defirisk.co
rubric v1.7.0

Prior exploit count

Chainlink CCIP's assessment for RD-F-077 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Zero confirmed CCIP-specific protocol exploits across all searched sources. Hacksdatabase grep returned 23 matching files; all reference Chainlink as an oracle provider used by other protocols (Bonq, Deus DAO, Inverse Finance, Lodestar, Venus/Blizz, WooFi, Rho, Moonwell) - none involve CCIP cross-chain infrastructure. REKT data-cache: sources.rekt.incidents = []. Web OSINT: no exploit, post-mortem, or CVE for CCIP lanes. The April 2026 KelpDAO $292M exploit was a LayerZero 1-of-1 DVN failure; CCIP was the migration destination, not the exploited system.

Sources #

  • URL
    KelpDAO blames LayerZero infrastructure for $292M rsETH hack, shifts to Chainlink CCIPKelpDAO exploit attributed to LayerZero 1-of-1 DVN failure, not CCIP; CCIP was migration destinationretrieved 2026-05-16
  • Internal
    Chainlink CCIP Data Cache - REKT incidents field00-data-cache.json sources.rekt.incidents = [] confirming zero REKT-indexed incidents for chainlink-ccip slugretrieved 2026-05-16
  • Internal
    Proprietary Hacks Database - CCIP/Chainlink grep resultshacksdatabase/ grep case-insensitive for chainlink/ccip: 23 files matched, all oracle-provider contamination not CCIP infrastructure exploitsretrieved 2026-05-16

Methodology #

Count the number of distinct incidents in the hack database affecting this protocol.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol chainlink-ccip factor RD-F-077 score green collected_at 2026-05-16 01:55:09