UK Edition

Monday, 28 September 2026

Time Trade

Markets, trading & finance — British perspective

Crypto

Chainlink updates its crypto bridge tech months after a $292 million hack at a rival exposed risks

· CoinDesk

The new software lets companies add custom security checks so they do not fall victim to the same single-point-of-failure vulnerabilities that plagued rival bridges.

  • Chainlink released CCIP 2.0, which lets companies add their own security checks to transfers between blockchains on top of Chainlink's default 16-operator verifier network.
  • The launch follows April's $292 million Kelp DAO hack, which was blamed on a LayerZero bridge setup that relied on a single verifier. Kelp later moved its rsETH token to Chainlink.
  • Chainlink's Risk Management Network no longer works as a separate safeguard, so users who don't add their own verifiers appear to rely on one verification network instead of two.

Chainlink released Cross-Chain Interoperability Protocol (CCIP) 2.0 on Monday, delivering a major upgrade to its communication and bridging infrastructure that lets different blockchains talk to each other and swap funds.

It lets companies add their own security checks to those transfers, with the launch coming five months after the year's biggest DeFi hack, blamed on a bridge that relied on just one of those checks.

Chainlink is best known as an oracle network, feeding blockchains outside data such as asset prices that lending and trading apps depend on. CCIP, first launched in 2023, extends into moving tokens and messages between chains.

Blockchains can't communicate directly, so moving a token from one to another depends on a bridge. The technology relies on verifiers, which confirm that a transaction really happened on the first chain before funds are released on the second. If a verifier is fooled, an attacker can withdraw money that was never deposited.

That is what happened to Kelp DAO in April. Attackers allegedly linked to North Korea's Lazarus Group drained about $292 million in rsETH from Kelp's bridge, which ran on LayerZero, after tricking the single verifier the setup relied on.

LayerZero blamed Kelp for using one verifier instead of several, while Kelp said LayerZero staff had reviewed its setup and never objected. CoinGecko data showed nearly half of active LayerZero apps used the same one-verifier arrangement, and Kelp said it would move rsETH to Chainlink.

CCIP 2.0 offers a similar menu of verifiers, which lets companies run their own or hire outside providers such as Infosys and Nethermind. Chainlink's own network of 16 independent node operators still checks every transfer, regardless of what else a user adds.

Users shouldn't have to be "cross-chain security infrastructure experts," the company told CoinDesk.

"Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive," Johann Eid, Chainlink Labs' chief business officer, said in a statement.

The upgrade also changes a safeguard Chainlink used to promote heavily; its Risk Management Network, a separate set of nodes that double-checked transactions, no longer plays that role. Chainlink said that kind of independent check can now come from the optional verifiers instead, which suggests a user who adds nothing now relies on one verifier network, where previously there were two.

Existing Chainlink users were automatically moved to the new version. Still, the company has not named any institution using the new verifiers yet, saying only that Aave and Maple have started adopting some of the upgrade's other features.

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.