Chainlink has released CCIP 2.0, which allows companies to add their own security checks to cross-chain transfers on top of the default network of 16 operational verifiers in Chainlink.

It has been five months since the $292 million Kelp DAO hacking incident in April. That incident was attributed to a bridging solution that relied on a single verifier.
Chainlink is renowned for its oracle network, providing off-chain data for blockchain systems, such as asset prices that are essential for lending and trading applications. CCIP was initially launched in 2023, and its functionality has since been extended to support the transfer of tokens and messages between different blockchains.
Blockchains cannot communicate directly with each other, so transferring tokens from one chain to another relies on bridges. This technology depends on validators; only after a validator confirms that a transaction has indeed occurred on the first chain will the funds be released on the second chain. If a validator is deceived, attackers may be able to withdraw funds that were not actually deposited.
This is exactly what happened on Kelp DAO in April. The attackers are alleged to be associated with North Korea Lazarus Group. After deceiving the single verifier that the bridging solution relied on, they stole approximately $292 million in rsETH from the bridge at Kelp. This bridge operates on LayerZero.
LayerZero accuses Kelp of using only one verifier instead of multiple; Kelp indicates that LayerZero employees reviewed the settings and never raised any objections. CoinGecko data shows that nearly half of the active LayerZero applications are using the same single-verifier arrangement, while Kelp indicates that rsETH will be migrated to Chainlink.
Chainlink told CoinDesk that users should not become "cross-chain security infrastructure experts".
Chainlink Labs Chief Commercial Officer Johann Eid stated in a statement: "Historically, traditional bridging solutions have resulted in billions of dollars in losses due to insecure infrastructure, while self-built solutions are slow and expensive."

The existing Chainlink users have been automatically migrated to the new version. However, the company has not yet named any institutions that are using the new verifiers; it only indicates that Aave and Maple have begun to adopt some of the other features included in this upgrade.












