an audit and not a security guarantee. Being quoted here is not a statement that this researcher is available for your sweep.
How it works
1. Scope
You send the contracts you want looked at (a repo link or verified addresses) and what you are most worried about. We agree a fixed scope and a fixed price in writing before anyone starts. No open-ended meter.
2. Sweep
One or more independent researchers from the group that has disclosed to Kerne run an adversarial pass against the scoped contracts inside a short, agreed window. They look for the classes of issue that actually lose funds: accounting and supply drift, access-control gaps, oracle and slippage manipulation, reentrancy, and upgrade and admin risk.
3. Report
You get a written report in the same template Kerne uses for its own disclosures: each finding with a severity, a class description, a reproduction where one exists, and a suggested direction. Clear enough to act on, honest about what was and was not covered.
4. Re-check (optional)
If you fix and ask, a researcher will re-check the specific findings against your patched code once, so you can show the fix was verified by the person who found the issue.
Price
Two fixed tiers. Which one applies is settled during scoping, in writing, before any work starts. There is no hourly meter and no scope creep: if the surface turns out to be wider than it looked, we tell you and requote rather than quietly billing more.
2 researchers have given the separate written yes to take paid work. A sweep is still confirmed only once one of them has accepted your specific scope, and the delivery window runs from that acceptance rather than from your payment.
The count, and how it is kept, are on the Desk's supply page.
Focused sweep
$2,500
A small, self-contained contract set: a vault, a staking path, a token and its minter, or a single well-bounded mechanism. This is the common case for a pre-launch protocol.
Up to 12 hours of researcher time.
Report delivered within 5 business days of scope confirmation.
$1,750 of that goes to the researcher.
Buying for a company and need paperwork? Request an invoice with a reference number and payment instructions. No wallet needed to ask.
Booking is optional and fully refundable until scope is confirmed. Scope and price are still agreed with you in writing first, and the delivery window above starts at that agreement, not at your payment. You can also just ask for a scope and pay on delivery.
Extended sweep
$5,000
A wider or more intricate surface: several interacting contracts, an oracle or accounting path with real subtlety, or a system where the interesting failures live between components rather than inside one.
Up to 24 hours of researcher time.
Report delivered within 10 business days of scope confirmation.
$3,500 of that goes to the researcher.
Buying for a company and need paperwork? Request an invoice with a reference number and payment instructions. No wallet needed to ask.
Booking is optional and fully refundable until scope is confirmed. Scope and price are still agreed with you in writing first, and the delivery window above starts at that agreement, not at your payment. You can also just ask for a scope and pay on delivery.
What is included, and how long it takes
- The adversarial pass itself, against the exact contract set named in the written scope.
- A written report: every finding with a severity, a class description, a reproduction where one exists, and a suggested direction.
- One re-check of those specific findings against your patched code, if you fix and ask.
- Coordinated disclosure throughout. Nothing is published without your agreement.
- Delivery inside the window for the tier you picked, counted from scope confirmation: 5 business days for a focused sweep, 10 for an extended one.
What the report actually looks like
Every finding is written up the same way, so you can act on it without a call. One of them, rendered in full:
First depositor can set the share price by donating to the vault
The vault mints shares from the ratio of total assets to total supply. Both are zero before the first deposit, so the first depositor can deposit one wei, transfer tokens straight to the vault address, and move the share price before anyone else arrives.
The next depositor rounds down to zero shares on a deposit that is not zero, and the balance stays with the first account. Nothing here needs a flash loan or a privileged key, and it is reachable by anyone from the moment the vault is deployed.
test/Sweep_FirstDepositor.t.sol, included with the report. Deploys the vault as configured in scope, runs the sequence above, and asserts the second depositor receives zero shares against a non-zero deposit.
Seed the vault at deployment, or hold virtual shares and assets in the conversion so the ratio is never read from an empty pool. Both are established fixes; which one suits you depends on whether the deployment script can be changed at this point.
Open at delivery. Re-checked once against your patch if you fix and ask.
This finding is written for this page as an example of the format. It is not a client's finding and not a redaction of one: the Desk publishes nothing from an engagement without that team's agreement, and the pattern shown here is a textbook one that belongs to no particular protocol. It is the same template as the findings tracker Kerne keeps on its own bugs, which is the closest thing to a work sample we can show you without anyone's permission.
