Loading prices…
🔥BULLISH

Chainlink Adds Custom Security Checks to CCIP 2.0 After $292M Hack

The upgrade gives users more control over bridge verification, but Chainlink's separate Risk Management Network no longer provides a second check.

Chainlink Adds Custom Security Checks to CCIP 2.0 After $292M Hack
Chainlink Adds Custom Security Checks to CCIP 2.0 After $292M Hack
Chainlink Adds Custom Security Checks to CCIP 2.0 After $292M Hack
Chainlink Adds Custom Security Checks to CCIP 2.0 After $292M Hack

Chainlink released CCIP 2.0, adding optional custom security checks to cross-chain transfers on top of its default network of 16 independent node operators. The update follows April's $292 million Kelp DAO exploit, which was blamed on a LayerZero bridge setup that relied on a single verifier.

Why it matters

Bridges use verifiers to confirm that a transaction occurred on one blockchain before releasing funds on another. If a verifier is compromised or fooled, attackers can take funds that were never deposited. The Kelp attack put the risks of relying on one verifier in sharp focus: attackers allegedly linked to North Korea's Lazarus Group drained about $292 million in rsETH. LayerZero blamed Kelp's single-verifier configuration, while Kelp said LayerZero staff had reviewed it without objecting. Kelp later said it would move rsETH to Chainlink.

CCIP 2.0 lets companies add their own verifiers or use outside providers such as Infosys and Nethermind. Chainlink's 16-operator network still checks every transfer, regardless of whether users add other verifiers. The change also removes the separate role previously played by Chainlink's Risk Management Network. Chainlink says independent checks can now come from optional verifiers, meaning users who add none appear to rely on one verification network rather than two.

Market impact

The upgrade shifts more responsibility for layered verification to CCIP users. Chainlink has not named an institution using the new verifiers; Aave and Maple have started adopting other features in the upgrade. Existing Chainlink users were automatically moved to CCIP 2.0, so adoption of additional checks will be an important measure of how the new security model is used.

Related tokens
$LINK

Frequently asked questions

  1. What security feature does Chainlink CCIP 2.0 add?

    CCIP 2.0 lets companies add custom security checks to cross-chain transfers, using their own verifiers or outside providers alongside Chainlink's 16-operator network.

  2. How did the Kelp DAO exploit relate to bridge verification?

    The April exploit drained about $292 million in rsETH from a LayerZero bridge setup that relied on a single verifier. The attackers allegedly tricked that verifier.

  3. What changed about Chainlink's Risk Management Network?

    It no longer acts as a separate safeguard that double-checks transfers. Chainlink says independent checks can now come from optional verifiers.

  4. What happens if a CCIP user does not add custom verifiers?

    Such users appear to rely on Chainlink's 16-operator verification network rather than the two separate networks that previously checked transfers.

  5. Have institutions adopted CCIP 2.0's new verifiers?

    Chainlink has not named any institutions using the new verifiers. Aave and Maple have started adopting other features in the upgrade.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 49m ago
Open original →