Chainlink CCIP 2.0 Adds Issuer-Controlled Transfer Gates
Required verifier checks can leave a transfer pending after tokens are locked or burned, making operator uptime and approval rules part of the holder’s exit path.
Every Zipp story tagged #BridgeSecurity, newest first.
Required verifier checks can leave a transfer pending after tokens are locked or burned, making operator uptime and approval rules part of the holder’s exit path.
The upgrade gives users more control over bridge verification, but Chainlink's separate Risk Management Network no longer provides a second check.
Using GIWA’s expected Chain ID, attackers made a counterfeit network look credible. The incident shows that a matching chain identifier does not authenticate the RPC endpoint or bridge users connect…
The dispute puts bridge security design and LayerZero’s alleged assurances under scrutiny, as KelpDAO says users have withdrawn more than $650M since the attack.
The April 22 attack drained 116,500 rsETH and helped trigger a $20B DeFi deposit exodus, putting bridge security and accountability under scrutiny.
The lawsuit puts bridge security and responsibility for the exploit at the center of a dispute involving LayerZero and its co-founder.
Two prior audits cleared the affected code; the bug only surfaced when signature verification, replay protection, and transaction execution were tested together as a system rather than three separate…
A 29 Fear reading and Boltz's shutdown after AI-assisted attacks add to a defensive backdrop, while the SEC delay keeps tokenized-securities progress in focus.
The episode turns a planned L2 shutdown into a test of bridge reliability and user exit procedures across DeFi.
The pivot is structural: $650M in 2025 bridge exploits is rerouting institutional and DeFi traffic to CCIP, with DTCC and Fidelity now onboarding alongside Mantle, Lombard and KelpDAO.
A five-week warning window, then forced withdrawal: the failure puts a spotlight on the part of rollup security that usually stays invisible, namely what happens when the bridge layer itself breaks.
The attacker rapidly shifted the stolen value from Solana to Ethereum and converted it into ETH, extending the incident across two major ecosystems.
Liquidity providers in affected pools were urged to withdraw funds after the attacker moved the stolen assets from Solana to Ethereum.
The migration is the latest signal that bridge security, not throughput, is the binding constraint for institutional tokenised assets, with Mantle alone moving $2.5B into the CCIP stack.
The $3,000 server that proved it is the story: a near-90% success rate against Move's type-system guarantees, patched in hours, but the systemic risk surface runs through bridges, USDC minting, and…
Another 2026 bridge exploit — but this one isn't a smart-contract bug. Researchers say the attacker walked in through the authorization layer, the same weak seam hit in Kelp DAO and Resolv earlier…
Gravity Bridge, the cross-chain protocol connecting Cosmos-based networks to Ethereum, was drained of $5.4 million…
The KelpDAO exploit cracked open LayerZero's verification model in public — and more than $3B in DeFi TVL is voting with its feet for Chainlink's CCIP.
The capital flight — triggered by April's $292M Kelp DAO exploit — is reshaping the cross-chain bridge market, with Chainlink's CCIP picking up clients and scrutiny that LayerZero once dominated.
After 116,500 rsETH were abnormally released in the April 18 bridge incident, the proposal leans on committed ETH funding plus a temporary oracle tweak to clear exploiter positions on Aave and…