How long it takes, as a commitment
A focused sweep is up to 12 hours of researcher time and the report lands within 5 business days. An extended sweep is up to 24 hours and lands within 10 business days. Those are numbers we agree to in writing, not an average, so you can plan around them.
The clock starts at scope confirmation, which is when the scope and the price are agreed in writing and a researcher has accepted the specific work. That is later than the moment you send the form, and we say so plainly: we engage researchers per sweep rather than keeping a bench sitting idle, so the date we can honestly commit to is the one that runs from a yes. If nobody suitable is free in the window you need, we tell you that instead of booking it.
The hour box and the calendar window sit next to each other on purpose. The box is a ceiling on the work, fixed in writing, so the scope cannot quietly grow on either side once we start. The window is set deliberately wider than the hours require, because a margin we do not need is what makes a date we can hold. Critical findings are sent the day they are found, not held to the report date.
Payment is on delivery of the report, in stablecoin or by invoice. That is the default and it is still the option most teams take. If you already know which tier you want, you can also book it up front in USDC on Base using the button on the tier above, which reserves it and moves you straight to scoping. Either way the sequence is the same: we agree the scope and the price with you in writing, then a researcher accepts the specific work, and only then does the delivery clock start. Money paid before that point is refundable in full, for any reason, without a fee. We would rather return it than hold a booking a team stopped wanting.
If you need it faster than the window above, say so during scoping and we will tell you what is possible and what it costs, only when a researcher has confirmed they can hold the shorter date. We do not publish a rush price we might not be able to staff.
Seventy percent of the fee goes to the researcher who does the work. Kerne keeps thirty percent for coordinating the engagement, standing behind the process, and handling scoping, payment, and delivery. The split favors the researcher on purpose: the work is theirs, and good researchers are the scarce thing. We pay that share in USDC within 72 hours of the report being delivered, not on a 30-day cycle. It is a term for the researcher, and one reason a good one will take a small scoped engagement at short notice.
Standing sweep retainer: $3,500 per month
An audit is a snapshot of the code on the day it was read. What breaks protocols afterwards is usually what shipped next: a new deployment, a parameter change, an admin key that moved. The retainer is for the period after your audit, when the report is done and the code keeps moving.
For teams that want this continuous rather than one-off, we run a standing retainer at $3,500 per month per protocol. Each month a researcher runs a delta pass over what changed since the last one: new deployments, upgrades, parameter and admin changes, and a re-check of anything still open from the previous report. Because it is scoped to the diff it is smaller than a one-off sweep, so it does not carry the 12-hour box or the 5-day window; those apply to the one-off tiers. Each month is scheduled with you rather than run against a fixed business-day window, and invoiced after that month's report is delivered. Same report template, same terms, and the same split in the researcher's favor. Cancel any month. The retainer lane goes live once three protocols are subscribed, so a researcher can commit the recurring time; until then we will tell you where you are in the queue rather than pretend the lane is already running.
On the price, since we would rather explain it than have you guess: seventy percent of it goes to the researcher who runs that month's pass, which is what makes a recurring commitment something a good researcher will hold. Comparable standing security coverage generally starts around $5,000 a month and goes up from there, so this still sits under that. It is not an attempt to be the cheapest option on the market. We raised it from $1,500 in July 2026 because the researcher share at the old number was less than what we had already committed to pay for the work.
If you need something other than a sweep, we will route you
Sometimes the honest answer is that a sweep is not what you need. In that case we would rather point you at the right venue than sell you the thing we happen to have. For a full private audit we can make a warm introduction to the firm running Kerne's own audit, and if that turns into a paying engagement Kerne is paid by them. You pay us nothing for the introduction, and we add nothing to what they quote you. For a competitive contest or a standing bug bounty the venue is Sherlock, where we have no agreement, have never been a customer, and may or may not qualify to claim a referral fee at all. The full disclosure, including what we cannot publish and the cases where we will tell you not to bother, is on the page that lays the routes side by side.
When a researcher is the one who sourced that lead, Kerne splits what it is paid with them fifty-fifty. And any researcher who approaches a team on our behalf is required to disclose the referral relationship up front, before anything else. We would rather lose a lead than have someone find out later that a recommendation was paid.
