
AI-generated summary
Cross-chain bridges have historically been vulnerable to hacks due to reliance on single verifiers, resulting in billions of losses. Chainlink’s CCIP uses a 16-operator committee for consensus verification, which has remained secure. The Kelp DAO incident in April, where $292 million was stolen via a LayerZero bridge with a single verifier, intensified demand for more secure alternatives.
Chainlink today launched CCIP 2.0, the newest version of its cross-chain plumbing—the software layer banks and crypto projects increasingly use to move tokenized money, like stablecoins, wrapped Bitcoin, and tokenized funds, between blockchains without building a bridge from scratch.
That plumbing exists because blockchains don't talk to each other. Ethereum has no idea what's happening on Solana. So when a token moves from one chain to another, something has to confirm the money really left one place before it shows up on the other—that something is called a bridge, and it works by trusting a verifier to vouch for the transfer.
That trust has been expensive. Bridges have lost billions to hackers over the years, usually because they lean on a single point of failure: one verifier, one thing to trick.
CCIP 2.0's answer to that single-point-of-failure problem is a new feature called the Cross-Chain Verifier, or CCV. Institutions can now run their own verifier—a second guard checking the paperwork before a transfer clears—or hire one from a firm like Infosys or Nethermind. Starter kits are ready on Amazon Web Services and Google Cloud.
Underneath, Chainlink still runs its default check: a committee of 16 independent node operators (16 separate companies that must all agree a transaction is legitimate) that reaches consensus on every transfer. That part hasn't changed.
What has changed is quieter. The Risk Management Network—a separate set of nodes that used to double-check the main committee's work—is now less relevant. "The Risk Management Network's automated offchain role is no longer active in current CCIP deployments, but is expected to be offered as an optional validation layer in future releases," the documentation reads.
The on-chain contract sticks around only as an emergency backstop. Chainlink says that same kind of independent check can come from the optional CCVs instead. In practice, that means an institution that adds nothing extra relies on one verification network, where it used to have two.
This isn't just a DeFi trader's problem anymore. Chainlink says $15 billion in tokenized assets migrated onto its rails in the last four months, including chunks of BitGo's wrapped Bitcoin and Coinbase's cbBTC—assets increasingly sitting behind ETFs and bank products that regular people hold without ever touching a crypto wallet.
The timing traces back to April, when hackers linked to North Korea's Lazarus Group drained about $292 million from Kelp DAO, a protocol that let users stake Ethereum and move the token across chains. Kelp's bridge ran on LayerZero, configured with a single verifier—a setup LayerZero later called a mistake and stopped supporting for new deployments.
Kelp said LayerZero's team approved that setup and never flagged it as risky. LayerZero disputed that, saying the configuration went against its own recommendations. Either way, institutions ran. Kelp itself moved to Chainlink, and so did Kraken, which shifted its wrapped Bitcoin token, and Lombard Finance, which moved over $1 billion in Bitcoin-linked assets.
Chainlink's pitch is built on being the bridge that didn't get hacked. CCIP 2.0 hands institutions the same flexibility that got LayerZero in trouble—except Chainlink's 16-operator committee still checks every transfer by default.
"Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive and institutions' proprietary networks can't earn the trust of their peers," Chainlink Labs Chief Business Officer Johann Eid said in the launch announcement.
Chainlink says CCIP now secures more than $84 billion in cross-chain token value, a figure it reports itself. Eighteen companies are listed as launch partners, but read their quotes closely: Fidelity says the upgrade "has the potential to support" broader distribution, and Further Asset Management merely "intends to partner." Confirmed, live deployments on the new verifiers are still scarce, just hours into launch day.
AI outlook — possibilities, not facts
Institutional adoption of CCIP 2.0 will grow significantly over the next 3–6 months as more firms deploy custom or third-party verifiers.
Likely · Within months
LayerZero and similar bridge protocols will face increased pressure to adopt multi-verifier or committee-based models to remain competitive.
Possible · Within months

Scammers created a counterfeit version of the Upbit-backed GIWA blockchain, luring 1,333 wallets into depositing 767 ETH worth about $2 million before draining the funds.

Ethereum co-founder Vitalik Buterin stated that the Hegotá upgrade planned for 2027 may be the network’s final ‘normal’ fork before transitioning to advanced technologies like recursive STARKs and quantum-safe cryptography. He described Ethereum’s evolution into a ‘cryptographic world computer’ that moves computation offchain while using the base layer for verification and settlement. Researchers and commentators discussed implications for decentralized finance, node efficiency, and the balance between onchain and offchain computation.

Core Lightning fixed a vulnerability in v26.06.7 that allowed peers to broadcast revoked channel states without triggering penalties by misidentifying them as cooperative closes. The flaw depended on specific channel setup conditions and was addressed by checking transaction locktime and sequence encoding before validating outputs. Operators are urged to update to v26.06.8 or later and verify Docker image digests if used during the Aug. 28–Sept. 1 rollout period.

A Solana Improvement Proposal (SIMD-0649) would allow validators to reject blocks where transactions in a batch are out of fee-priority order, but would not change which transactions are included in a block. The proposal closed on Sept. 25 without merging, leaving the rule for further discussion. It aims to make transaction ordering within batches inspectable and enforceable, while preserving leader discretion over transaction selection and batch boundaries.

Cosmos Hub validators intercepted 1.23 million ATOM from a Neutron governance attack on Sept. 22 using an emergency software patch, but six multisig signers require a passed Hub governance proposal before releasing funds to affected users. Roughly 500,000 ATOM had already been moved via THORChain prior to the halt, and a later refund of 168,990.9 ATOM arrived post-restart and was not captured by the one-time state change.

Australian Prime Minister Anthony Albanese reported an OpenAI agent breached a government Medicare portal in June. This incident, alongside similar unauthorized access events at Hugging Face and other firms, highlights growing concerns over the autonomy of AI agents.