Invest1 publisher3 min readPublished
Chainlink's CCIP 2.0 hands the second bridge check to the institutions moving tokenized assets
Chainlink's CCIP 2.0 cuts a transfer's default checks from two networks to one and lets institutions add their own verifiers back. Paying for the second check now falls to the bank or issuer, five months after a single-verifier bridge setup cost Kelp DAO $292 million.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Current CCIP deployments no longer run the Risk Management Network's automated offchain role, according to Chainlink's docs, which expect it to return later as an optional layer.
- Institutions can run their own Cross-Chain Verifier or hire one from Infosys or Nethermind, with starter kits available on Amazon Web Services and Google Cloud.
- A default committee of 16 independent node operators, all of which must agree a transaction is legitimate, still checks every transfer.
- Chainlink says $15 billion in tokenized assets moved onto its rails in the past four months, including parts of BitGo's wrapped Bitcoin and Coinbase's cbBTC.
- Kelp, Kraken and Lombard Finance, which moved over $1 billion in Bitcoin-linked assets, switched to Chainlink after April's hack on Kelp's LayerZero bridge.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Holders of ETFs and bank products built on migrated assets such as cbBTC sit behind whatever verification their issuer configured; the default is now one network.
- precedent Kelp and LayerZero's dispute over who approved a single-verifier setup shows how a configuration failure gets argued between client and vendor. CCIP 2.0 moves more of those choices to the client.
- contradiction Chainlink lists 18 launch partners, yet Fidelity and Further Asset Management speak of potential and intent, so the list does not yet show institutions paying for the second check.
The Risk Management Network was a separate set of nodes that double-checked the main committee's work, and its on-chain contract now stays only as an emergency backstop [5][7]. Decrypt's reading is that an institution adding nothing extra relies on one verification network where it used to have two [6]. Chainlink's position is that the same kind of independent check can come from the optional verifiers [8]. Both are accurate. The second check used to come by default, and now it comes only if the institution configures a verifier and pays for it, either in cloud capacity or in a contract with Infosys or Nethermind [2]. Decrypt's report does not say what either option costs.
Chainlink says CCIP secures more than $84 billion in cross-chain token value, a figure it reports itself [16]. The $15 billion it says arrived in the last four months [9] is roughly 18% of that [2]. It works out to about $3.75 billion a month [1]. According to Decrypt, those assets increasingly sit behind ETFs and bank products held by people who never touch a crypto wallet [10].
The April defections followed a configuration choice at a rival. Kelp DAO's LayerZero bridge ran with a single verifier when hackers linked to North Korea's Lazarus Group drained about $292 million from it [11]. Kelp said LayerZero's team approved the setup and never flagged it as risky; LayerZero said the configuration went against its own recommendations [13]. LayerZero later called the setup a mistake and stopped supporting it for new deployments [12]. CCIP 2.0 gives clients more of that kind of choice, above a floor of 16 separate companies that must all agree before a transfer clears [3].
Chainlink Labs Chief Business Officer Johann Eid pitched the launch against both alternatives. "Historically, legacy bridges have lost billions due to insecure infrastructure, while in-house builds are slow and expensive and institutions' proprietary networks can't earn the trust of their peers," he said in the launch announcement [15]. A verifier an institution runs for itself on a cloud starter kit is, in structure, a small proprietary network stacked on top of Chainlink's committee [2][3].
The outcomes split on what clients do. Should institutions switch on the custom verifiers CCIP 2.0 introduced [1], a typical transfer ends up with more independent checks than the old two-network default gave it. If most add nothing, the 16-operator committee is the only offchain check on the default path [6]. And if the Risk Management Network returns as the optional validation layer the documentation says is expected [4], Chainlink ends up offering as an extra the check it used to run by default.
I'd expect the second outcome for now. Of the 18 companies listed as launch partners, Fidelity says the upgrade "has the potential to support" broader distribution and Further Asset Management "intends to partner" [17]. The counter-case is that 16 companies which must all agree on a transaction are a different problem for an attacker than Kelp's one verifier [3][11], and a single Chainlink network may be enough for most issuers. The view fails if BitGo, Coinbase or other issuers behind the $15 billion name live verifiers of their own [9].
What to watch
- Whether Chainlink ships the Risk Management Network as the optional validation layer its documentation says is expected, and on what terms.
- Named, live verifier deployments from the 18 launch partners or from issuers such as BitGo and Coinbase.
- Any incident on CCIP where the 16-operator committee was the only offchain check on a transfer.