Skip to content
Crypto Almanac Daily
C
Bridges

CCIP

Best for independently tracked protocol

Value locked:$1,831m at this checkChains:21Audits recorded:0Audit report linked:Not foundRubric:v2.0 · verified 9 Aug 2026
Kayla PetersonKayla PetersonDeFi Research Analyst· Last verified August 9, 2026
Confidence ARubric v2.0Verified August 9, 2026
7.1
out of 10
Open account
Scorecard

How it rates

Counterparty & contract risk · 45%6.0
Cost transparency · 15%9.0
Market quality · 15%7.0
Transparency & track record · 15%8.0
Public documentation surface · 10%8.0
Pros
  • Accounting methodology published
  • $1,831m recorded independently
Cons
  • No audit report linked in the public dataset at this check
How this score was built

Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.

Counterparty & contract risk · 45% weight6/10 points · 6.0/10
Cost transparency · 15% weight9/10 points · 9.0/10
Market quality · 15% weight7/10 points · 7.0/10
Transparency & track record · 15% weight8/10 points · 8.0/10
Public documentation surface · 10% weight8/10 points · 8.0/10

A cross-chain interoperability protocol from the dominant oracle provider, securing $1.83bn across 21 chains with a risk management network.

Our assessment

CCIP secures $1.83bn across 21 chains, built by the provider whose price feeds most of DeFi depends on. Its distinguishing feature is an independent risk management network monitoring transfers alongside the main protocol.

A second network watching the first

CCIP runs a separate risk management layer that independently validates cross-chain messages and can halt transfers if it detects anomalies. Most bridges have one verification path; a bug in it is a total failure. Requiring two independent systems to agree, with one empowered to stop the other, is the most robust structure available for a bridge.

Oracle experience is directly relevant

The operator has spent years running infrastructure where being wrong causes immediate, large, cascading losses. That operational experience — node operator management, monitoring, incident response — transfers directly to cross-chain messaging, which fails in similar ways.

No audit report at this check

No audit report was retrievable at a public address. That is a notable gap for a protocol whose entire value proposition is security architecture, and one that would be straightforward to close given the scrutiny the operator's other products receive.

Who it suits

CCIP fits institutions and applications wanting cross-chain transfers with defence in depth. End users typically encounter it inside an application rather than choosing it directly.

Alternatives

How rivals compare

ServiceScoreBest for
Portal9.6audited protocol with published methodologyRead →
Reference

Frequently asked

Does this score mean CCIP is safe?

No. It measures what an outsider can verify: linked audits, published methodology and independently recorded data. Contract and custody risk are not tested by us.

Where do these figures come from?

A public analytics dataset queried at the verification date, plus the audit reports it links. Anyone can re-run the query.

Why do some protocols score zero on audits?

Because no audit report is linked in the public record. It records what a user can reach, not a claim that no audit exists.