Chainlink launches CCIP 2, letting enterprises add their own cross-chain validators

Chainlink launches CCIP 2, letting enterprises add their own cross-chain validators

N
News Editor
2026-09-28 12:35:30
Chainlink on Monday released CCIP 2, a major upgrade to the messaging and bridge infrastructure behind its Cross-Chain Interoperability Protocol. The new version lets enterprises add their own security checks on top of Chainlink’s default validation network of 16 independent node operators. Companies can run validators themselves or hire outside providers such as Infosys and Nethermind. Chainlink said users should not have to become “experts in cross-chain security infrastructure.” The release comes about five months after the April hack affecting Kelp DAO, in which attackers reportedly linked to North Korea’s Lazarus Group deceived the single validator used by Kelp’s LayerZero-based bridge and stole about $292 million in rsETH. LayerZero blamed Kelp for relying on a single validator, while Kelp said LayerZero employees had reviewed its setup and raised no objections. Kelp later said it would migrate rsETH to Chainlink. The upgrade also changes Chainlink’s previous safety design: its risk management network no longer acts as an independent review node, with that extra check now handled by optional validators. As a result, users that do not add validators now rely on one validation network instead of two. Existing users have been migrated automatically, and Chainlink said Aave and Maple are already using other features introduced in the upgrade.

Chainlink on Monday released CCIP 2, a major upgrade to the communications and bridge infrastructure behind its Cross-Chain Interoperability Protocol.

The new version allows enterprises to add their own security verification checks on top of Chainlink’s default validation network, which is run by 16 independent node operators. Companies can operate their own validators or hire outside service providers including Infosys and Nethermind. Chainlink said users should not be forced to become “experts in cross-chain security infrastructure.”

The update arrives after a high-profile bridge attack

The release comes about five months after Kelp DAO was hacked in April. The attackers were reportedly tied to North Korea’s Lazarus Group and are said to have stolen about $292 million in rsETH by deceiving the single validator used by Kelp’s cross-chain bridge. That bridge ran on LayerZero.

LayerZero blamed the incident on Kelp’s decision to use only one validator. Kelp, for its part, said LayerZero employees had reviewed its configuration and did not object. Kelp later announced that it would migrate rsETH to Chainlink.

Chainlink also changed its earlier protection model

The upgrade revises a safeguard that Chainlink had previously promoted heavily. Its risk management network will no longer operate as an independent review node. Instead, those independent checks will now be provided through optional validators.

That leaves users who do not add any validators relying on a single validation network, down from two before the change. Existing Chainlink users have already been migrated to the new version automatically.

Chainlink has not disclosed which institutions are using the new validator setup. It said only that Aave and Maple have started using other features included in the upgrade.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.