Every major bridge exploit shares a shape: an invalid message was accepted as valid, and nothing stopped it. CCIP separates execution from oversight, running a second independent network — the Risk Management Network — whose only function is to monitor transfers and halt anything anomalous.
Why a veto layer is useful
The Wormhole exploit minted 120,000 unbacked wETH in a single transaction. A monitoring network with authority to freeze would have caught a mint of that size against no corresponding deposit. Defence in depth is standard practice in every other critical system and has been almost absent from bridge design; CCIP is the main exception.
The trust assumptions
Both the transfer network and the risk network are made up of node operators selected by Chainlink. That is a permissioned set chosen by one organisation, which is more accountable than an anonymous multisig and less trust-minimised than light-client verification. It is an honest middle position rather than a claim of trustlessness.
Cost and audience
Fees are higher and latency longer than consumer bridges, reflecting a design aimed at institutional and enterprise transfers where a few extra minutes and dollars are irrelevant against the value of not being exploited.
Who should use it
Institutions and protocols moving significant value who want an additional safety layer. Retail users making routine transfers will find Across or CCTP faster and cheaper.