A full audit may also cost less than you expect. The firm we would route you to takes part in the Ethereum Foundation and Areta Audit Subsidy Program, which can cover up to 30 percent of an audit for teams it accepts into a cohort. We will point you to the application when we make the introduction. It lowers your cost, not our involvement, and it does not change your terms with the firm.
Terms, in plain language
Read these before engaging. They are the whole deal, and they are written to be honest rather than reassuring.
- This is an adversarial sweep, not an audit. It is a time-boxed, best-effort review by independent researchers. It is not a formal audit, not a certification, and not a substitute for one. Teams handling real user funds should still get a full audit.
- A clean sweep is not a guarantee of safety. Finding nothing, or finding only what is listed, does not mean the code is free of vulnerabilities. Security reviews reduce risk; they never eliminate it. No result from this Desk should be presented as proof that a protocol is safe.
- No warranty and no liability for missed issues. The sweep is provided as is. Neither Kerne nor any participating researcher warrants that the review is complete or that all issues have been found, and neither is liable for any loss arising from an issue the sweep did not surface. Scope, price, and these terms are confirmed in writing before any work begins.
- Independent researchers, coordinated by Kerne. Kerne introduces and coordinates the work and handles payment; the review is performed by independent researchers. Kerne is not vouching for, employing, or warranting any individual researcher's work, and no researcher is named publicly without their consent.
- Coordinated disclosure. Findings are shared privately with the requesting team first. Nothing is published by Kerne or the researcher without the team's agreement.
- We book only what we can staff, and the delivery window is a commitment. A sweep is confirmed once a researcher has accepted the specific scope, not when you submit the form, and the published window runs from that confirmation: 5 business days for a focused sweep, 10 for an extended one. If nobody suitable is free in your window we will tell you that instead of taking the work and being late.
- If you pay up front, that money is yours until scope is confirmed. Booking a tier on this page is optional and it is not the same as buying a sweep: scope and price are still agreed with you in writing afterwards, and the delivery clock still starts at that agreement rather than at your payment. Until scope is confirmed you can ask for the full amount back for any reason, including changing your mind, and we return it without a fee and without a discussion. If scoping shows you picked the wrong tier we requote and either refund the difference or invoice it, and if you do not like the requote you take the whole amount back instead. After scope is confirmed the cancellation remedy in the next term is what applies. Paying up front never buys you a place in a queue ahead of anyone, and it never changes what the sweep is or what these terms say.
- What happens if we are late, and the limit of what we owe. The window pauses for anything we are waiting on from you: access, a question we asked, or a change you make to the code in scope after we confirmed it. If the researcher who accepted your sweep has to step away, we tell you the same day, and you choose between a new date with someone else or cancelling at no cost. Anything genuinely outside our control extends the window by the time it costs, and we tell you as it happens. If we still miss a date that was ours to hold, you can cancel before we deliver and owe nothing. That, and a refund of anything already paid, is the whole of what you can recover from us for a late report: neither Kerne nor any researcher is liable for lost profit, a missed launch or listing, the cost of buying the work elsewhere, or any other indirect loss, and our total liability on any engagement is capped at the fee for that engagement.
Where Kerne itself stands
Kerne has had one external audit and it is finished. Hexens delivered its final report on July 31, 2026, and it is published in full and unedited, with our answer to each of its ten findings beside it. We still will not call this code passed or clean: an audit reads a commit, not a chain, and the live vault was deployed from earlier source, so the report's vault findings stand open on it and deposits into it are closed. We say that on every surface, and it would be absurd to leave it off the one where we sell security work.
We think it is the reason to take the Desk seriously rather than a reason not to. Our own findings, including the ones that were embarrassing, are published with dates and status on the acknowledgments wall and the findings tracker. You can judge how we handle a disclosure before you trust us with yours.
When you should skip this and get a full audit
If you are about to hold serious user deposits, if a counterparty or listing requires an audit, or if your design is novel enough that it needs weeks of scrutiny rather than days, get a full audit. We would rather tell you that than sell you a sweep you should not buy. If a full engagement is the right call, we can point you to the firm running Kerne's own audit.
Request a sweep
Tell us what the contracts do and what worries you. We come back with a scope, a fixed price, and a window, and nothing starts until you agree to those in writing. If you are a researcher who wants to take sweeps through the Desk, switch the first option and send us a sample of prior work.