Finst

Chainlink Launches CCIP 2.0 With Extra Security

The upgrade is meant to make cross-chain transfers safer with extra verifiers, after the major DeFi hack at Kelp DAO and earlier concerns around bridges.

Chainlink Launches CCIP 2.0 With Extra Security

Key Takeaways

  • Chainlink has released CCIP 2.0, an upgrade for communication and bridges between blockchains.
  • Companies can add extra security checks, while Chainlink's network of 16 node operators keeps checking every transfer.
  • The launch follows the Kelp hack, and Aave and Maple have already adopted parts of the upgrade.

Chainlink has released CCIP 2.0, a major upgrade to its infrastructure for communication and bridges between blockchains. The new version is meant to make it easier for crypto apps to move tokens and messages between chains, while companies can add their own extra security checks.

More Control Over Transfers

CCIP, short for Cross-Chain Interoperability Protocol, launched in 2023 and builds on Chainlink's role as an oracle network. The network provides off-chain data to blockchains, such as price information that lending and trading apps need. With CCIP, Chainlink is also moving deeper into the world of cross-chain transfers.

The core of the problem lies in bridges between blockchains. They cannot talk to each other directly, so a verifier has to check whether a transaction on one chain really happened before funds are released on the other chain. If that check goes wrong, an attacker can withdraw money that was never deposited.

CCIP 2.0 now offers a menu of verifiers that companies can choose from. They can add their own checks or bring in outside parties, such as Infosys and Nethermind. Chainlink does say that its own network of 16 independent node operators will keep checking every transfer, no matter which extra options a user chooses.

Lessons From the Kelp Hack

The launch comes five months after the biggest DeFi hack of this year. In April, Kelp DAO was hit by an attack in which, according to the allegations, a group linked to North Korea's Lazarus Group siphoned off about $292 million (€256 million) in rsETH through a bridge on LayerZero. In that case, a single verifier is said to have been fooled.

That attack pushed the debate over cross-chain security even further. After the incident, LayerZero pointed to Kelp because the setup relied on only one verifier. Kelp, meanwhile, said LayerZero employees had reviewed the setup and raised no objections. According to CoinGecko, nearly half of active LayerZero apps used the same single-verifier setup.

Chainlink is positioning CCIP 2.0 as a response to that kind of risk. The company says users do not need to be experts in cross-chain security. At the same time, the upgrade also changes an older security layer: the Risk Management Network no longer plays that role, because that extra check can now also run through optional verifiers.

Why This Matters for DeFi

For European crypto readers, this matters mainly because cross-chain bridges remain one of the weakest parts of DeFi. The Kelp hack showed how much damage can happen when a bridge relies on too few checks. That makes upgrades like CCIP 2.0 interesting for apps that work across multiple chains and for teams that want to tighten up their security setup.

Chainlink has not named any major institution that is already using the new verifiers. It does say, though, that Aave and Maple have already adopted parts of the upgrade. That shows the rollout is already underway, but the real test will only become clear once more major apps start using the new setup.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.