Updated Monday, June 29, 2026

#ZeroLend#TinyHumans#Fraud

Zero To Tiny

The team didn't get hacked. They migrated.

ZeroLend was never a lending protocol. It was a vessel. The founders copied technical assets from Radiant Capital — itself later rekt for $53M in October 2024 — wrapped them in marketing, filled the system with mercenary TVL, then drained it. When the heat came, they didn't fix it. They stayed silent for sixteen months, extracted what was left, promised compensation that never came, and moved to a new project called TinyHumans. Only now — under sustained pressure — have they returned to dribble back partial refunds in illiquid tokens worth a fraction of what was deposited. This is the playbook, and we have every transaction.

So who's really running the con — the hacker, or the team that built the door and left it unlocked?


Déjà Vu in Eighteen Days

May 11, 2024: Blast chain, $5.5M, same PT-LBTC oracle manipulation. PeckShield flagged it. The team responded — paused the market, offered a 10% bounty, commissioned audits. They knew the vulnerability class.

Eighteen days before that, the same flaw was already live on Base. They never patched Base.

If you discover your front-door lock is broken, do you leave the back door the same way?


The Audit Salad

ZeroLend forked Radiant Capital — an Aave v3 derivative built for cross-chain. DeFiLlama's adapter for ZeroLend is literally aave.ts. The audit logos on the site (Mundus, Quill, Halborn) were camouflage while the protocol ran insolvent.

You don't hire three auditors to prove you're safe. You hire three auditors to look safe.

And when the logos start mattering more than the code, who's the auditor really working for?


February 23, 2025 — Zero To Lend

0x218C572b1Ab6065D74bEbcB708a3f523D14F7719. Fresh wallet, funded that day via Railgun. 38.81 ETH in, 35.58 ETH through Pendle/Odos to acquire PT-LBTC collateral, then three borrows in 45 minutes — 0.953 LBTC, 1.477 LBTC, 1.493 LBTC. 3.92 LBTC. ~$371K. Gone through Aerodrome, Across, and into Hyperliquid before anyone could blink.

Who times a forty-five-minute heist on a wallet they minted that morning, with capital routed through a privacy pool, unless they already knew the door was unlocked?


The Zombie Market

The market stayed open. For sixteen months. The deposit UI accepted new funds while the protocol was insolvent. Discord moderators told users the issue was "high utilization," "maintenance," a "UI issue." The ACLManager's last transaction was October 1, 2024. No setReserveFreeze. No setBorrowCap. No pause.

A protocol that's been drained but keeps the deposit button lit — is that really negligence, or is that the business?


The Silent Extraction

April 27, 2025 — two months after the exploit — a Gnosis Safe appears: 0x0f2876396a71fe09a175d97f83744377be9b6363. Created by capstack.eth(0x3fB00C...7558), funded from a Binance KYC account.

The Safe deposited 0.494 LBTC on June 21, 2025 — the only post-exploit depositor — then extracted 0.766 LBTC via Chainlink CCIP, automated by Gelato, while the team publicly said they were "working diligently to trace and recover funds." $291K moved.

Working diligently — with a stopwatch and a bridge.


The Empty Promise

February 16–17, 2026. Under shutdown pressure, the team announced "partial refunds" to Base LBTC depositors, funded by a Linea airdrop allocation. One hundred and twenty-six days later: zero victims received anything. On-chain, 71.8% of the ZERO token went to ten concentrated wallets. 1.4% showed any victim-compensation pattern.

The token itself had collapsed 94.7% from its TGE-day ATH — $0.001229 to $0.0000658 — so even the promised compensation was denominated in dust.

A promise made in a dead token, to people you'd already robbed, on a timeline you never started.


UPDATE — The Wind-Down

June 24–25, 2026 — Deadshotryker returns to Discord

Sixteen months of silence, and now — under sustained victim pressure — the team is suddenly active again. Deadshot Ryker reappeared in the ZeroLend Discord and began posting a live wind-down: "Most funds have been withdrawn. We're now going to start force liquidating borrowers so that the remainder of funds can be withdrawn." Partial refunds have started — not in the promised form, but as airdropped mstETH + ZRC dropped into wallets with no on-site balance, routed through the Zircuit bridge and EigenPie withdrawal queue.

