January 16, 2026, 21:28 UTC. Nine thousand DUSK leave a compromised signing wallet. By 23:12 the bridge is off, and the attacker's last move, 8.91M DUSK, fails because there's nothing running to sign it. @Dusk published the full timeline, tx hashes included.

My take: that post-mortem is the best argument for a decision Dusk had already made two months earlier. In November 2025, Dusk and NPEX picked Chainlink CCIP as their canonical cross-chain layer rather than maintaining bridge code themselves. The incident didn't cause that call. It just made the reasoning legible.

What gets outsourced there is transport, not control. CCIP reaches 65+ chains today, and the CCT standard moves DUSK between networks like Ethereum and Solana on a burn and mint model. Dusk and NPEX keep ownership of the token contracts.

One line from the rebuilt bridge stuck with me: ingestion is no longer equivalent to spending. Events get checkpointed, persisted as jobs, and a separate worker does the spending. Receiving an instruction stopped being authority to move money.

Same idea on the data side. Chainlink DataLink is meant to publish official NPEX exchange data onchain as the exclusive oracle, with Data Streams handling low-latency updates. My day job is testing a securities trading app, and the number on a user's screen was never just a price. It's a licensed feed from a named venue, and at end of day we reconcile against the exchange's official figures, never against an aggregator. Provenance is the product.

Where I'd hold back: both data integrations were written in future tense in November 2025, and I can't point at a live NPEX feed today. Every integration announcement reads as inevitable until it isn't. $DUSK pays gas and secures the network through staking.

Back to 23:12. What saved that last 8.91M DUSK was a fast off switch, not clever code. If your system had to fail closed right now, which component would you still have to shut by hand?

#dusk