Dossier

Shivank Kashyap

Solidity Developer — Smart Contract Engineer


Photographs

LinkedIn profile photo — Shivank Kashyap
LinkedIn profile photo — Shivank Kashyap

Charges


What this defendant knew

As a Solidity developer at ZeroLend, Kashyap possessed direct technical knowledge of: (1) the smart contract architecture including the PT-LBTC oracle implementation that was exploited, (2) the May 2024 Blast exploit that revealed the vulnerability class, (3) the decision not to patch the identical vulnerability on the Base deployment, (4) the protocol's true centralization despite decentralization marketing. A Solidity developer is the single most technically positioned role to identify, flag, and patch the oracle vulnerability that caused both the $5.5M Blast loss (May 2024) and the $371K Base loss (Feb 2025).


Intent indicators


Public identity traces


Prosecution's theory

Shivank Kashyap's culpability is elevated by his technical position. A Solidity developer is not a peripheral figure — he is the person who writes, reviews, and is responsible for the exact code that contained the PT-LBTC oracle vulnerability. The prosecution's theory: (1) the vulnerability was known after the May 2024 Blast exploit, (2) a Solidity developer would have been tasked with or aware of any patch effort, (3) the Base deployment was never patched — a decision that could not have occurred without the engineering team's knowledge or acquiescence, (4) his continued silence during the 16-month concealment period, while the deposit UI stayed open and users kept losing funds, makes him an active participant in the deception. Engineers who know their code is vulnerable and choose silence over a patch are not mere accessories — they are co-conspirators whose technical enablement was essential to the fraud.


Incriminating exhibits


Proofs & Evidence Collection

The following evidentiary items are preserved in this repository. Each item is timestamped, verifiable on public block explorers or web archives, and subpoena-ready for law enforcement. File paths reference the local evidence archive; URLs link to live public sources.

LinkedIn profile — Solidity Developer at ZeroLend

Shivank Kashyap's LinkedIn profile (linkedin.com/in/shivank11) identifies him as a Solidity Developer for ZeroLend. This establishes his direct technical role: he wrote or maintained the smart contracts containing the PT-LBTC oracle vulnerability that was exploited on Blast (May 2024, $5.5M) and Base (Feb 2025, $371K). As the Solidity developer, he is the single most technically responsible individual for the vulnerable code.

🔗 View source →

LinkedIn profile photo verification

LinkedIn profile photo of Shivank Kashyap extracted via public LinkedIn profile. Confirms human identity behind the Solidity developer role. Preserved for law enforcement identification and cross-referencing with any ZeroLend GitHub commit authorship.

📁 team/shivank/linkedin-photo.jpg

PT-LBTC oracle vulnerability — code responsibility

The exploited vulnerability was in the PT-LBTC oracle implementation within ZeroLend's smart contracts. As Solidity developer, Kashyap had direct responsibility for this code. The identical flaw existed on both Blast and Base; the team patched Blast after the May 2024 exploit but left Base vulnerable for 10 more months. A Solidity developer would have been central to any patch decision.

📁 team/forensic-may2024-exploit-separate.json

May 2024 Blast exploit — prior knowledge evidence

The May 11, 2024 Blast chain exploit ($5.5M, PT-LBTC oracle manipulation, flagged by PeckShield) established that the engineering team — including the Solidity developer — knew the vulnerability class. The team responded on Blast (paused market, offered 10% bounty, commissioned audits) but never patched Base. This is the strongest single piece of evidence for engineering-team prior knowledge.

📁 team/forensic-may2024-exploit-separate.json

Admin role and ACL control — engineer access

Complete ACLManager role assignment log across all chains. As a Solidity developer, Kashyap would have had knowledge of which addresses held DEFAULT_ADMIN_ROLE and the ability to pause, freeze, or adjust borrow caps. The absence of any such protective action after the Feb 2025 exploit — for 16 months — was an engineering-team decision.

📁 team/forensic-admin-role-events.json

Deployer infrastructure and code provenance

Analysis of deployer wallets, deployment scripts, and smart contract provenance across all ZeroLend chains. A Solidity developer's work product is directly visible in the deployed bytecode. Cross-referencing deployed contract code with GitHub commit history can establish which engineer wrote the vulnerable oracle implementation.

📁 team/forensic-deployer-tracing.json

Old deployments and audit analysis

Audit of old deployment scripts, constructor parameters, and the audit reports (Mundus, Quill, Halborn) commissioned after the May 2024 Blast exploit. A Solidity developer would have been the recipient of these audit reports and responsible for implementing any recommended fixes — the persistence of the Base vulnerability suggests audit findings were not acted upon.

📁 team/forensic-old-deploys-audits.json

GitHub address extraction and commit authorship

Extraction of Ethereum addresses and commit authorship from ZeroLend GitHub repositories. Cross-referencing Kashyap's identity with commit metadata can establish which specific commits and which vulnerable code paths he authored — directly linking him to the exploited code.

📁 team/forensic-github-addresses.json