"Chainlink launched CCIP 2 on Monday, a major upgrade to its cross-chain interoperability and bridge infrastructure. According to ChainCatcher, the new version lets enterprises add their own security verification checks on top of Chainlink’s default network of 16 independent node operators, with companies able to run their own validators or hire outside providers such as Infosys and Nethermind.
The upgrade comes about five months after Kelp DAO was hacked in April. Attackers allegedly linked to North Korea’s Lazarus group tricked a single validator used by Kelp’s cross-chain bridge and stole about $292 million worth of rsETH from a bridge running on LayerZero. LayerZero blamed Kelp for using only one validator, while Kelp said LayerZero staff had reviewed its setup and raised no objections. Kelp later said it would migrate rsETH to Chainlink.
Chainlink also changed a safeguard it had previously promoted heavily. Its risk management network will no longer operate as" means that Chainlink has upgraded its CCIP bridge system to give institutions more control over how cross-chain transfers are verified.
In simple terms, a cross-chain bridge moves tokens or data between different blockchains. Because bridges are frequent targets for attackers, Chainlink CCIP 2 allows an enterprise to add extra security reviewers—either its own validators or external firms—on top of Chainlink’s standard group of 16 independent node operators.
The Kelp DAO incident is used as an example of why this matters: its bridge reportedly relied on just one validator, creating a single point of failure. If that one verifier is deceived or compromised, a fraudulent transfer may be approved. Using multiple independent validators can reduce this type of risk, although it cannot eliminate all security risks.
The unfinished final sentence refers to another important change: Chainlink’s separate risk-management review layer will no longer automatically act as an additional independent check. Instead, extra checks will be optional through added validators.
The upgrade comes about five months after Kelp DAO was hacked in April. Attackers allegedly linked to North Korea’s Lazarus group tricked a single validator used by Kelp’s cross-chain bridge and stole about $292 million worth of rsETH from a bridge running on LayerZero. LayerZero blamed Kelp for using only one validator, while Kelp said LayerZero staff had reviewed its setup and raised no objections. Kelp later said it would migrate rsETH to Chainlink.
Chainlink also changed a safeguard it had previously promoted heavily. Its risk management network will no longer operate as" means that Chainlink has upgraded its CCIP bridge system to give institutions more control over how cross-chain transfers are verified.
In simple terms, a cross-chain bridge moves tokens or data between different blockchains. Because bridges are frequent targets for attackers, Chainlink CCIP 2 allows an enterprise to add extra security reviewers—either its own validators or external firms—on top of Chainlink’s standard group of 16 independent node operators.
The Kelp DAO incident is used as an example of why this matters: its bridge reportedly relied on just one validator, creating a single point of failure. If that one verifier is deceived or compromised, a fraudulent transfer may be approved. Using multiple independent validators can reduce this type of risk, although it cannot eliminate all security risks.
The unfinished final sentence refers to another important change: Chainlink’s separate risk-management review layer will no longer automatically act as an additional independent check. Instead, extra checks will be optional through added validators.