Chainlink’s CCIP upgrade adds extra security layers after $292M hack
Five months after a $292 million hack rattled the decentralized finance world, Chainlink has rolled out a major fix aimed at preventing the next one. The Chainlink CCIP upgrade, officially named CCIP 2.0, gives companies far more control over how their cross-chain transfers get verified, letting them stack extra security checks on top of the network’s existing safeguards instead of relying on a single point of failure.
Summary
Key takeaways
- Chainlink released CCIP 2.0 on Monday, upgrading its cross-chain communication and bridging infrastructure.
- The launch comes five months after attackers drained $292 million in rsETH from Kelp DAO’s bridge, which ran on rival LayerZero and relied on just one verifier.
- CCIP 2.0 lets companies add optional security verifiers on top of Chainlink’s default 16-node operator network, run either in-house or through outside providers such as Infosys and Nethermind.
- Chainlink’s Risk Management Network, a previous independent safeguard, no longer performs that double-check role; optional verifiers now cover that function instead.
- Existing CCIP integrations continue working without any changes, and Aave and Maple have already adopted some of the new features.
Chainlink launches CCIP 2.0 to enhance crypto bridge security
The core problem CCIP 2.0 tries to solve is simple to describe but hard to fix: blockchains can’t talk to each other directly. Moving a token from one chain to another means trusting a bridge, and that bridge depends on verifiers confirming a transaction actually happened before releasing funds on the other side. Fool the verifier, and an attacker can pull out money that was never really deposited.
Kelp DAO faced this very scenario back in April, when hackers reportedly tied to North Korea’s Lazarus Group siphoned off roughly $292 million in rsETH by deceiving the sole verifier underpinning Kelp’s bridge, a system built on Chainlink competitor LayerZero. LayerZero blamed Kelp for relying on just one verifier instead of several, while Kelp countered that LayerZero staff had reviewed the setup and never raised objections. CoinGecko data cited by CoinDesk showed nearly half of active LayerZero apps used a similar one-verifier arrangement at the time. Kelp later said it would move rsETH over to Chainlink.
That backdrop makes the timing of the Chainlink CCIP upgrade hard to ignore. Chainlink is best known as an oracle network, feeding blockchains external data like asset prices that lending and trading apps rely on. CCIP, which first launched in 2023, extended that role into moving tokens and messages across chains, and this new version arrives, directly addressing the kind of single-verifier weakness that cost Kelp DAO hundreds of millions.
Advanced security options with multiple verifiers
CCIP 2.0’s biggest change is giving companies the ability to layer extra verification on top of a baseline that already requires broad agreement among independent operators. Chainlink’s default network runs on 16 independent node operators, which must reach a quorum on every transfer before it goes through.
On top of that baseline, companies can now add their own Cross-Chain Verifiers, or CCVs, running them on their preferred cloud infrastructure. Firms that don’t want to build and run verification systems themselves can instead outsource the job to third-party enterprise providers, including Infosys and Nethermind, according to Chainlink. It’s a similar approach to the one LayerZero itself offers, but crucially those extra verifiers sit on top of Chainlink’s 16-operator quorum rather than replacing it as the sole line of defense.
Chainlink told CoinDesk that users shouldn’t have to be “cross-chain security infrastructure experts” just to move assets safely between chains. Johann Eid, Chainlink Labs’ chief business officer, framed the trade-off institutions have faced until now in a statement: “Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive.”
Changes in security mechanism and compatibility
The upgrade also retires a safeguard Chainlink had promoted heavily in the past. Its Risk Management Network, a separate set of nodes that independently double-checked transactions, no longer performs that function under CCIP 2.0. Chainlink says the same kind of independent check can now come from the optional verifiers instead.
In practice, that means a company that adds no extra verifiers is now relying on one verification system where previously there were two layers, the 16-operator network and the separate Risk Management Network. That single system, however, is still built from 16 independent operators reaching quorum, rather than the lone verifier that failed in Kelp DAO’s case.
