Chainlink released CCIP 2.0 on Monday, making cross-chain security an optional module: enterprises can add their own validators on top of the default 16 independent node network. The trade-off is that the original Risk Management Network’s independent recheck is cancelled—if you add nothing, cross-chain transfers are left with just a single layer of validation, whereas before there were two sets. The backdrop is the April attack on the Kelp DAO: the attacker minted 116,500 rsETH out of thin air within 46 minutes—about $292 million—then took out loans using the minted rsETH as collateral to borrow real assets; that bridge relied on a single validator. My take: making security optional effectively pushes risk pricing onto the integrators, and most teams have little incentive to pay extra—so the default configuration will become the greatest common denominator. The key question about $LINK is whether this upgrade will draw institutional adoption; so far, no institution has been named as using it. Would you add an extra validator layer beyond the default?