Security options open up to applications with CCIP 2.0
Chainlink launched CCIP 2.0 on Monday, a new version of its protocol for sending messages and transferring tokens across different blockchains. The update gives companies the option to add their own security checks to cross-chain transactions or rely on verification services from outside providers.
First introduced in 2023, CCIP was designed to go beyond Chainlink’s oracle network and enable cross-chain movement of funds and data. Because blockchains cannot communicate directly with one another, bridge infrastructure is seen as critical for liquidity flows in DeFi markets; changes to the verification model therefore have a direct impact on operational risk and market confidence.
What changed in the verification structure?
In CCIP 2.0, optional extra validators can be added on top of the default network of 16 independent node operators. A transfer must receive enough operator consensus to be completed. Companies can either build their own controls or work with outside providers such as Infosys and Nethermind.
- The default verification layer relies on multi-operator consensus for each transaction.
- Additional security layers can be added later based on need.
Meanwhile, Chainlink’s previously promoted Risk Management Network no longer acts as a separate security network that independently double-checks transactions. According to the company, that function can now be handled by optional validators, meaning customers that do not use the extra layer will rely on a single verification network instead of the previous two-network setup.
Security pressure rises after a $292 million attack
The update comes about five months after one of the biggest attacks to hit the DeFi market this year. In April, about $292 million worth of rsETH was drained from the Kelp DAO bridge, in an attack reportedly linked to the Lazarus Group, which has been associated with North Korea.
The bridge in question ran on infrastructure from Chainlink rival LayerZero and used only one validator in its setup. If a validator is deceived in a bridge mechanism, an asset that was not actually deposited on the first chain can be released on the second chain.
LayerZero blamed the issue on the choice to use a single validator, while Kelp DAO said its staff reviewed the setup and raised no objections. According to CoinGecko data, about half of active LayerZero applications used a similar single-validator setup, and Kelp DAO said it would move rsETH to Chainlink.
Existing integrations stay in place as adoption is watched
Chainlink said existing integrations will continue to work without changes. The company has not yet named any institution using the new validator model, although it said Aave and Maple have started adopting some of the update’s other features.
Key takeaways for the market
- CCIP 2.0 introduces a hybrid bridge-security model that combines the default multi-operator network with optional additional checks.
- In DeFi protocols, bridge security is not just a technical issue; it is also a factor priced into capital flows, user trust and institutional adoption.
Cross-chain bridges are closely watched by market participants because they play a central role in moving stablecoin and token liquidity across networks. For that reason, the pace of CCIP 2.0 adoption will be an important indicator for both Chainlink’s product positioning and DeFi protocols’ risk-management choices.
"""
Comments (0)
No comments yet. Be the first to comment.
Write a Comment
Yorum yazmak için giriş yapın. Üyelik ücretsiz; yorumunuz editör onayından sonra yayımlanır.