Chainlink released CCIP 2.0 on September 28, letting companies add their own security checks to cross-chain transfers on top of its default 16-operator verifier network. The upgrade follows April's $292 million Kelp DAO hack, which exploiters linked to North Korea's Lazarus Group carried out after tricking a bridge that relied on a single verifier.
Chainlink released Cross-Chain Interoperability Protocol (CCIP) 2.0 on Monday. The launch comes five months after a rival bridge's exploit exposed the risks of relying on a single verifier. The upgrade lets companies layer their own security checks on top of Chainlink's default protections when moving tokens and messages between blockchains.
What changed in CCIP 2.0
The new cross-chain bridge architecture is built around Cross-Chain Verifiers, structures that independently check a message before it moves across chains. Underneath sits a Committee Verifier network of 16 independent node operators per lane, the directional pathway between two blockchains. Companies can now run their own verifiers or hire outside providers such as Infosys and Nethermind, while Chainlink's own 16-operator network still checks every transfer regardless of what else a user adds.
However, the upgrade also retires a safeguard Chainlink used to promote heavily. Its Risk Management Network, a separate set of nodes that used to double-check transactions, no longer plays that role, and Chainlink said an equivalent independent check can now come from the optional verifiers instead. As a result, a user who adds nothing appears to rely on one verification network where previously there were two.
The hack that preceded the launch
The upgrade follows April's $292 million exploit at Kelp DAO, attributed to attackers allegedly linked to North Korea's Lazarus Group. Attackers carried out the exploit by tricking the single verifier that Kelp's LayerZero-based bridge relied on. LayerZero blamed Kelp for using one verifier instead of several, while Kelp said LayerZero staff had reviewed the setup and never objected. Kelp has since said it would move its rsETH token to Chainlink.
According to a statement from Chainlink Labs chief business officer Johann Eid: "in-house builds are slow and expensive".
Migration and institutional interest
More than $15 billion in token value moved onto the protocol in the four months between the Kelp DAO hack and the CCIP 2.0 launch, including wrapped Bitcoin and Coinbase's cbBTC. Launch partners for CCIP 2.0 include Amazon Web Services, Google Cloud, ANZ Bank, and Deutsche Börse Group's Crypto Finance division, pointing toward use cases in cross-chain settlement of tokenized assets.
Existing Chainlink users were automatically moved to the new version, though the company has not named any institution using the new optional verifiers yet. Chainlink said only that Aave and Maple have started adopting some of the upgrade's other features.
Sources: CoinDesk, Crypto Briefing
Trading involves risk.