0x3920d9e73920…3920d9e4
Chainlink launches CCIP 2.0 with custom verifier option after $292M Kelp DAO hack
Chainlink released CCIP 2.0 on Monday, letting protocols add custom verifiers atop a 16-node network after the $292M Kelp DAO exploit exposed single-verifier bridge risk.

Outputs
Chainlink released CCIP 2.0 on Monday, adding an opt-in verifier layer atop its 16-node default network.
April's Kelp DAO exploit drained roughly $292 million in rsETH through a single-verifier LayerZero setup.
Chainlink's Risk Management Network no longer functions as a separate secondary safeguard under CCIP 2.0.
CoinGecko data showed nearly half of active LayerZero apps used a one-verifier setup at the time of the April hack.
Chainlink has not yet named an institution using the new verifier tier; Aave and Maple have adopted other CCIP 2.0 features.
Chainlink released CCIP 2.0 on Monday, upgrading the oracle provider's cross-chain bridging infrastructure to let protocols add their own security checks atop a default 16-node verifier network.
The launch follows April's $292 million Kelp DAO exploit — the year's largest DeFi hack to that point — which targeted a LayerZero-powered bridge running on a single verifier. Attackers linked to North Korea's Lazarus Group drained the funds in rsETH after tricking that one check.
What changed in CCIP 2.0?
The Cross-Chain Interoperability Protocol, first launched in 2023, lets blockchains move tokens and messages between chains. Cross-chain transfers depend on verifiers — services that confirm a transaction happened on the source chain before releasing funds on the destination. A fooled verifier lets an attacker withdraw money never deposited.
CCIP 2.0 retains Chainlink's default quorum of 16 independent node operators, which must agree on every transfer. The upgrade adds an opt-in path for protocols to run additional verifiers or hire outside providers including Infosys and Nethermind.
Chainlink is best known as an oracle network, feeding blockchains outside data such as asset prices that lending and trading apps depend on. CCIP extends that infrastructure into token and message movement between chains.
What does the Kelp DAO exploit have to do with it?
CoinGecko data showed nearly half of active LayerZero applications relied on a one-verifier setup at the time of the April hack. LayerZero publicly blamed Kelp for the configuration. Kelp said LayerZero staff had reviewed the setup and never objected.
Following the exploit, Kelp said it would migrate rsETH to Chainlink's CCIP, marking a high-profile defection for LayerZero's bridging business.
"Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive," Johann Eid, Chainlink Labs' chief business officer, said in a statement.
Users shouldn't have to be "cross-chain security infrastructure experts," the company told CoinDesk.
What happens to the Risk Management Network?
The upgrade retires a feature Chainlink previously promoted as a primary safeguard. The Risk Management Network — a separate node set that double-checked transfers — no longer serves that role under CCIP 2.0. Chainlink said independent checks can now come from the optional verifiers instead.
The result: a user who adopts no additional verifiers now relies on one 16-operator network where previously there were two. Existing integrations continue to operate without changes, Chainlink said.
The company has not named any institution using the new verifier tier. It said Aave and Maple have begun adopting other CCIP 2.0 features, including broader tooling around the upgrade. Neither protocol has confirmed whether it will route optional verifiers through external providers.
Like LayerZero's full stack, CCIP 2.0 gives protocols the option to assemble a customized verification stack. The structural difference is the default: a 16-operator quorum on Chainlink's side versus LayerZero's configurable model where many apps still rely on a single verifier.
The structural change leaves secondary verification in protocols' hands. CCIP 2.0's near-term traction will hinge on whether the first wave of institutional adopters — none yet named — route transfers through outside providers like Infosys and Nethermind, or simply accept the 16-operator default alone.
via CoinDesk (Source)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles