Chainlink rolled out Cross-Chain Interoperability Protocol (CCIP) 2.0 on Monday, providing a substantial upgrade to its cross-chain communication and messaging tools that facilitate data sharing and token transfers across disparate ledgers.
This update allows organizations to integrate custom verification parameters into their transfers, arriving five months after the most significant decentralized finance exploit of the year, which stemmed from a competing bridge utilizing only a single validation check.
Chainlink is primarily recognized as an oracle provider that supplies external data, such as asset valuations, to blockchains to support lending platforms and trading systems. Introduced initially in 2023, CCIP expands these capabilities into cross-chain token and message transfers.
Because independent blockchains lack native communication channels, transferring tokens between them necessitates a bridging mechanism. Such systems rely on verifiers to validate that a transaction genuinely occurred on the source network before unlocking assets on the destination network. If a verifier becomes compromised, malicious actors can withdraw funds that were never actually deposited.
That exact vulnerability materialized during the April incident involving Kelp DAO. Attackers tied to North Korea’s Lazarus Group siphoned roughly $292 million worth of rsETH from Kelp’s bridge—which operated on Chainlink competitor LayerZero—after exploiting the singular verifier underpinning the architecture.
LayerZero attributed the incident to Kelp’s decision to rely on one verifier rather than multiple options, while Kelp countered that LayerZero personnel had previously evaluated and approved the configuration. Figures from CoinGecko revealed that almost half of all active LayerZero deployments utilized that identical single-verifier arrangement, prompting Kelp to announce plans to migrate its rsETH asset to Chainlink.
Similar to LayerZero, CCIP 2.0 empowers entities to select supplemental verifiers, either operating their own or engaging external service providers such as Nethermind and Infosys. Unlike Kelp’s setup, however, these additional checks operate on top of Chainlink’s default baseline network of 16 decentralized node operators, which must achieve consensus on every single transaction.
Management emphasized to CoinDesk that end users should not be forced to become cross-chain security specialists.
Johann Eid, chief business officer at Chainlink Labs, remarked in an official statement that legacy bridges have historically incurred billions in losses due to fragile architectures, whereas building custom solutions internally remains both slow and costly.
The release also alters a defensive measure previously emphasized by Chainlink: its Risk Management Network, a separate cluster of nodes dedicated to cross-checking transactions, no longer fulfills that specific function. Chainlink explained that independent validations can now be handled by the optional verifiers instead. Consequently, users who decline to add custom verifiers will depend on a single validation framework where two previously existed, though that framework comprises 16 operators rather than a sole verifier.
Existing integrations will maintain full compatibility with CCIP 2.0 with zero modifications required, according to Chainlink. Nevertheless, the firm has not yet publicly identified any institutional clients utilizing the new verifiers, noting solely that protocols like Aave and Maple have begun adopting alternate capabilities introduced in the upgrade.
Originally published at https://www.coindesk.com/business/2026/09/28/chainlink-updates-its-crypto-bridge-tech-months-after-a-usd292-million-hack-shook-the-industry.