The admissions are on the record now. On Base LBTC: "We have partial recovery... we're looking at a partial refund 1–2 weeks from now... 30% roughly (estimated), 30–40%." The same "1–2 weeks" timeline they have used since February 2026. One depositor watched 17 ETH of stated balance return as 8 ETH, told the rest was "overinflated because of the interest rates." Another was simply informed their Zircuit WETH was "totally worthless as it's liquidated."

When a victim said "stop the bs, you guys have promised this many times with the same timeline," Deadshot Ryker's answer was an admission: "Yes I know. Sorry on that. We have been genuinely delayed. We've moved onto other things hence couldn't get time to sort this out." The other things are TinyHumans. And when a depositor tagged Deadshot Ryker, another user corrected them: "you tagging the wrong acc, real owner is @enamakelbut he won't reply anymore here" — the two-founders-one-man structure, confirmed again by the community in real time.

Meanwhile, on the TinyHumans Discord, the team is actively banning anyone who mentions ZeroLend or asks where their withdrawal went. Suppression on the new project, a fire-sale liquidation on the old one. The protocol is being "wound down by next week or so (tentative)" — borrowers force-liquidated market by market, lenders handed illiquid collateral on a chain whose liquidity has "gone to almost 0," and told to bridge it out themselves.

A refund you have to chase across three bridges, in a token worth a fraction of what you deposited, from a team that admits it was too busy with the next project to give you back the last one.

The offer was made. The answer was a threat.

A fair off-ramp was on the table: make the victims as whole as possible — a genuine, good-faith, best-effort recovery, real value, a real timeline, full transparency — and this story would have been finished. This page would have become an exoneration instead of an indictment. That offer stood.

Instead, Deadshot Ryker made contact and chose to threaten. Not to settle, not to commit to a timeline — to intimidate. The reading is simple: the "1–2 weeks" and "30–40%" were never a plan, they were a stall. The strategy is, and has always been, to buy time.

So the posture changes. Counsel is now drafting a formal report to the Dubai eCrime unit with the complete evidentiary record — on-chain trails, identity attribution, the documented admissions, and the threat itself. The off-ramp is still open: process the refunds in good faith and the record will reflect it. But stalling and intimidation are no longer met with patience. They are met with a filing.

June 27: A Polished Schedule, Privately Backed by Threats

The day after the threats, an official, lawyer-flavoured announcement appeared in the ZeroLend Discord announcement channel. Calm, structured, full of dates — "the majority of assets have now been withdrawn," oracle issues "resolved" on Ethereum, zkSync and Zircuit, and a tidy wind-down schedule:

Every date carries the same escape hatch it always has: "these dates are our current target timeline and may be adjusted." Blame is pre-assigned to "factors outside of the protocol's direct control" — oracle infrastructure, RPC degradation, "chain instability... (Zircuit especially)." The collateral is still illiquid. The borrowers are still force-liquidated. The lenders are still told to bridge dust out themselves.

We are not impressed, and we do not believe it.

A team that threatens a complainant in private and posts a polished, blameless schedule in public is not two different teams — it is one strategy with two faces. The announcement is not evidence of good faith. It is evidence of presentation. The same "1–2 weeks," the same "subject to timelock," the same "outside our control," now in nicer paragraphs.

We will believe it when victims' wallets hold real, liquid value — not collateral dust on a dead chain, not a screenshot of a schedule. Threaten on one side and reassure on the other, and the reassurance counts for nothing. The clock runs on delivery, not announcements. The eCrime report does not pause for a paragraph; it pauses for refunds that actually land.

