Chainlink Rolls Out CCIP 2.0, Letting Institutions Run Their Own Bridge Verifiers
Key Takeaways
- •Chainlink's CCIP 2.0 debuts the Cross-Chain Verifier feature, enabling institutions to operate their own verifiers or contract providers such as Infosys and Nethermind, with starter kits offered on AWS and Google Cloud.
- •Chainlink's documentation states that the Risk Management Network's automated offchain role is inactive in current CCIP deployments, leaving institutions that add no extra verifier dependent on a single verification network until an optional layer ships in future releases.
- •The launch arrives five months after hackers linked to North Korea's Lazarus Group drained roughly $292 million from LayerZero-based Kelp DAO, a breach that prompted Kraken and Lombard Finance to shift assets to Chainlink.
- •Chainlink says $15 billion in tokenized assets migrated onto its rails over the past four months, including portions of BitGo's wrapped Bitcoin and Coinbase's cbBTC, while its CCIP system secures a self-reported $84 billion in cross-chain token value.
- •Eighteen companies are listed as launch partners, but commitments vary in firmness—Fidelity says the upgrade only has potential to support broader distribution—and confirmed live deployments on the new verifiers remained scarce hours after launch.

Chainlink launched CCIP 2.0 on Monday, introducing an upgrade that lets institutions operate their own custom verifiers for cross-chain transfers rather than depending solely on Chainlink's default network. The release arrives five months after Kelp DAO, a protocol built on LayerZero, lost $292 million to hackers linked to North Korea—a breach that drove Kraken and Lombard Finance to migrate to Chainlink.
Chainlink's own documentation confirms a quieter change alongside the headline feature. "The Risk Management Network's automated offchain role is no longer active in current CCIP deployments," according to Chainlink's technical documentation, ending that system's role as an independent second check on transfers.
What CCIP 2.0 does
CCIP 2.0 is the newest version of Chainlink's cross-chain infrastructure—the software layer that banks and crypto projects increasingly use to move tokenized money, such as stablecoins, wrapped Bitcoin, and tokenized funds, between blockchains without building a bridge from scratch, per Chainlink's launch announcement.
The infrastructure exists because blockchains do not communicate with each other: Ethereum has no visibility into what happens on Solana. When a token moves between chains, something must confirm that the funds actually left one network before they appear on the other. That task falls to a bridge, which relies on a verifier to vouch for each transfer.
That trust model has proven costly. Bridges have lost billions of dollars to hackers over the years, typically because they depend on a single point of failure—one verifier, one thing to trick.
Custom verifiers arrive
CCIP 2.0's answer to that vulnerability is a new feature called the Cross-Chain Verifier (CCV). Institutions can now run their own verifier—a second guard reviewing the paperwork before a transfer clears—or contract one from a firm such as Infosys or Nethermind. Starter kits are available on Amazon Web Services and Google Cloud.
Beneath that, Chainlink still runs its default check: a committee of 16 independent node operators—16 separate companies that must all agree a transaction is legitimate—that reaches consensus on every transfer. That component has not changed.
What has changed is less visible. The Risk Management Network, a separate set of nodes that previously double-checked the main committee's work, is being scaled back. "The Risk Management Network's automated offchain role is no longer active in current CCIP deployments, but is expected to be offered as an optional validation layer in future releases," the documentation reads.
The network's on-chain contract remains only as an emergency backstop. Chainlink says an equivalent independent check can now come from the optional CCVs instead. In practice, an institution that adds nothing extra relies on one verification network where it previously had two.
Billions in tokenized assets
The stakes now extend beyond DeFi traders. Chainlink says $15 billion in tokenized assets migrated onto its rails in the last four months, including portions of BitGo's wrapped Bitcoin and Coinbase's cbBTC—assets increasingly held behind ETFs and bank products by people who never touch a crypto wallet.
The backdrop dates to April, when hackers linked to North Korea's Lazarus Group drained roughly $292 million from Kelp DAO, a protocol that let users stake Ethereum and move the resulting token across chains. Kelp's ran on LayerZero and was configured with a single verifier—a setup LayerZero later called a mistake and stopped supporting for new deployments.
Kelp said LayerZero's team had approved that configuration and never flagged it as risky. LayerZero disputed the account, saying the setup contradicted its own recommendations.
Either way, institutions fled. Kelp itself moved to Chainlink, as did Kraken, which shifted its wrapped Bitcoin token, and Lombard Finance, which transferred more than $1 billion in Bitcoin-linked assets.
Chainlink's pitch rests on being the bridge that has not been hacked. CCIP 2.0 now hands institutions the same flexibility that got LayerZero into trouble—except Chainlink's 16-operator committee still checks every transfer by default.
"Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive and institutions' proprietary networks can't earn the trust of their peers," Chainlink Labs Chief Business Officer Johann Eid said in the launch announcement.
Chainlink says CCIP now secures more than $84 billion in cross-chain token value, a self-reported figure. Eighteen companies are listed as launch partners, though the commitments vary in firmness: Fidelity says the upgrade "has the potential to support" broader distribution, while Further Asset Management "intends to partner." Confirmed live deployments on the new verifiers remained scarce just hours into day. How quickly those named partners convert stated intent into verifiers running in production—and whether Chainlink ships the optional Risk Management Network layer its documentation says is expected in future releases—are the most direct signals of how much of the new architecture institutions actually put to use.
This article is based on Decrypt's original report.