Chainlink launches CCIP 2.0 with customizable verification and compliance tools
Chainlink announced the launch of CCIP 2.0, introducing user-operated Cross-Chain Verifiers, integrated compliance features, and adjustable transaction settlement times to its cross-chain protocol.

Chainlink introduced CCIP 2.0 at the Sibos 2026 conference on September 28, rolling out an upgrade to its Cross-Chain Interoperability Protocol aimed at institutional financial infrastructure. The new framework allows token issuers and institutions to set custom delivery requirements, configure settlement speeds, and manage regulatory screening for moving digital assets across blockchains.[3][6][12]
A central addition to the protocol is the Cross-Chain Verifier (CCV), which enables institutions to make their own attestation mandatory before transfers are minted or released on the destination chain. These CCVs can be hosted on cloud providers such as AWS and Google Cloud or managed by infrastructure firms such as Infosys and Nethermind. Any required CCV must sign off alongside Chainlink's baseline Committee Verifier of 16 independent node operators, while the protocol's standalone Risk Management Network has been retired. Reporting from CoinDesk and Decrypt linked the multi-verifier approach to earlier security failures in the ecosystem, notably the April single-verifier bridge exploit that cost Kelp DAO $292 million.[1][6][7][9][10][11]
The release also integrates the Chainlink Automated Compliance Engine (ACE) to enforce rules such as KYC, AML, and sanctions checks before or after token transfers begin. Additionally, Chainlink and ethlabs_org introduced an optional fast confirmation rule for Ethereum that reduces confirmation times to between 12 and 24 seconds, compared to the standard 13-minute default finality wait. Chainlink stated that CCIP secures over $84 billion in cross-chain token value, with institutional support from firms such as ANZ, Fidelity International, Deutsche Börse's Crypto Finance, and SBI Digital Markets. However, CryptoSlate reported that an unresponsive required verifier can stall destination execution, noting that launch materials did not identify a production asset currently using an issuer-run required CCV.[2][5][6][8][11][12]
Key facts
- Chainlink launched CCIP 2.0 at the Sibos 2026 conference on September 28, 2026.
- CCIP 2.0 introduces Cross-Chain Verifiers, allowing issuers and institutions to require their own sign-off alongside Chainlink's default 16-operator Committee Verifier before destination release.
- The upgrade retires Chainlink's Risk Management Network as a standalone safeguard.
- The protocol adds the Automated Compliance Engine to handle KYC, AML, sanctions screening, and exposure limits.
- Chainlink and ethlabs_org added an optional Ethereum Fast Confirmation Rule that reduces confirmation waits from 13 minutes to 12 to 24 seconds.
- The launch directly addresses single-verifier vulnerabilities linked to the $292 million April hack of Kelp DAO's bridge.
- Chainlink reported that CCIP secures more than $84 billion in cross-chain token value, with over $15 billion moved onto the protocol in the preceding four months.
- An unresponsive required verifier can stall destination token execution, and Chainlink launch materials did not identify any production asset using an issuer-run required CCV.
Sources · 11 sources
- CO
CoindeskArticle ·
Chainlink launches new version of its crypto bridge tech 'CCIP' to give apps more control over their security The new software lets companies add custom security checks so they do not fall victim to the same type of vulnerabilities that plagued rival bridges.
Open source - SI
Solid Intel 📡@solidintel_xPost on X ·
INTEL: ethereum:0x514910771af9ca656af840dff83e8264ecf986ca launches CCIP 2.0 for institutions, adding faster transfers and built-in compliance for moving tokenized assets across blockchains CCIP now secures over $84B in cross-chain token value, with $15B+ moving to it in the past four months
Open source - CB
Crypto BriefingArticle ·
Chainlink launches CCIP 2.0 at Sibos 2026, targeting institutional cross-chain infrastructure CCIP 2.0's launch signifies a pivotal shift towards seamless blockchain integration in finance, enhancing efficiency and compliance for institutions. The post Chainlink launches CCIP 2.0 at Sibos 2026, targeting institutional cross-chain infrastructure appeared first on Crypto Briefing .