For companies already plugged into Chainlink’s bridging infrastructure, the transition should be painless: existing CCIP integrations continue to work with CCIP 2.0 without any changes required on their end. Chainlink hasn’t named a specific institution using the new optional verifier feature yet, but says Aave and Maple have already begun adopting some of the upgrade’s other capabilities.
Lessons from recent hacks illustrate bridge vulnerabilities
The Kelp DAO episode remains the clearest illustration of why this matters. A bridge that leaned on a single verifier turned out to be a soft target, and the fallout, a $292 million loss and a public dispute between Kelp and LayerZero over who bore responsibility for the setup, became a cautionary tale across the industry. Nearly half of LayerZero’s active applications reportedly used a comparable one-verifier configuration when the hack happened.
Chainlink’s pitch with CCIP 2.0 is essentially that spreading trust across multiple independent checks, rather than concentrating it in one place, closes off the kind of exploit that hit Kelp. Whether institutions actually adopt the optional verifier layer at scale, and how quickly, will determine whether this Chainlink CCIP upgrade meaningfully reduces the frequency of cross-chain attacks or simply shifts where the next weak point emerges.
FAQ
What is Chainlink’s CCIP 2.0?
CCIP 2.0 is an upgraded version of Chainlink’s cross-chain communication and token bridge technology that allows companies to add custom security verifiers.
Why did Chainlink upgrade its crypto bridge technology?
The upgrade follows a $292 million Kelp DAO hack caused by a rival bridge relying on a single verifier, highlighting the need for stronger multi-verifier security.
How does CCIP 2.0 improve security compared to earlier versions?
CCIP 2.0 lets companies add extra security verifiers on top of Chainlink’s default 16-node operator network, replacing the previous Risk Management Network safeguard.
Are existing CCIP integrations compatible with the new upgrade?
Yes, existing CCIP integrations continue to work without any changes after upgrading to CCIP 2.0.
{"@context":"","@type":"FAQPage","mainEntity":[{"@type":"Question","name":"What is Chainlink's CCIP 2.0?","acceptedAnswer":{"@type":"Answer","text":"CCIP 2.0 is an upgraded version of Chainlink's cross-chain communication and token bridge technology that allows companies to add custom security verifiers."}},{"@type":"Question","name":"Why did Chainlink upgrade its crypto bridge technology?","acceptedAnswer":{"@type":"Answer","text":"The upgrade follows a $292 million Kelp DAO hack caused by a rival bridge relying on a single verifier, highlighting the need for stronger multi-verifier security."}},{"@type":"Question","name":"How does CCIP 2.0 improve security compared to earlier versions?","acceptedAnswer":{"@type":"Answer","text":"CCIP 2.0 lets companies add extra security verifiers on top of Chainlink's default 16-node operator network, replacing the previous Risk Management Network safeguard."}},{"@type":"Question","name":"Are existing CCIP integrations compatible with the new upgrade?","acceptedAnswer":{"@type":"Answer","text":"Yes, existing CCIP integrations continue to work without any changes after upgrading to CCIP 2.0."}}]}
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Dow Jones Industrial Average gives back Friday's rally on a Boeing delay
ECB rate hike expectations cool down, Lagarde: Rising long-term rates will suppress growth and inflation
Christine Lagarde, President of the European Central Bank, stated that a significant rise in long-term interest rates will slow economic growth and suppress the transmission of energy prices to overall inflation, exceeding the extent forecasted by the ECB in September. She also emphasized that in the absence of signs of second-round effects, the ECB should adopt "moderate response measures" to control inflation. As a result, the market’s expectation of an ECB rate hike in October has dropped to less than 40%.

BitMine stock trades near golden cross as Ethereum holdings approach 5%
XDC crypto’s bullish setup strengthens – Why $1.08M in exchange inflows matter
