Chainlink launches new version of its crypto bridge tech ‘CCIP’ to give apps more control over their security

Chainlink launches CCIP 2.0 to give big crypto apps more control over their security

Finance

The new software lets companies add custom security checks so they do not fall victim to the same type of vulnerabilities that plagued rival bridges.

By Oliver Knight|Edited by Omkar Godbole

Updated Published

2min read

Share this article

Chainlink co-founder Sergey Nazarov speaks at the project's SmartCon conference in Barcelona. (Chainlink)

Summary

Chainlink released the Cross-Chain Interoperability Protocol (CCIP) 2.0 on Monday, delivering a major upgrade to its communication and bridging infrastructure that enables different blockchains to communicate and swap funds.

It lets companies add their own security checks to those transfers, with the launch coming five months after the year’s biggest DeFi hack, blamed on a rival bridge that relied on just one of those checks.

Chainlink is best known as an oracle network, feeding blockchains outside data such as asset prices that lending and trading apps depend on. CCIP, first launched in 2023, extends into moving tokens and messages between chains.

Blockchains can’t communicate directly, so moving a token from one to another depends on a bridge. The technology relies on verifiers, which confirm that a transaction really happened on the first chain before funds are released on the second. If a verifier is fooled, an attacker can withdraw money that was never deposited.

That is what happened to Kelp DAO in April. Attackers allegedly linked to North Korea’s Lazarus Group drained about $292 million in rsETH from Kelp’s bridge, which ran on Chainlink’s rival LayerZero, after tricking the single verifier the setup relied on.

LayerZero blamed Kelp for using one verifier instead of several, while Kelp said LayerZero staff had reviewed its setup and never objected. CoinGecko data showed nearly half of active LayerZero apps used the same one-verifier arrangement, and Kelp said it would move rsETH to Chainlink.

Like LayerZero, CCIP 2.0 lets companies choose extra verifiers, running their own or hiring outside providers such as Infosys and Nethermind. Unlike Kelp’s setup, though, those sit on top of Chainlink’s default network of 16 independent node operators, which must reach a quorum on every transfer.

Users shouldn’t have to be “cross-chain security infrastructure experts,” the company told CoinDesk.

“Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive,” Johann Eid, Chainlink Labs’ chief business officer, said in a statement.

The upgrade also changes a safeguard Chainlink used to promote heavily; its Risk Management Network, a separate set of nodes that double-checked transactions, no longer plays that role. Chainlink said that kind of independent check can now come from the optional verifiers instead. That means a user who adds nothing relies on one verifier network where previously there were two, though that network is made up of 16 operators rather than a single verifier.

Existing integrations continue to work with CCIP 2.0 without any changes, Chainlink said. Still, the company has not named any institution using the new verifiers yet, saying only that Aave and Maple have started adopting some of the upgrade’s other features.

Update (Sept. 28, 14:41 UTC, 2026): An earlier version of the story said existing Chainlink users were automatically moved to CCIP. The story was updated to clarify how CCIP 2.0’s verifiers work.


 

Leave a Reply

Your email address will not be published. Required fields are marked *