Open source - LS
Laura Shin@laurashinPost on X ·
Chainlink's CCIP 2.0 is live. Institutions and token issuers can now run or hire their own verifiers, and a transfer won't execute until both that verifier and Chainlink's 16-operator committee sign off. https://t.co/R375nL6oNB
Open source - BS
BSCN@BSCNewsPost on X ·
Ethereum transfers in seconds, not 13 minutes @ethlabs_org worked with @chainlink to build Ethereum's Fast Confirmation Rule into CCIP 2.0, which launched today. Confirmations that took about 13 minutes can now land in 12 to 24 seconds. Unlike @ethereum's full 13-minute finality, the fast rule has no staked $ETH at risk if it fails. It relies on the network running normally, and in rare cases a fast-confirmed block can still be reversed. That's why CCIP still waits the full 13 minutes by default. Token issuers can decide how much value to put on the fast path and charge extra fees for that risk.
Open source - UN
UnchainedArticle ·
Chainlink Upgrade Gives Institutions Their Own Sign-Off on Cross-Chain Token Transfers Chainlink launched CCIP 2.0 on Monday, a new version of its Cross-Chain Interoperability Protocol in which institutions and token issuers can make their own approval a required step before tokens or messages move from one blockchain to another. The main addition is the Cross-Chain Verifier , or CCV. An issuer can operate one itself or pay an outside provider to run it, and it must sign off on a transaction before CCIP executes it on the receiving chain. Chainlink’s default Committee Verifier , a group of 16 independent node operators who have to agree on every transfer, still signs too. Chainlink named Infosys and Nethermind among the firms building CCVs for clients. The upgrade also retires Chainlink’s Risk Management Network , an independent group of nodes that reviewed each transaction a second time, as a standalone safeguard, CoinDesk reported . Chainlink said the new optional verifiers can now supply that kind of check, according to the report. Issuers can also apply KYC, anti-money laundering and sanctions screening to each transfer, and choose how long a transfer waits for finality. Chainlink said Aave , Maple and reinsurance platform Re have adopted the faster option for their tokens. “Institutions need a neutral standard for moving digital assets across chains,” Johann Eid, chief business officer at Chainlink Labs, said in the announcement . Get Unchained’s crypto news in your inbox with the free Unchained Daily newsletter . What a Verifier Does Verifiers confirm that tokens were locked or burned on the source chain before matching tokens are issued on the other side. Kelp DAO’s rsETH bridge, built on Chainlink competitor LayerZero, depended on a single verifier when an attacker pushed a forged message through it on April 18, releasing 116,500 rsETH worth about $292 million with no deposits behind them. LayerZero later tied the attack to North Korea’s Lazarus Group. Under CCIP 2.0, an added verifier can’t clear a transfer on its own, since Chainlink’s committee must also sign. Kelp said in May it was moving rsETH to CCIP, and last week it sued LayerZero, alleging the company had approved that single-verifier configuration. Adoption Chainlink said CCIP carries more than $84 billion in cross-chain token value, and that over $15 billion moved onto it in the last four months, including BitGo’s WBTC and Coinbase’s cbBTC. It said Bitcoin yield platform Lombard is building custom verification into its tokens with the new CCVs. Related Listen: Why Robinhood Chain Saw Memecoins Take Off Before Real World Assets The post Chainlink Upgrade Gives Institutions Their Own Sign-Off on Cross-Chain Token Transfers appeared first on Unchained .
