Chainlink on Tuesday launched CCIP 2.0, the latest version of its cross-chain infrastructure for moving tokenized assets between blockchains. The system is used by banks and crypto projects to transfer assets such as stablecoins, wrapped Bitcoin, and tokenized funds without building a bridge from scratch.
That infrastructure exists because blockchains do not natively communicate with each other. Ethereum does not know what is happening on Solana, so when an asset moves from one chain to another, some mechanism has to confirm that the funds actually left the source chain before they appear on the destination chain. In practice, that mechanism is a bridge, and it relies on a verifier to attest that the transfer is valid.
That trust model has carried a heavy cost. Over the years, bridges have lost billions of dollars to hacks, often because they depended on a single point of failure: one verifier, one thing to compromise.
CCIP 2.0 adds optional institution-controlled verification
Chainlink’s answer in CCIP 2.0 is a new feature called the Cross-Chain Verifier, or CCV. Institutions can now run their own verifier as an added checkpoint before a transfer is cleared, or use a third-party provider such as Infosys or Nethermind. Chainlink said starter kits are available on Amazon Web Services and Google Cloud.
Under the hood, Chainlink’s default validation model is unchanged. A committee of 16 independent node operators still checks each transfer, and all 16 companies must reach consensus that a transaction is legitimate.
The quieter change sits elsewhere in the stack. The Risk Management Network, a separate group of nodes that previously double-checked the main committee’s work, now plays a smaller role. According to Chainlink’s documentation, “The Risk Management Network’s automated offchain role is no longer active in current CCIP deployments, but is expected to be offered as an optional validation layer in future releases.”
The on-chain contract remains in place only as an emergency backstop. Chainlink said the same kind of independent review can now come from optional CCVs. In practical terms, an institution that adds no extra validation now relies on one verification network, where it previously had two.
The Kelp DAO hack put bridge design back under scrutiny
This is no longer limited to DeFi traders. Chainlink said $15 billion in tokenized assets moved onto its rails over the last four months, including portions of BitGo’s wrapped Bitcoin and Coinbase’s cbBTC. Those assets are increasingly used inside ETFs and bank products that ordinary holders may own without ever interacting with a crypto wallet.
The timing points back to April, when hackers linked to North Korea’s Lazarus Group drained about $292 million from Kelp DAO. The protocol allowed users to stake Ethereum and move the token across chains. Kelp’s bridge ran on LayerZero and had been configured with a single verifier, a setup LayerZero later described as a mistake and said it no longer supports for new deployments.
Kelp said LayerZero’s team had approved that configuration and never identified it as risky. LayerZero rejected that account, saying the setup went against its own recommendations. Whatever the dispute, institutions moved away. Kelp shifted to Chainlink, Kraken moved its wrapped Bitcoin token, and Lombard Finance also switched over, bringing more than $1 billion in Bitcoin-linked assets.
Chainlink keeps its 16-operator committee as the default check
Chainlink’s pitch is built around being the bridge that has not been hacked. CCIP 2.0 gives institutions the same sort of flexibility that became a problem for LayerZero, except Chainlink’s 16-operator committee still verifies every transfer by default.
Chainlink Labs Chief Business Officer Johann Eid said in the launch announcement: “Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive and institutions’ proprietary networks can’t earn the trust of their peers.”
Chainlink also said CCIP now secures more than $84 billion in cross-chain token value, a figure reported by the company itself. Eighteen companies are listed as launch partners, but the early production picture remains limited. Fidelity said the upgrade “has the potential to support” broader distribution, while Further Asset Management said only that it “intends to partner.” Just hours after the rollout, confirmed live deployments using the new verifier model were still scarce.

