- Chainlink released Cross-Chain Interoperability Protocol 2.0 on Monday, letting companies add their own security checks to transfers between blockchains. These sit on top of a default network of 16 independent node operators that must reach a quorum on every transfer, and companies can run verifiers themselves or hire outside providers including Infosys and Nethermind.
- The launch comes five months after the largest DeFi exploit of the year. Attackers allegedly linked to North Korea Lazarus Group took about $292 million in rsETH from Kelp DAO bridge, which ran on rival LayerZero and depended on a single verifier.
- Responsibility remains disputed. LayerZero blamed Kelp for using one verifier rather than several, while Kelp said LayerZero staff had reviewed the configuration without objecting. CoinGecko data showed nearly half of active LayerZero applications used the same single-verifier arrangement, and Kelp said it would move rsETH to Chainlink.
- The upgrade also retires a safeguard Chainlink previously promoted heavily. Its Risk Management Network, a separate set of nodes that double-checked transactions, no longer performs that function, with Chainlink saying equivalent independent checking can now come from the optional verifiers instead.
What Happened?
Blockchains cannot communicate directly, so moving a token between them requires a bridge, and bridges depend on verifiers confirming that a transaction genuinely occurred on the originating chain before funds are released on the destination chain. If a verifier is deceived, an attacker can withdraw funds that were never deposited. Chainlink, best known as an oracle network supplying outside data such as asset prices to lending and trading applications, extended into token and message transfer with CCIP in 2023. Johann Eid, chief business officer at Chainlink Labs, said legacy bridges have lost billions through insecure infrastructure while building in-house is slow and costly, and the company said users should not have to be cross-chain security experts. Existing integrations continue working without changes.
Why It Matters?
The default configuration got weaker even as the optional configuration got stronger, and that distinction is the one institutions should focus on. Retiring the Risk Management Network means a user who adds nothing now relies on a single verifier network where two existed before. Chainlink reasonable counterpoint is that the remaining network comprises 16 operators requiring quorum rather than the single verifier that failed at Kelp, so the absolute security level is not comparable. But the direction of travel matters because defaults are what most users actually run. The Kelp episode demonstrated exactly that: nearly half of active LayerZero applications were using the minimum configuration, which is what made one failure a $292 million event rather than an isolated one. Moving protection into an optional tier assumes users will opt in, and the evidence from the rival platform is that most do not. Adoption remains unproven on the security feature specifically. Chainlink has named no institution using the new verifiers, and the two protocols cited, Aave and Maple, are described as adopting other features of the upgrade. Infosys appearing as a verifier provider is the more interesting signal, since a listed enterprise IT services firm taking a role in blockchain transaction verification indicates institutional infrastructure forming around this market. For anyone assessing tokenization and cross-chain settlement, bridge security is the concentrated point of failure, and it is where state-linked theft has focused, consistent with reporting that sanctioned entities received 694% more crypto during 2025.
What Next?
The measure that matters is how many users actually configure additional verifiers rather than accepting the default, and Chainlink naming institutional adopters would be the first evidence. Watch whether Kelp completes its stated move of rsETH to Chainlink, as that would be a visible endorsement from the party that suffered the loss. Track whether LayerZero changes its own defaults in response, since nearly half its applications were running the configuration that failed. On the enterprise side, whether Infosys or Nethermind sign named clients as verifier operators will show if outsourced verification becomes a real business. The unresolved dispute between LayerZero and Kelp over who approved the setup is also worth following, because liability for bridge configuration is an open question that will eventually be settled somewhere other than in blog posts.
Affected Tickers and Coins: LINK, AAVE, ETH, INFY
Source: CoinDesk