We Are Watching the Wallets

This is not a matter of taking anyone's word. We hold eleven confirmed victim addresses — real depositors, real losses — and every one of them is being monitored on-chain. The moment any effective reimbursement lands in real, liquid value, we will see it, timestamp it, and record it here. The ledger is public; there is nowhere to claim a refund that the chain does not confirm.

And the number is growing. Victims are coming forward — reaching out directly on Telegram, sharing their wallets, their deposits, and their losses. What started as a forensic trace is becoming a coordinated case file built by the people who were actually robbed. Eleven wallets today, and counting. If you lost funds, you are not alone, and your address strengthens the record.

It is no longer one voice. Two of the claimants who came forward and provided their addresses for verification have offered to co-file the Dubai eCrime report — named complainants, with documented losses, willing to put their names to the filing. That changes its weight entirely: a single researcher's dossier becomes a multi-party criminal complaint from identified victims. A solo post is easy to dismiss. A coordinated filing by named depositors is not.

📣 Dubai residents with a UAE Pass — please come forward.

The subject self-locates in Dubai, which puts this squarely within the jurisdiction of the Dubai Police eCrime unit. If you are a victim, live in the UAE, and hold a UAE Pass digital identity, your participation materially strengthens the filing — it lets the complaint be lodged through the official eCrime channel by a verified local complainant, exactly the standing the authorities act on fastest. Reach out on Telegram. Your status and details stay between you and counsel.

As of today, against those eleven addresses: zero effective reimbursement. Not a partial. Not a token gesture. Nothing that converts to the value these people deposited. Collateral dust airdropped onto a dead chain is not a refund — it is a screenshot waiting to be called one.

And note why any of this is happening at all. The wind-down did not begin out of conscience. It began because they were exposed. For sixteen months the deposit button stayed lit and the team stayed silent; the activity, the announcements, the schedule — all of it started only once the evidence was public and the names were attached. They are not moving because they want to make victims whole. They are moving because they were caught.

And the hardest part to stomach: by the time a fraction of dust trickles back, they have almost certainly already profited — extracted, migrated, and funded the next project — on money that was never theirs. A partial refund of what you took, years late, under legal pressure, is not redemption. It is a rounding error on the proceeds.


Enamakel = Deadshotryker

Old databases listed two founders: Steven Enamakel and Deadshot Ryker. They are one person. We have the proofs and the pictures. Enamakel — @senamakel on X, senamakel on GitHub, "Creator @ ZeroLend" on LinkedIn — controlled 97% of the ZERO supply from a single wallet (0x9FA7...429e) while marketing the protocol as "decentralized."

He held the deployer keys across ten chains (0x0F6e98...289d). He never transferred governance to the community.

Two founders, one man, and a 97% lie.


Zero To Tiny

The team didn't disappear. They relocated. @tinyhumansai / OpenHuman is Steven Enamakel's new project — "Chef Buildooor @tinyhumansai" reads his X bio today. Same pattern, new label.

This is what bad actors cost the entire industry: every silent exit scam, every drained-then-abandoned protocol, every "decentralized" lie erodes the trust that legitimate builders depend on. When founders can drain their own protocol, hide for sixteen months, and launch a fresh "AI" project the next week, the reputational damage is paid by everyone in DeFi — not just the users who lost money.

The victims of the next version of this team haven't deposited yet.


A Formal Report Is Being Filed

This is not a vigilante post. The on-chain trail is preserved, timestamped, and verifiable on public block explorers. Counsel is now drafting a formal report to the Dubai eCrime unit with the complete evidentiary record — and parallel notice to law enforcement in the United States, Canada, and India. After a good-faith off-ramp was answered with threats and continued stalling, the matter moves from publication to prosecution.

The Binance KYC trail to capstack.eth is the single highest-value lead. The Linea allocation ledger, the Discord archive, the deployer hierarchy, the documented June 2026 admissions, and the threat itself — all subpoena-ready and attached to the filing.

The blockchain remembers. The threats were documented. The report is being filed.