Open source - BS
BSCN@BSCNewsPost on X ·
What will Chainlink CCIP 2.0 bring for Institutions? @Chainlink CCIP 2.0 is now live. This protocol is positioning itself as the infrastructure layer for the next wave of on-chain finance, with Chainlink calling it "the rails" for hundreds of trillions of dollars of assets moving on-chain. Before, interoperability came at the cost of a bad compromise. Either organizations had to rely on insecure legacy bridges that have already been hacked for over $3.3 billion, or spend six months or more building customized connections for every new chain. Neither option is feasible when banks, asset managers, and regulated issuers want to distribute tokenized assets across both public and private networks without reconstituting their entire technology stack for each one. CCIP 2.0 was constructed as a universal standard that satisfies institutional criteria for security, compliance, and controlled settlement speed. What CCIP 2.0 brings: (1.) Institutions can add Cross-Chain Verifiers on AWS, Google Cloud, or via operators like Infosys and Nethermind, adding layers of verification beyond the 16 nodes CCIP provides by default. (2.) Issuers could control settlement speed via fast tracks for high-frequency settlements, with full finality and delayed settlements for high-value transactions. (3.) Integrated native ACE in CCIP could provide KYC, AML, sanctions checks, allow-listing, and exposure limits within cross-chain settlements. (4.) CCIP already protects $84B+ in cross-chain token value and $15B+ in cross-chain migrations (WBTC, cbBTC, kBTC). (5.) CCIP launch partners include ANZ, Fidelity, SWIFT-enabled institutions, AWS, Google Cloud, Infosys, Aave, and over 80 connected chains. (6.) The aim would be to have one universal standard instead of thousands of private chains for institutions. This effort aims to allow regulated capital to move through the onchain economy without sacrificing the regulation large financial firms need. Hundreds of trillions of assets are set to join the onchain economy, and CCIP 2.0 is Chainlink’s answer to how that will happen.
Open source - CR
CryptoSlate@CryptoSlatePost on X ·
Chainlink’s CCIP 2.0 lets issuers require an extra verifier after a cross-chain transfer starts. Without its attestation, destination delivery can stall. Chainlink has not identified a production asset using an issuer-run required verifier. https://t.co/HCN9sP16Vm
Open source - CO
CoinDesk@CoinDeskPost on X ·
NEW: @Chainlink launches CCIP 2.0 allowing companies to layer their own security verifiers on top of cross-chain transfers, directly addressing the single-verifier vulnerability blamed for April's $292M Kelp DAO bridge hack. https://t.co/XhC7HHGelV
Open source - DE
DecryptArticle ·
Months After the $292M Kelp Hack, Chainlink Lets Institutions Add Their Own Bridge Checks Chainlink's CCIP 2.0 lets banks run their own security checks on cross-chain transfers, five months after a rival's setup lost $292 million to hackers.
Open source - CR
CryptoSlateArticle ·
Chainlink CCIP 2.0 exposes bridge risk, and issuer gates trigger stalls Chainlink's CCIP 2.0 lets a token issuer require an additional verifier before tokens finish moving from one blockchain to another. A sending pool may already have locked or burned the tokens when that check becomes decisive: without the verifier's attestation, the receiving chain cannot release or mint them. Announced on Sept. 28 , the feature adds optional Cross-Chain Verifiers (CCVs) alongside CCIP's default Committee Verifier. An issuer or third party can operate one and make its approval a condition of delivery. That gives the operator's rules and uptime a direct role in a holder's exit path. Chainlink's launch material does not identify a named production asset and lane using an issuer-run required CCV, so the mechanism is not evidence of a holder's transfer being blocked. The point where a transfer can wait CCIP's OnRamp assembles the applicable verifier requirements of a token transfer, and the token pool locks or burns the tokens. The OnRamp then records the message for offchain verifier services. Those services watch the source event, apply their finality and verification rules, and publish attestations tied to the message ID. On the destination chain, CCIP's OffRamp checks the required attestations before the pool releases or mints tokens. Its checks draw on the lane and token-pool settings and, when a receiver contract is involved, that receiver's requirements. Sender preferences can add to the source-side verifier set. A token-only transfer has no receiver callback whose verifier preferences must be checked. This sequence places the lock or burn before verification and the destination release after it. Chainlink's CCIP 2.0 lets issuers reject transfers before lock or release, while required attestations can delay delivery. A source transaction may have succeeded while destination delivery remains pending, so Chainlink says all required CCVs must return valid results before execution proceeds. Its trust model