FinanceChainlink has introduced an upgraded version of its Cross-Chain Interoperability Protocol (CCIP 2.0), allowing businesses to implement personalized security checks for blockchain transfers, addressing vulnerabilities exposed by a significant hack earlier this year.

The enhanced software enables firms to integrate their own security protocols, reducing the risk of single points of failure that affected competing bridge technologies.

By Oliver Knight|Edited by Omkar GodboleSep 28, 2026, 8:30 a.m. EDT2 min read

  • Chainlink's CCIP 2.0 upgrade allows businesses to add their own security checks for blockchain transactions, building on top of Chainlink's existing network of 16 operator verifiers.
  • This update follows the April incident where a $292 million hack of Kelp DAO was attributed to a vulnerability in a LayerZero bridge that depended on a single verifier. Kelp subsequently migrated its rsETH token to Chainlink.
  • Chainlink's Risk Management Network, which previously served as an additional layer of protection, is no longer operating independently, meaning users who do not add their own verifiers are now reliant on a single verification network.

Chainlink has rolled out its Cross-Chain Interoperability Protocol (CCIP) 2.0, significantly enhancing the framework that enables different blockchains to interact and exchange funds.

This update allows companies to incorporate their own security measures into these transactions. The timing of this launch is particularly relevant, coming five months after the year's largest decentralized finance (DeFi) hack, which was linked to a bridge that depended solely on one verifier.

Recognized primarily as an oracle network, Chainlink provides external data, such as asset prices, to blockchains, which is essential for various lending and trading applications. The CCIP, first introduced in 2023, facilitates the transfer of both tokens and messages between blockchains.

Because blockchains cannot directly communicate with one another, transferring tokens from one to another relies on bridges. These bridges depend on verifiers to confirm that a transaction occurred on the initial blockchain before funds can be released on the subsequent one. If a verifier is compromised, an attacker can withdraw funds that were never deposited.

This was the case with Kelp DAO in April, when attackers, allegedly associated with North Korea's Lazarus Group, siphoned off approximately $292 million in rsETH from Kelp's bridge, which utilized LayerZero technology, by deceiving the single verifier it relied upon.

LayerZero attributed the incident to Kelp's decision to use just one verifier, while Kelp contended that LayerZero had approved its configuration without objection. Data from CoinGecko indicated that nearly half of the active applications using LayerZero employed a similar single-verifier setup, prompting Kelp to transition its rsETH to Chainlink.

The CCIP 2.0 offers a variety of verifier options, enabling companies to either manage their own or engage external providers like Infosys and Nethermind. Chainlink's network of 16 independent node operators will continue to verify every transaction, irrespective of additional checks that users choose to implement.

Chainlink emphasized that users should not need to be "cross-chain security infrastructure experts" to utilize the system effectively. "Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive," stated Johann Eid, chief business officer of Chainlink Labs.

The upgrade also modifies a previously emphasized safeguard, the Risk Management Network, which was a distinct set of nodes that provided additional transaction verification. Chainlink has indicated that independent checks can now be performed by optional verifiers, suggesting that users who do not add any extra verifiers are now dependent on a single verification network rather than two as before.

Current Chainlink users have been automatically transitioned to the new version. However, the company has yet to disclose any institutions that are utilizing the new verifier options, only mentioning that Aave and Maple have begun to implement some of the features from the upgrade.

HackLatest Crypto News