Coin Brief ENDE

Chainlink CCIP 2.0 lets institutions run their own cross-chain verifiers

Chainlink has released CCIP 2.0, a new version of its Cross-Chain Interoperability Protocol, which moves tokens and messages between blockchains. The company says the release is live and available to all institutions and digital asset issuers, and it positions the update around three barriers it says institutions face across chains: cost, control and security.

The central addition is what Chainlink calls user attestations. An institution can operate its own Cross-Chain Verifier, which independently verifies and cryptographically signs each transaction; CCIP will not execute the transfer on the destination chain until that step is complete. The verifiers can run on bare metal or in a cloud, with starter kits for Amazon Web Services and Google Cloud, and third parties can operate them for clients: Chainlink names Infosys as one provider already building them. The same mechanism lets issuers layer extra verification on top of Chainlink's own infrastructure.

CCIP 2.0 also adds built-in compliance controls, so issuers can attach governance policies, approval workflows, KYC and AML checks and transaction limits to every cross-chain transfer, and configurable finality, from near-instant transfers to waiting for full finality on the source chain.

Chainlink says CCIP secures more than $84 billion in cross-chain token value, and that more than $15 billion moved onto it in the past four months, including wrapped bitcoin products from BitGo and Coinbase. It lists AWS, ANZ Bank, Deutsche Börse's Crypto Finance, Fidelity International, Google Cloud and SBI Digital Markets among launch partners and supporters. These figures are the company's own.

Chainlink CCIP 2.0 lets institutions run their own cross-chain verifiers
Chainlink CCIP 2.0 lets institutions run their own cross-chain verifiers — Coin Brief

What it means

Bridges have been among the most costly failure points in crypto, and the design answer here is to let the asset issuer hold a veto: a transfer that its own verifier does not sign does not complete. That shifts part of the security question from trusting the bridge operator to trusting one's own infrastructure, which is closer to how regulated institutions already think about custody.