Overview
- Chainlink unveiled CCIP 2.0 on Monday, enabling institutions to utilize their own custom verification systems rather than relying solely on Chainlink’s default network.
- This update comes five months after Kelp DAO, linked to LayerZero, suffered a $292 million hack attributed to North Korean hackers, prompting companies like Kraken and Lombard to migrate to Chainlink.
- According to Chainlink’s documentation, the automated offchain function of the Risk Management Network is no longer active in current CCIP implementations, effectively ending its role as an independent verification layer for transactions.
Chainlink has launched CCIP 2.0, the latest iteration of its cross-chain infrastructure that banks and crypto firms increasingly use to transfer tokenized assets—such as stablecoins and wrapped Bitcoin—across different blockchains without needing to create a new bridge from scratch.
This infrastructure is crucial because various blockchains operate independently; for example, Ethereum and Solana do not communicate with each other. Thus, when a token is transferred between chains, a mechanism is required to verify that the asset has indeed left its original location before it appears on the receiving chain. This function is performed by a bridge, which relies on a verifier to authenticate the transfer.
However, this reliance on a single verifier has proven costly, with bridges losing billions to cyberattacks over the years due to their vulnerability to a single point of failure.
To address this issue, CCIP 2.0 introduces the Cross-Chain Verifier (CCV). Institutions now have the option to operate their own verifiers—providing an additional layer of scrutiny before a transfer is approved—or they can engage services from firms like Infosys or Nethermind. Initial setups are available through Amazon Web Services and Google Cloud.
Chainlink continues to maintain its standard verification process, which involves a consensus among 16 independent node operators (a group of distinct companies that must all validate a transaction's legitimacy) for every transfer, a feature that remains unchanged.
However, the Risk Management Network, which previously acted as an additional check on the main committee's verification, has been rendered less significant. The documentation states, "The Risk Management Network's automated offchain role is no longer active in current CCIP deployments, but is expected to be offered as an optional validation layer in future releases."
The on-chain contract now serves merely as a backup. Chainlink suggests that independent checks can be provided by the optional CCVs. This means that institutions that do not integrate any additional features will rely on a single verification network instead of the previous dual-layer verification approach.
This is not solely a concern for DeFi traders any longer. Chainlink reported that $15 billion in tokenized assets have transitioned onto its platform in the past four months, which includes parts of BitGo's wrapped Bitcoin and Coinbase's cbBTC—assets increasingly being utilized in ETFs and bank products that everyday consumers hold without engaging with crypto wallets.
This shift follows an incident in April when hackers associated with North Korea's Lazarus Group stole approximately $292 million from Kelp DAO, a protocol that allowed users to stake Ethereum and transfer tokens across chains. Kelp's bridge relied on LayerZero and employed a single verifier—a configuration that LayerZero later admitted was a mistake and ceased supporting for new deployments.
Kelp claimed that LayerZero's team approved the setup without flagging any risks. LayerZero countered, asserting that the configuration contradicted its own guidelines. Regardless, this incident led many institutions to migrate; Kelp itself switched to Chainlink, as did Kraken, which moved its wrapped Bitcoin token, and Lombard Finance, which transitioned over $1 billion in Bitcoin-related assets.
Chainlink's value proposition centers on being a bridge that has not been compromised. CCIP 2.0 offers institutions the flexibility that caused issues for LayerZero, but with Chainlink's 16-operator committee still verifying every transfer by default.
"Historically, traditional bridges have lost billions due to insecure infrastructure, while custom-built solutions are often slow and costly, and private networks fail to gain the trust of their peers," stated Johann Eid, Chief Business Officer of Chainlink Labs, during the launch announcement.
Chainlink claims that CCIP now secures more than $84 billion in cross-chain token value, a figure it reports itself. Eighteen companies are named as launch partners, but their statements warrant careful reading: Fidelity notes that the upgrade "has the potential to support" broader distribution, while Further Asset Management merely "intends to partner." As of now, confirmed deployments utilizing the new verifiers are limited, occurring just hours after the launch.
