Chainlink launches CCIP 2.0, introducing custom verifiers that let institutions run their own security checks on top of Chainlink's default 16-operator network. The upgrade follows April's $292 million Kelp DAO hack, which exposed the risks of single-verifier bridges. While CCIP 2.0 adds flexibility and embedded compliance controls, it quietly deprecates the automated Risk Management Network, meaning users who do not configure custom verifiers now rely on one verification network instead of two.
Custom verifiers in CCIP 2.0
- ▪Chainlink’s CCIP 2.0 launched on September 28, 2026, letting institutions run or hire blockchain-transfer verifiers
- ▪Chainlink’s CCIP 2.0 custom verifiers supplement its 16 independent Committee Verifier nodes, whose consensus remains mandatory
- ▪Amazon Web Services and Google Cloud host starter kits for Chainlink's CCIP 2.0 Cross-Chain Verifiers, while firms like Infosys and Nethermind can be hired to run them
Changes to CCIP verification architecture
- ▪Without adding custom verifiers, institutions using CCIP 2.0 rely on Chainlink's single 16-operator committee network, whereas previous CCIP deployments utilized two separate networks for verification
- ▪Chainlink's Risk Management Network is no longer active as an automated off-chain double-check in current CCIP 2.0 deployments, leaving its on-chain contract as an emergency backstop
Compliance and execution controls
- ▪CCIP 2.0 allows asset issuers to choose execution paths, enabling faster execution for high-frequency transfers and requiring full finality or time-delayed approvals for high-value transactions
- ▪Chainlink’s CCIP 2.0 uses ACE for KYC, AML, sanctions screening and exposure limits in cross-chain transfers
CCIP adoption
- ▪Chainlink claims its Cross-Chain Interoperability Protocol secures more than $84 billion in total cross-chain token value as of September 28, 2026
- ▪Chainlink stated on September 28, 2026, that Aave, Maple, and reinsurance platform Re adopted the faster CCIP 2.0 option of the Cross-Chain Interoperability Protocol for their tokens
Debatable claims
- ▪Retiring the Risk Management Network compromises default security for Chainlink CCIP users
- ▪Chainlink's CCIP 2.0 is ready for widespread institutional adoption
- ▪Compliance controls should be embedded directly into cross-chain transfer protocols
- ▪Chainlink's default 16-operator committee provides sufficient security for institutional transfers
Story comments
Loading comments…