Chainlink launches CCIP 2.0 with custom bridge verifiers
Chainlink's CCIP 2.0 lets institutions run their own cross-chain verifiers, five months after the $292 million Kelp DAO hack pushed several firms onto its rails.
Key points
- Chainlink launched CCIP 2.0 on Monday, adding a Cross-Chain Verifier that institutions can run themselves or hire from Infosys or Nethermind.
- The Risk Management Network's automated offchain role is no longer active in current CCIP deployments, per Chainlink's documentation.
- A default committee of 16 independent node operators still reaches consensus on every transfer.
- Kelp DAO lost about $292 million in April to hackers linked to North Korea's Lazarus Group; its LayerZero bridge used a single verifier.
- Chainlink says $15 billion in tokenized assets moved onto its rails in four months, and CCIP now secures over $84 billion.
Chainlink launched CCIP 2.0 on Monday, a new version of its cross-chain software that lets institutions run their own bridge verifiers instead of relying only on Chainlink's default network. The upgrade arrives five months after the $292 million Kelp DAO hack, which pushed several firms towards Chainlink's rails.
Bridges exist because blockchains cannot read each other. When a token moves between chains, a verifier must confirm the money left one chain before it appears on the other. That trust has proved costly, as bridges have lost billions to hackers, usually because a single verifier became a single point of failure.
CCIP 2.0 answers that with the Cross-Chain Verifier, or CCV. Institutions can operate their own verifier as a second check before a transfer clears, or hire one from firms such as Infosys or Nethermind. Starter kits are available on Amazon Web Services and Google Cloud, according to Decrypt.
Chainlink ships CCIP 2.0
Underneath, Chainlink still runs its default check: a committee of 16 independent node operators that must all agree a transaction is legitimate. That part is unchanged. What changed quietly is the Risk Management Network, a separate set of nodes that used to double-check the committee's work.
Chainlink's documentation states that the Risk Management Network's automated offchain role is no longer active in current CCIP deployments, though it is expected to return as an optional validation layer. Its on-chain contract remains only as an emergency backstop. In practice, an institution adding nothing extra now relies on one verification network where it once had two.
The timing traces to April, when hackers linked to North Korea's Lazarus Group drained about $292 million from Kelp DAO, a protocol for staking and moving Ethereum across chains. Kelp's bridge ran on LayerZero with a single verifier, a setup LayerZero later called a mistake and stopped supporting for new deployments. Kelp said LayerZero approved it; LayerZero disputed that.
Kelp hack drove migration
Institutions moved after the hack. Kelp itself shifted to Chainlink, as did Kraken with its wrapped Bitcoin token and Lombard Finance with over $1 billion in Bitcoin-linked assets. Chainlink says $15 billion in tokenized assets migrated onto its rails in four months, including parts of BitGo's wrapped Bitcoin and Coinbase's cbBTC, and that CCIP now secures more than $84 billion in cross-chain value, a figure it reports itself.