Chainlink Empowers Institutions with Custom Bridge Security Post-Kelp Hack
UpGatePositiveTechnology innovation

Chainlink Empowers Institutions with Custom Bridge Security Post-Kelp Hack

Reading time: 4 min

Chainlink Unveils CCIP 2.0, Enhancing Cross-Chain Interoperability with New Security Features

Chainlink has launched CCIP 2.0, the latest iteration of its cross-chain communication protocol. This software layer is increasingly adopted by financial institutions and cryptocurrency projects to facilitate the transfer of tokenized assets, such as stablecoins, wrapped Bitcoin, and tokenized funds, across different blockchains without the need for custom-built bridges.

Blockchains, by nature, operate in isolation, meaning one network has no inherent knowledge of activity on another. When a token moves between chains, a mechanism is required to confirm its departure from the origin and its arrival at the destination. This is the role of a bridge, which relies on a verifier to validate the transfer.

However, this reliance on verifiers has proven costly. Bridges have been the target of numerous hacks, resulting in billions of dollars in losses, often due to a single point of failure—a lone verifier that can be compromised.

CCIP 2.0 addresses this vulnerability with a new feature called the Cross-Chain Verifier (CCV). This allows institutions to deploy their own verifiers, acting as a secondary check on transactions before they are finalized, or to engage third-party firms like Infosys or Nethermind to provide this service. Starter kits for implementation are available on Amazon Web Services and Google Cloud.

Underpinning these new options, Chainlink’s default security mechanism remains in place: a committee of 16 independent node operators, representing separate companies, must reach a consensus on the legitimacy of every transfer. This core consensus layer has not been altered.

More subtle changes have been made to the protocol’s architecture. The Risk Management Network, a separate set of nodes that previously served as a secondary validation layer for the main committee’s work, has been de-emphasized. According to the project’s documentation, “The Risk Management Network’s automated offchain role is no longer active in current CCIP deployments, but is expected to be offered as an optional validation layer in future releases.”

The on-chain contract now functions primarily as an emergency backup. Chainlink asserts that the independent verification previously provided by the Risk Management Network can now be replicated by the optional CCVs. In practice, this means institutions that do not opt for additional verification layers will rely on a single verification network, a reduction from the previous two.

The implications of these advancements extend beyond the decentralized finance (DeFi) community. Chainlink reports that $15 billion in tokenized assets have been moved across its network in the past four months, including significant portions of BitGo’s wrapped Bitcoin and Coinbase’s cbBTC. These are assets increasingly integrated into traditional financial products like ETFs and bank offerings, held by everyday investors who may not directly interact with cryptocurrency wallets.

The timing of this upgrade appears to be influenced by recent security incidents. In April, hackers attributed to North Korea’s Lazarus Group reportedly stole approximately $292 million from Kelp DAO, a protocol that enabled users to stake Ethereum and transfer the resulting tokens across blockchains. Kelp’s bridge was configured with a single verifier on the LayerZero protocol, a setup that LayerZero later acknowledged as a mistake and ceased supporting for new deployments.

Kelp stated that LayerZero’s team had approved the configuration and did not flag it as risky. LayerZero contested this, asserting that the setup deviated from its own recommendations. Regardless of the specifics, the incident prompted a significant migration of institutions. Kelp itself transitioned to Chainlink, as did Kraken, which moved its wrapped Bitcoin token, and Lombard Finance, which transferred over $1 billion in Bitcoin-linked assets.

Chainlink’s value proposition centers on its track record as a secure cross-chain solution. CCIP 2.0 offers institutions the flexibility that contributed to LayerZero’s challenges, but with the added assurance that Chainlink’s 16-operator committee still validates every transfer by default.

“Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive and institutions’ proprietary networks can’t earn the trust of their peers,” said Johann Eid, Chief Business Officer at Chainlink Labs, in the launch announcement.

Chainlink claims that CCIP currently secures over $84 billion in cross-chain token value, a figure it self-reports. While eighteen companies are listed as launch partners, their statements suggest varying levels of commitment. Fidelity noted the upgrade “has the potential to support” broader distribution, while Further Asset Management indicated it “intends to partner.” As of launch day, confirmed, live deployments utilizing the new verifiers remain limited.

Tags:UpGatePositiveTechnology innovation
Copied