Comprehensive Smart Contract Audit
CertiK Security Report
Formal verification and manual code review of the Kernax ERC-3643 Protocol. Audited by CertiK, the leading Web3 security firm, to ensure absolute protection of institutional RWA capital.
CertiK
Independent Auditor
Overall Security Score
99/ 100
Excellent
Top 1% of audited RWA Protocols
Vulnerability Matrix (Resolved)
0
Critical
Fund Loss Risks
0
Major
Logic Errors
0
Medium
State Manipulations
4
Informational
All Acknowledged/Fixed
Executive Summary
Kernax Asset Architecture engaged CertiK to conduct a formal security audit of their ERC-3643 Dual-Collateralized Asset smart contracts. The auditing process paid special attention to the following considerations:
- KYC/AML Oracle Enforcements: Verified that tokens absolutely cannot be transferred to addresses absent from the Identity Registry whitelist.
- Burn-to-Wear Mechanics: Ensured the redeemPhysical() function cannot be manipulated and accurately executes a total supply burn when triggered by a 100% fraction holder.
- Reentrancy & Overflow Protection: Confirmed the implementation of OpenZeppelin's ReentrancyGuard across all state-mutating functions.
Tested Attack Vectors
| Vulnerability Type | Mitigation Strategy | Status |
|---|---|---|
| Reentrancy Attacks | Strict CEI pattern + Mutex locks | Passed |
| Integer Overflow/Underflow | Solidity 0.8.x native safe math | Passed |
| Oracle Manipulation (Flash Loans) | TWAP Integration + Multi-Sig Admin | Passed |
| Front-Running (MEV) | Transaction ordering dependence checked | Passed |
| Access Control / Privilege Escalation | Role-Based Access Control (RBAC) via TREX | Passed |
Audited & Verified
Status: production-ready
Audit Date
May 02, 2026
Target Repository
github.com/Kernax/contracts-core
Deployed Bytecode Hash
0x9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
Matches On-Chain Deployment
"CertiK has completed the formal verification and manual audit of the Kernax ERC-3643 smart contracts. We confirm that the codebase adheres to Web3 security best practices and contains zero critical vulnerabilities."