Who can reroute CCIP, and what do the v1.6/v2.0 verifiers, RMN curse, and timelocks actually control?
3 comments
permissionless execution doesn’t mean permissionless routing, the router still gates which offramps are trusted.
The routing gate point seems right, but I don’t get why a timelock matters much if the same operator set can still flip the router once the delay passes, so what actually stops a fast reroute during an incident?
During a rollout, our timelock failed and ops could still reroute everything.