Chainlink rolls out CCIP 2.0 after rival bridge hack exposed single-verifier risk

Chainlink rolls out CCIP 2.0 after rival bridge hack exposed single-verifier risk

N
News Editor
2026-09-28 12:30:59
Chainlink on Monday released CCIP 2.0, a new version of its Cross-Chain Interoperability Protocol that lets companies add their own verification checks to cross-chain transfers on top of Chainlink’s default 16-operator network. The upgrade arrives months after the April attack on Kelp DAO’s bridge, in which about $292 million in rsETH was drained after a LayerZero-based setup that relied on a single verifier was allegedly tricked. Kelp later said it would move rsETH to Chainlink. The update expands the menu of verifier options available to users. Companies can run their own verifiers or hire outside providers including Infosys and Nethermind, while Chainlink’s own node-operator network continues to check every transfer. At the same time, the release changes how Chainlink’s Risk Management Network works. That separate set of nodes no longer acts as an independent backstop, meaning users who do not add optional verifiers appear to depend on one verification network rather than the two-layer design Chainlink previously promoted. Chainlink said existing users were automatically migrated, and added that Aave and Maple have begun adopting some of the upgrade’s other features, though it did not name any institution using the new verifier model yet.

Chainlink on Monday released CCIP 2.0, an upgraded version of its Cross-Chain Interoperability Protocol that expands how blockchains exchange messages and move funds. The new software allows companies to add their own security checks to transfers, on top of Chainlink’s default verification system made up of 16 node operators.

The release comes five months after the year’s largest DeFi hack, an April attack on Kelp DAO that was tied to a bridge configuration using a single verifier. About $292 million in rsETH was drained in that incident, and Kelp later said it would migrate the token to Chainlink.

CCIP 2.0 adds customizable verification options

Chainlink is best known for its oracle network, which supplies blockchains with outside data such as asset prices used by lending and trading applications. CCIP, first launched in 2023, extends that business into moving tokens and messages across chains.

Because blockchains cannot communicate directly, moving a token from one network to another requires a bridge. Those systems depend on verifiers to confirm that a transaction actually occurred on the source chain before funds are released on the destination chain. If a verifier is deceived, an attacker can withdraw assets that were never deposited in the first place.

CCIP 2.0 introduces a menu of verifier options. Companies can run their own verifiers or use outside providers such as Infosys and Nethermind. Chainlink’s own network of 16 independent node operators still checks every transfer, regardless of what additional verification layers a user chooses to add.

Users should not need to be 「cross-chain security infrastructure experts」, the company told CoinDesk.

In a statement, Chainlink Labs Chief Business Officer Johann Eid said, 「Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive.」

Kelp DAO attack sharpened focus on bridge design

In April, attackers allegedly linked to North Korea’s Lazarus Group drained about $292 million in rsETH from Kelp DAO’s bridge. The bridge ran on LayerZero, and the attackers succeeded after tricking the single verifier used in that setup.

LayerZero said Kelp was responsible because it had chosen to use one verifier instead of several. Kelp responded that LayerZero staff had reviewed the configuration and never raised objections. CoinGecko data showed that nearly half of active LayerZero applications used the same one-verifier arrangement. Kelp later said it would move rsETH to Chainlink.

Risk Management Network no longer serves as a separate backstop

The release also changes a safeguard that Chainlink had previously emphasized. Its Risk Management Network, once described as a separate set of nodes that performed a second check on transactions, no longer fills that role in CCIP 2.0.

Chainlink said that independent check can now come from optional verifiers added by users. In practice, that suggests a user who adds nothing extra now appears to rely on one verification network, whereas the earlier setup had two.

Existing Chainlink users were automatically migrated to the new version. The company has not identified any institution using the new verifier setup so far. It said only that Aave and Maple have started adopting some of the upgrade’s other features.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.