Chainlink Unveils CCIP 2.0 with Custom Security Layers Following Major Bridge Hack

Chainlink Unveils CCIP 2.0 with Custom Security Layers Following Major Bridge Hack

Chainlink upgrades cross-chain bridge technology

Chainlink has released version 2.0 of its Cross-Chain Interoperability Protocol (CCIP), a major update designed to let applications control their own security settings. This launch comes five months after a significant hack involving a rival bridge system.

The new software allows companies to add custom security checks to token transfers between different blockchains. These checks sit on top of Chainlink's default network, which uses 16 independent operators to verify transactions. Previously, the system relied heavily on a separate "Risk Management Network" for extra safety, but that component no longer functions as an independent safeguard in this new version.

Security changes after Kelp DAO loss

  • CCIP 2.0 enables users to hire external security providers or run their own verifiers alongside Chainlink's default 16-node network.
  • The update follows a $292 million hack in April against Kelp DAO, which used a rival bridge called LayerZero.
  • Kelp DAO's setup relied on a single verifier, which attackers allegedly tricked to steal funds.
  • Chainlink co-founder Sergey Nazarov and the team stated that users should not need to be security experts to stay safe.

Context from the Kelp DAO incident

The April hack involved approximately $292 million in rsETH tokens being drained from Kelp DAO. Reports allege the attackers were linked to North Korea's Lazarus Group. The breach occurred because the bridge configuration used only one verifier to confirm transactions.

LayerZero, the technology provider, blamed Kelp DAO for choosing a single-verifier setup. However, Kelp DAO claimed that LayerZero staff had reviewed and approved their configuration without objection. Data from CoinGecko indicated that nearly half of active LayerZero applications used this same single-verifier arrangement. Following the attack, Kelp DAO announced plans to move its rsETH token to Chainlink.

How the new verification works

In the previous model, Chainlink promoted a dual-network approach where a separate Risk Management Network double-checked transactions. Under CCIP 2.0, that separate layer is gone. Instead, users who do not add their own custom verifiers will rely solely on the default network of 16 independent node operators. These operators must reach a consensus, or quorum, on every transfer before funds are released.

Johann Eid, Chainlink Labs' chief business officer, noted that legacy bridges have historically lost billions due to weak infrastructure, while building internal security systems is often slow and costly.

What remains uncertain

While the new protocol offers more flexibility, it shifts some responsibility to the application developers to configure their own additional security layers. It is not yet clear how many projects will adopt these custom checks versus relying on the default 16-operator network alone.

Next steps for developers

Companies can now integrate CCIP 2.0 to add custom security measures. They may choose to run their own verification nodes or contract outside firms like Infosys and Nethermind to perform these checks.

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!