Chainlink has officially rolled out CCIP 2.0, a significant update to its cross-chain interoperability protocol designed to give developers and companies far more autonomy over how they secure assets moving between blockchains. While Chainlink is primarily recognized as an oracle network providing real-time data like price feeds, the CCIP tool allows different blockchain networks to communicate and swap funds. Because blockchains cannot talk to each other natively, they rely on bridges and verifiers to ensure a transaction actually occurred on one chain before releasing funds on another.
The timing of this release is particularly pointed, arriving just five months after a devastating attack on Kelp DAO that saw roughly 292 million dollars drained by hackers allegedly linked to North Korea. That breach was attributed to a vulnerability in a rival bridge provided by LayerZero, specifically because the setup relied on a single verifier that was easily tricked. In response to that disaster, Kelp shifted its rsETH token over to Chainlink, highlighting a growing industry demand for more robust, multi layered security architectures.
Under the new version of CCIP, companies can now layer their own custom security checks or hire third party providers like Nethermind and Infosys to act as additional verifiers. Crucially, these optional checks sit on top of Chainlinks existing default network of 16 independent node operators who must reach a consensus on every transfer. According to Johann Eid, chief business officer at Chainlink Labs, this approach aims to protect users from having to become expert security architects themselves while avoiding the costly mistakes associated with building in house infrastructure from scratch.
One notable shift in the upgrade is the retirement of the Risk Management Network as a standalone safeguard. Previously, this served as a separate secondary check for all transactions, but Chainlink says this function can now be handled by those optional external verifiers instead. For users who choose not to add their own extra layers of security, they will now rely solely on the primary 16 operator network rather than two distinct systems. While early adopters like Aave and Maple have begun integrating parts of the update, Chainlink has yet to name specific institutions utilizing the new customizable verifiers.





