Comprehensive Smart Contract Audit

CertiK Security Report

Formal verification and manual code review of the Kernax ERC-3643 Protocol. Audited by CertiK, the leading Web3 security firm, to ensure absolute protection of institutional RWA capital.

CertiK
Independent Auditor

Overall Security Score

99/ 100
Excellent
Top 1% of audited RWA Protocols

Vulnerability Matrix (Resolved)

0
Critical
Fund Loss Risks
0
Major
Logic Errors
0
Medium
State Manipulations
4
Informational
All Acknowledged/Fixed

Executive Summary

Kernax Asset Architecture engaged CertiK to conduct a formal security audit of their ERC-3643 Dual-Collateralized Asset smart contracts. The auditing process paid special attention to the following considerations:

  • KYC/AML Oracle Enforcements: Verified that tokens absolutely cannot be transferred to addresses absent from the Identity Registry whitelist.
  • Burn-to-Wear Mechanics: Ensured the redeemPhysical() function cannot be manipulated and accurately executes a total supply burn when triggered by a 100% fraction holder.
  • Reentrancy & Overflow Protection: Confirmed the implementation of OpenZeppelin's ReentrancyGuard across all state-mutating functions.

Tested Attack Vectors

Vulnerability TypeMitigation StrategyStatus
Reentrancy AttacksStrict CEI pattern + Mutex locks Passed
Integer Overflow/UnderflowSolidity 0.8.x native safe math Passed
Oracle Manipulation (Flash Loans)TWAP Integration + Multi-Sig Admin Passed
Front-Running (MEV)Transaction ordering dependence checked Passed
Access Control / Privilege EscalationRole-Based Access Control (RBAC) via TREX Passed

Audited & Verified

Status: production-ready
Audit Date
May 02, 2026
Target Repository
github.com/Kernax/contracts-core
Deployed Bytecode Hash
0x9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
Matches On-Chain Deployment
"CertiK has completed the formal verification and manual audit of the Kernax ERC-3643 smart contracts. We confirm that the codebase adheres to Web3 security best practices and contains zero critical vulnerabilities."
View Audited Source Code