warns that an unresponsive verifier can stall every message requiring its attestation. If an issuer runs such a verifier and makes it required for its token pool, the issuer's service becomes one of the parties able to delay completion. A third-party operator would create a similar dependency under that operator's control. That is a control the design permits, not evidence that an issuer has deliberately blocked a holder's transfer. Chainlink says the default Committee Verifier comprises 16 independent node operators, with additional CCVs sitting alongside that baseline. An issuer or application choosing one gains another check but must also assess who operates its contracts and offchain service, what rules that service applies, and whether it stays available. Chainlink assigns external CCV operators responsibility for implementation, maintenance, and uptime. The key question for a holder is which attestations are mandatory for this token on this route, and who can produce each one. Related Reading Nearly $15B is moving off LayerZero, now a $292M lawsuit puts its security model on trial What a holder can do when delivery stops Execution on the destination chain is permissionless once every required proof exists and any optional verifier quorum has been met. Chainlink's default executor normally submits the transaction, but anyone can submit it, including through the manual execution path . Changing the executor or paying destination-chain gas does not waive a missing required CCV attestation. The OffRamp still checks the proofs before releasing or minting tokens. The recovery path depends on where a message stopped. If the required attestation has not been assembled, the destination message can remain UNTOUCHED, meaning no execution has been recorded. If a submitted destination attempt fails inside the OffRamp's protected path, it can be marked FAILURE. Chainlink says a failed attempt can be retried after the underlying problem is fixed. Its default executor retries failures within a configured window currently set at eight hours, and that limit describes the automated service. A holder has a usable manual route only after the necessary proofs are available and any destination-side failure is fixed. The manual execution guide describes how to inspect verifier status and execution state, including cases where the indexer has not collected an external verifier's result. Chainlink's published manual execution route does not specify a general automatic cancellation, refund, or return of source-chain tokens when a required verifier never attests. Any issuer-specific remedy would depend on that asset's arrangements. On EVM chains, a configured Chainlink Automated Compliance Engine hook can reject an outbound transfer before the source pool locks or burns anything. That preflight failure reverts the source transaction. A separately configured destination postflight hook can reject release or mint after the source-side transfer has started, leaving the tokens undelivered until the policy condition is resolved and execution is retried. The ACE integration guide describes these as distinct, optional configurations. A live release, with deployment questions Chainlink's mainnet directory lists supported networks and tokens, but a listing does not show whether a given production lane requires an issuer-operated verifier or has enabled a destination ACE gate. Nor does a partner announcement or an earlier asset migration establish those settings. Without the token pool, route, and verifier configuration, this new power cannot be attributed to the issuer of a named asset. The release separately offers faster-than-finality transfers. Full source-chain finality remains the default, while the faster option can expose a transfer to duplicate destination execution after a deep enough reorganization, according to Chainlink's FTF guide . Other required CCVs may apply their own reorganization rules, but that speed choice does not change the need for required attestations. CCIP 2.0 gives issuers a stronger way to set cross-chain delivery conditions. For holders, the essential questions are which checks apply to their asset, who controls them, and what remedy exists if one cannot be completed after the transfer starts. The post Chainlink CCIP 2.0 exposes bridge risk, and issuer gates trigger stalls appeared first on CryptoSlate .
Open source - TB
The Block@TheBlockCoPost on X ·
THE BLOCK: Chainlink has launched CCIP 2.0, an upgraded version of its cross-chain infrastructure designed to help institutions move tokenized assets across public and private blockchains. The update adds features including configurable transaction finality, compliance controls, and a Cross-Chain Verifier that allows institutions and third parties to add additional verification layers to transactions. Chainlink said CCIP 2.0 is being supported by financial and infrastructure firms including ANZ, Fidelity International, Deutsche Börse's Crypto Finance, SBI Digital Markets, Sygnum, Taurus, AWS and Google Cloud.
Open source

