Aave Labs says it has chosen Chainlink’s Cross-Chain Interoperability Protocol, or CCIP, as the primary cross-chain infrastructure for its new mobile application and broader multichain ecosystem. The move follows an updated review by LlamaRisk that, according to Aave, identified CCIP as the most secure option among the cross-chain solutions assessed.

Security review drove the decision

Aave said the latest LlamaRisk assessment compared available cross-chain approaches and concluded that CCIP did not introduce additional trust assumptions beyond systems Aave already depends on. That point appears to have been central to the decision.

According to Aave, security was the main factor in selecting CCIP. The company also pointed to the structure of Chainlink’s network, saying each bridge lane is supported by at least 16 independent node operators distributed across different organizations and regions. Aave further cited built-in rate limits designed to activate during abnormal conditions, along with a single interface for handling messages and token transfers.

Expanding an existing Chainlink relationship

The adoption builds on a relationship that has already expanded over several years. Aave has used Chainlink oracles since 2020, and it has also used CCIP for GHO transfers and governance.

With the latest decision, Aave said its reliance on Chainlink now extends beyond data feeds to include cross-chain messaging, governance, GHO transfers, and app infrastructure. The company presented the change as a way to make multichain interactions more seamless while avoiding the need to assemble different bridge systems for different networks.

CCIP is Chainlink’s framework for transferring digital assets, messages, instructions, and smart contract data between blockchains. Rather than requiring separate integrations for each chain connection, the protocol is designed to offer a standardized communication layer that developers can integrate once and then use across multiple chains.

Broader risk management push

The announcement also fits into a wider tightening of Aave’s risk standards. The company said every dependency used by the protocol must satisfy criteria set out in the Aave Technical Asset Listing Framework as well as the updated Aave Risk Framework from LlamaRisk.

In June, LlamaRisk proposed a protocol-wide framework covering Aave’s V3, V4, and Horizon deployments. Under that approach, assets that fail to meet the updated requirements could be removed. The proposal was presented as part of a broader effort to apply stricter standards across the protocol’s ecosystem.

What it may mean for Aave’s expansion

By standardizing on CCIP, Aave said it expects to expand to additional chains without sacrificing security or user experience. The emphasis in the company’s announcement was not on adding a new standalone tool, but on consolidating cross-chain operations around infrastructure it already uses in several parts of the protocol.

The timing also comes as Aave has recently seen user activity improve. Earlier this month, the protocol recorded its largest single-day increase in new users in nearly five years, according to the source report.

The decision places Aave’s new mobile app within a broader operational strategy: fewer moving parts across chains, tighter dependency standards, and a stronger preference for infrastructure that has already been incorporated into key functions such as governance and GHO transfers.

Source: Coin Edition