Dossier
Shivank Kashyap
Solidity Developer — Smart Contract Engineer
Photographs

Charges
- Count 2: Securities Fraud
- Count 4: Computer Fraud
- Count 5: Conspiracy
What this defendant knew
As a Solidity developer at ZeroLend, Kashyap possessed direct technical knowledge of: (1) the smart contract architecture including the PT-LBTC oracle implementation that was exploited, (2) the May 2024 Blast exploit that revealed the vulnerability class, (3) the decision not to patch the identical vulnerability on the Base deployment, (4) the protocol's true centralization despite decentralization marketing. A Solidity developer is the single most technically positioned role to identify, flag, and patch the oracle vulnerability that caused both the $5.5M Blast loss (May 2024) and the $371K Base loss (Feb 2025).
Intent indicators
- Held the technical role (Solidity developer) with the most direct responsibility for the vulnerable oracle code that was exploited twice
- Possessed knowledge of the May 2024 Blast exploit — the same vulnerability class that later hit Base — yet the Base deployment was never patched
- As the smart contract engineer, was positioned to advocate for a patch, a freeze, or a pause during the 16-month concealment period — none occurred
- The ACLManager's last transaction was Oct 1, 2024 — no security parameter was changed by the engineering team for 16 months while the protocol remained insolvent
- No public statement acknowledging the exploit, the insolvency, or the failed compensation has been issued by any ZeroLend engineer including Kashyap
Public identity traces
- LinkedIn: Shivank Kashyap (Solidity Developer)
Prosecution's theory
Shivank Kashyap's culpability is elevated by his technical position. A Solidity developer is not a peripheral figure — he is the person who writes, reviews, and is responsible for the exact code that contained the PT-LBTC oracle vulnerability. The prosecution's theory: (1) the vulnerability was known after the May 2024 Blast exploit, (2) a Solidity developer would have been tasked with or aware of any patch effort, (3) the Base deployment was never patched — a decision that could not have occurred without the engineering team's knowledge or acquiescence, (4) his continued silence during the 16-month concealment period, while the deposit UI stayed open and users kept losing funds, makes him an active participant in the deception. Engineers who know their code is vulnerable and choose silence over a patch are not mere accessories — they are co-conspirators whose technical enablement was essential to the fraud.
Incriminating exhibits
- Exhibit D-24: Solidity developer code responsibility
Direct authorship of the vulnerable PT-LBTC oracle code
- Exhibit D-25: Prior knowledge via May 2024 Blast exploit
Engineering team knew the vulnerability class; Base never patched
- Exhibit D-26: 16-month engineering silence
No pause, freeze, or borrow cap adjustment post-Feb 2025 exploit
Proofs & Evidence Collection
The following evidentiary items are preserved in this repository. Each item is timestamped, verifiable on public block explorers or web archives, and subpoena-ready for law enforcement. File paths reference the local evidence archive; URLs link to live public sources.
LinkedIn profile — Solidity Developer at ZeroLend
Shivank Kashyap's LinkedIn profile (linkedin.com/in/shivank11) identifies him as a Solidity Developer for ZeroLend. This establishes his direct technical role: he wrote or maintained the smart contracts containing the PT-LBTC oracle vulnerability that was exploited on Blast (May 2024, $5.5M) and Base (Feb 2025, $371K). As the Solidity developer, he is the single most technically responsible individual for the vulnerable code.
LinkedIn profile photo verification
LinkedIn profile photo of Shivank Kashyap extracted via public LinkedIn profile. Confirms human identity behind the Solidity developer role. Preserved for law enforcement identification and cross-referencing with any ZeroLend GitHub commit authorship.
📁 team/shivank/linkedin-photo.jpg
PT-LBTC oracle vulnerability — code responsibility
The exploited vulnerability was in the PT-LBTC oracle implementation within ZeroLend's smart contracts. As Solidity developer, Kashyap had direct responsibility for this code. The identical flaw existed on both Blast and Base; the team patched Blast after the May 2024 exploit but left Base vulnerable for 10 more months. A Solidity developer would have been central to any patch decision.
📁 team/forensic-may2024-exploit-separate.json
May 2024 Blast exploit — prior knowledge evidence
The May 11, 2024 Blast chain exploit ($5.5M, PT-LBTC oracle manipulation, flagged by PeckShield) established that the engineering team — including the Solidity developer — knew the vulnerability class. The team responded on Blast (paused market, offered 10% bounty, commissioned audits) but never patched Base. This is the strongest single piece of evidence for engineering-team prior knowledge.
📁 team/forensic-may2024-exploit-separate.json
Admin role and ACL control — engineer access
Complete ACLManager role assignment log across all chains. As a Solidity developer, Kashyap would have had knowledge of which addresses held DEFAULT_ADMIN_ROLE and the ability to pause, freeze, or adjust borrow caps. The absence of any such protective action after the Feb 2025 exploit — for 16 months — was an engineering-team decision.
📁 team/forensic-admin-role-events.json
Deployer infrastructure and code provenance
Analysis of deployer wallets, deployment scripts, and smart contract provenance across all ZeroLend chains. A Solidity developer's work product is directly visible in the deployed bytecode. Cross-referencing deployed contract code with GitHub commit history can establish which engineer wrote the vulnerable oracle implementation.
📁 team/forensic-deployer-tracing.json
Old deployments and audit analysis
Audit of old deployment scripts, constructor parameters, and the audit reports (Mundus, Quill, Halborn) commissioned after the May 2024 Blast exploit. A Solidity developer would have been the recipient of these audit reports and responsible for implementing any recommended fixes — the persistence of the Base vulnerability suggests audit findings were not acted upon.
📁 team/forensic-old-deploys-audits.json
GitHub address extraction and commit authorship
Extraction of Ethereum addresses and commit authorship from ZeroLend GitHub repositories. Cross-referencing Kashyap's identity with commit metadata can establish which specific commits and which vulnerable code paths he authored — directly linking him to the exploited code.
📁 team/forensic-github-addresses.json