In brief
- Chainlink launched CCIP 2.0 on Monday, letting institutions operate their own custom verifiers instead of depending solely on Chainlink's default network.
- The upgrade lands five months after LayerZero-linked Kelp DAO lost $292 million to hackers tied to North Korea, a hack that pushed Kraken and Lombard to Chainlink.
- Chainlink's own docs confirm "the Risk Management Network's automated offchain role is no longer active in current CCIP deployments," ending its job as an independent second check on transfers.
Chainlink today launched CCIP 2.0, the newest version of its cross-chain plumbing—the software layer banks and crypto projects increasingly use to move tokenized money, like stablecoins, wrapped Bitcoin, and tokenized funds, between blockchains without building a bridge from scratch.
That plumbing exists because blockchains don't talk to each other. Ethereum has no idea what's happening on Solana. So when a token moves from one chain to another, something has to confirm the money really left one place before it shows up on the other—that something is called a bridge, and it works by trusting a verifier to vouch for the transfer.
That trust has been expensive. Bridges have lost billions to hackers over the years, usually because they lean on a single point of failure: one verifier, one thing to trick.
CCIP 2.0's answer to that single-point-of-failure problem is a new feature called the Cross-Chain Verifier, or CCV. Institutions can now run their own verifier—a second guard checking the paperwork before a transfer clears—or hire one from a firm like Infosys or Nethermind. Starter kits are ready on Amazon Web Services and Google Cloud.
Underneath, Chainlink still runs its default check: a committee of 16 independent node operators (16 separate companies that must all agree a transaction is legitimate) that reaches consensus on every transfer. That part hasn't changed.
What has changed is quieter. The Risk Management Network—a separate set of nodes that used to double-check the main committee's work—is now less relevant. "The Risk Management Network's automated offchain role is no longer active in current CCIP deployments, but is expected to be offered as an optional validation layer in future releases," the documentation reads.
The on-chain contract sticks around only as an emergency backstop. Chainlink says that same kind of independent check can come from the optional CCVs instead. In practice, that means an institution that adds nothing extra relies on one verification network, where it used to have two.
This isn't just a DeFi trader's problem anymore. Chainlink says $15 billion in tokenized assets migrated onto its rails in the last four months, including chunks of BitGo's wrapped Bitcoin and Coinbase's cbBTC—assets increasingly sitting behind ETFs and bank products that regular people hold without ever touching a crypto wallet.
The timing traces back to April, when hackers linked to North Korea's Lazarus Group drained about $292 million from Kelp DAO, a protocol that let users stake Ethereum and move the token across chains. Kelp's bridge ran on LayerZero, configured with a single verifier—a setup LayerZero later called a mistake and stopped supporting for new deployments.
Kelp said LayerZero's team approved that setup and never flagged it as risky. LayerZero disputed that, saying the configuration went against its own recommendations. Either way, institutions ran. Kelp itself moved to Chainlink, and so did Kraken, which shifted its wrapped Bitcoin token, and Lombard Finance, which moved over $1 billion in Bitcoin-linked assets.
Chainlink's pitch is built on being the bridge that didn't get hacked. CCIP 2.0 hands institutions the same flexibility that got LayerZero in trouble—except Chainlink's 16-operator committee still checks every transfer by default.
"Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive and institutions' proprietary networks can't earn the trust of their peers," Chainlink Labs Chief Business Officer Johann Eid said in the launch announcement.
Chainlink says CCIP now secures more than $84 billion in cross-chain token value, a figure it reports itself. Eighteen companies are listed as launch partners, but read their quotes closely: Fidelity says the upgrade "has the potential to support" broader distribution, and Further Asset Management merely "intends to partner." Confirmed, live deployments on the new verifiers are still scarce, just hours into launch day.