Partner · Blockchain Life 2026 — Dubai, December 1–2 · 15,000+ attendees from 130+ countriesGet tickets →
LIVE
BTC—ETH—SOL—BNB—XRP—ADA—AVAX—DOGE—LINK—DOT—MATIC—ATOM—LTC—TRX—TON—BTC—ETH—SOL—BNB—XRP—ADA—AVAX—DOGE—LINK—DOT—MATIC—ATOM—LTC—TRX—TON—
—▲0.0%
Blockchain

Chainlink's CCIP 2.0 Lets Apps Add Their Own Cross-Chain Verifiers

29 Sept 2026by CryptoJazz Admin1 min read27 views
Chainlink's CCIP 2.0 Lets Apps Add Their Own Cross-Chain Verifiers

Chainlink released CCIP 2.0 on Monday and changed how its cross-chain messages are checked. Applications can now add verifiers of their own over the default set of 16 independent node operators, or pay a third party to run them. The separate Risk Management Network, which had provided a second confirmation on every transfer, is gone; the optional verifiers take over that job. Existing integrations were moved to the new version automatically, on accounts from Cryptowisser and Bloomingbit. Chainlink says the protocol secures $84 billion of cross-chain token value, a figure no outlet in this sweep checked.

A verifier, and where it sits

Chainlink calls them Cross-Chain Verifiers, or CCVs. In the company's own description, a CCV independently verifies a cross-chain transaction and cryptographically signs it before the destination chain executes anything. An organization can run one on its own hardware or in the cloud, and Chainlink says it ships starter kits for AWS and Google Cloud. The effect is that a bank or a lending protocol no longer has to accept a single shared security assumption for every message it sends. The default 16 still verify everything. What changes is what may sit above them.

The partner list does not reconcile

Who is actually using this depends on the account. Chainlink's announcement names Infosys, Further Asset Management and Nethermind around CCV infrastructure, and says Lombard has adopted CCV-enabled verification. CoinDesk, publishing at 8:30 a.m. Eastern on Monday and updating at 10:56, names Infosys and Nethermind as external providers and puts Aave and Maple among the applications that have taken up some of the upgrade's features. That same CoinDesk report says no institution has yet been announced as using the new external verifier option, a line Bloomingbit and Cryptowisser both carry. Adopting a feature and running an external verifier are separate things, and no piece here draws the line between them. We could not establish which account is current.

Johann Eid, chief business officer at Chainlink Labs, set the release against the two alternatives.

"Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive," Eid said.

Cryptonomist carries that sentence whole. CoinDesk stops after the first clause.

The exploit behind the redesign

The release lands five months after April's loss of $292 million in rsETH, drained across 20 chains by exploiting a single-verifier configuration on a LayerZero bridge. Three outlets here give that figure and none disputes it. Cryptonomist, citing CoinDesk, puts close to half of active LayerZero applications on a single-verifier setup at the time, and that count stands on one outlet. Responsibility is contested. LayerZero has said Kelp DAO should have used multiple verifiers, and Kelp DAO has said LayerZero staff reviewed the configuration without objecting, an exchange Cryptowisser reports and the tier-1 piece here does not. The argument is now in front of a Vancouver court.

The part that stays voluntary

Cryptonomist reports that Kelp DAO is migrating rsETH to Chainlink, which no other outlet in this sweep confirms. Chainlink's own post puts more than $15 billion migrated onto CCIP in the past four months, again with no corroboration. The competitive backdrop is visible elsewhere, and LayerZero ends its offchain service for 13 chains on 30 September.

Optional security is still optional. An application that leaves the defaults alone after Monday has the same 16 operators it had on Friday, minus the Risk Management Network's second look, and Chainlink has not published what share of traffic now runs with an extra verifier attached. That number is the one that would show whether the redesign changed anything.

Read also: Switchboard Oracle Ends Support September 25, Points Users to Pyth

← All news