Months After the $292M Kelp Hack, Chainlink Lets Institutions Add Their Own Bridge Checks

Chainlink launched CCIP 2.0, an upgrade to its cross-chain messaging protocol that lets institutions run their own custom verifiers (Cross-Chain Verifiers, or CCVs) or hire third-party verifiers for transfer checks. The release comes five months after a LayerZero-linked bridge used a single verifier and lost $292 million in the Kelp DAO hack; Chainlink says its default 16-operator committee still provides primary verification for transfers.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 2 hours agoUpdated about 2 hours ago0 views
Months After the $292M Kelp Hack, Chainlink Lets Institutions Add Their Own Bridge Checks

Why It Matters

The change gives banks and custodians more control over cross-chain validation at a time when tokenized assets are moving into mainstream financial products, and follows a high-profile $292 million exploit that exposed risks from single-verifier bridge setups. How institutions adopt optional CCVs could affect the security posture of major token flows that now sit behind ETFs and bank products.

Key Facts

  • Product: Chainlink CCIP 2.0
  • New feature: Cross-Chain Verifier (CCV) allowing institutions to run or procure custom verifiers
  • Default verification: Committee of 16 independent node operators remains Chainlink's primary verifier
  • Risk Management Network: Its automated offchain role is no longer active in current CCIP deployments (per Chainlink docs)
  • Hack referenced: $292 million Kelp DAO loss (April), linked to North Korea's Lazarus Group

Chainlink rolled out CCIP 2.0, a major update to its Cross-Chain Interoperability Protocol that adds a new Cross-Chain Verifier (CCV) feature. CCVs let institutions run their own verification software as a second check on cross-chain transfers, or hire verification services from firms such as Infosys or Nethermind. Starter kits for building verifiers are available on cloud platforms including Amazon Web Services and Google Cloud. Under CCIP 2.0, Chainlink continues to use its existing default verification layer: a committee of 16 independent node operators that must reach consensus before a transfer is finalized. However, documentation indicates that the Risk Management Network, which previously provided an independent off-chain secondary check, is no longer active in current deployments; Chainlink says that independent validation can now be provided via optional CCVs and that the on-chain contract remains as an emergency backstop. The upgrade arrives amid heightened institutional focus on bridge security after a high-profile exploit in April, when about $292 million was stolen from Kelp DAO—a protocol tied to LayerZero that used a single-verifier configuration. That incident prompted migrations by Kelp itself and by other projects, with Kraken and Lombard Finance among entities that moved assets onto Chainlink's infrastructure. Chainlink reports $15 billion of tokenized assets migrated onto its rails in the past four months and states CCIP now secures more than $84 billion in cross-chain token value. Chainlink lists 18 launch partners for the CCIP 2.0 release and cites examples of assets already using its network, including portions of BitGo's wrapped Bitcoin and Coinbase's cbBTC. The company frames CCIP as a more secure alternative to legacy bridge models that have frequently relied on single points of failure; confirmed live deployments using the new optional verifier configurations were limited in the hours immediately after launch.

Keep Reading