Credits

Sources: rekt.news, CoinDesk (Omkar Godbole, 2026-02-17), The Block, Basescan, Etherscan, Arbiscan, Lineascan, DeFiLlama, CoinGecko, GitHub (zerolend org), Discord archive, PeckShield (May 2024). Compiled by an independent forensic researcher. REKT serves as a public platform for anonymous authors.


⚠ WANTED

FOR CONSPIRACY, WIRE FRAUD, SECURITIES FRAUD, COMPUTER FRAUD

Every person named below is cited by verifiable public record. Each links to a full dossier. All names cleared for publication by counsel.

Steven EnamakelGRADE B

Steven Enamakel

aka @senamakel, @semamakel (secondary GitHub)

Dubai, UAE

Creator, Founder — Primary Beneficiary

Principal

Full dossier →
deadshotrykerGRADE A

deadshotryker

aka Deadshot Ryker, confirmed alias of Steven Enamakel per user-provided dox

Dubai, UAE

Operational Lead, Discord Administrator, Public Face During Concealment

Principal

Full dossier →
NO
PHOTO
GRADE A

capstack.eth

aka ENS operator 0x3fB0...7558, Safe creator

Coordinated Extraction Infrastructure Operator

Co-conspirator

Full dossier →
Gafoor KhanGRADE B

Gafoor Khan

aka Gafoor K, Gafoor Khan Hafiz Khan

India / UAE (Chess.com: IN, LinkedIn: AE, Duolingo: Hindi)

Co-Founder, Technical Architect — Deployer Infrastructure

Co-conspirator

Full dossier →
NO
PHOTO
GRADE B

Brody

aka iambrody_zerolend

Discord Moderator, "Refund Status" Admitter

Aider/Abettor

Full dossier →
Evidence AdogaGRADE B

Evidence Adoga

aka Evhydo, @_Evhydo

Nigeria (WhatsApp +234)

Discord Moderator, Community Manager — Concealment Participant

Aider/Abettor

Full dossier →
Pooja KhannaGRADE C

Pooja Khanna

India (probable)

Claimed Co-Founder (Self-Proclaimed)

Accessory After the Fact

Full dossier →
Ankita SontakkeGRADE C

Ankita Sontakke

India (probable)

Product Marketer — Concealment Enabler

Accessory After the Fact

Full dossier →
Tanya VargheseGRADE C

Tanya Varghese

India (probable)

Community Manager — User-Facing Deception

Accessory After the Fact

Full dossier →
ShivamGRADE B

Shivam

aka SilentHex (GitHub)

India (probable, zerolend.xyz email)

Engineer — Code Contributor during Vulnerability Preservation

Accessory After the Fact

Full dossier →
Nikhil BajajGRADE B

Nikhil Bajaj

aka oxoxDev (GitHub), nikhilbajaj31 (GitHub alt)

Abu Dhabi, UAE / Pune, Maharashtra, India

Engineer — Dual GitHub Accounts, Code Contributor

Accessory After the Fact

Full dossier →
NO
PHOTO
GRADE C

Dan / Lendlord

aka Discord moderators (silent post-complaint)

Discord Moderators — Gatekeepers During Concealment

Accessory After the Fact

Full dossier →
Kunal KaraniGRADE C

Kunal Karani

aka kunalkarani

India (Calendly: Asia/Kolkata, Chess.com: IN, Duolingo: Hindi)

Developer — Technical Contributor

Accessory After the Fact

Full dossier →
Shivank KashyapGRADE B

Shivank Kashyap

India (probable)

Solidity Developer — Smart Contract Engineer

Co-conspirator

Full dossier →
Manjit SinghGRADE C

Manjit Singh

India (probable)

ZeroLend Team Member — Engineer / Operations

Accessory After the Fact

Full dossier →
Pranshu JainGRADE C

Pranshu Jain

aka pranshu0x

India (probable)

ZeroLend Team Member — Engineering / Operations

Accessory After the Fact

Full dossier →
Dhruv PGRADE C

Dhruv P

India (probable)

ZeroLend Team Member — Operations / Engineering

Accessory After the Fact

Full dossier →