Chainlink
KLEAR3 ResearchPublished Updated
Chainlink, a network of independent node operators that reports information from outside a blockchain so a smart contract can act on it, has published code since November 2017. Its repository took 490 commits in the last 90 days, and its LINK token was minted once, at a fixed 1,000,000,000.
What does Chainlink actually do?
Chainlink is a network of independent computers that read information outside a blockchain (a price, a weather report, a sports score) and report it on-chain so a smart contract can act on it. Multiple operators answer the same request, and their answers get combined before anything is used.
A smart contract cannot fetch a web page on its own; everything it sees has to arrive inside a transaction, written by somebody. Chainlink is the layer that does the writing, run by operators who have no reason to trust one another and are paid to disagree honestly if the data disagrees.
The specific product depends on what is being asked for. A data feed reports a price on a schedule; Automation triggers a contract function when a condition is met; VRF supplies a random number a contract could not otherwise produce; CCIP carries a message or a token from one chain to another. All four share the same idea: something has to happen outside the chain before a contract can act, and one operator's word alone is not enough.
The organisation names a second identity on its own repository, node of the decentralized oracle network, bridging on and off-chain computation. We read that line at the source rather than paraphrase it, because it is the shortest accurate description on offer.
Source GitHub, read 2026-09-26
Is the code actually open?
The code is public, mostly under MIT, and 490 commits landed in the last 90 days. Two blocks of it, tied to cross-chain messaging, sit under a Business Source License that converts to MIT on a fixed date. GitHub cannot label that mix, so it reports no license at all.
The repository reports NOASSERTION as its licence, which reads like a red flag until the actual file is opened. It is not empty: most of the repository is under the plain MIT licence, and two named directories tied to cross-chain messaging carry a Business Source License 1.1 instead, each with a change date already fixed in the text (2027-05-23 and 2029-04-25) after which they convert to MIT on their own.
GitHub's detector expects one licence per repository. Faced with three coexisting inside one file, it gives up and prints NOASSERTION rather than guess, and most directories that scrape that field pass the guess along as a fact.
The paths named in that same licence file, for the Solidity contracts, no longer exist in this repository: we confirmed a 404 on both. The contracts moved to a companion repository, chainlink-evm, a detail the licence text has not caught up with.
Source GitHub, read 2026-09-26
No audit report sits in this repository, and neither does an audits folder: we asked for it and the API answered 404, the same answer it gave for the contracts directory the licence points to. That is not the same claim as "Chainlink was never audited", and this page does not make the larger one.
What does exist, run by the project itself rather than a third party's guess, is a bug bounty paying up to 3,000,000 dollars, live since 2021-05-11. A bounty rewards whoever finds a flaw first; it is a different kind of evidence from a dated report, and it does not replace one.
Is anyone still working on it?
Very much so. The repository took 490 commits from 68 distinct Git identities over the 90 days to 26 September 2026, and the last one landed the day before we read it. Ninety days is a window that slides: the same count taken next week will already differ.
Sixty eight is a floor on the number of people involved, not a headcount: one contributor can sign under two identities, and a company account can hide several people behind one. What the number does say plainly is that this is not a repository someone walked away from.
The repository itself was also pushed to on the day we read it, which is a separate signal from the commit count above: that date covers every branch, while the commit window above counts only the default one, develop. The two agreeing is not a coincidence worth reading into; it is simply what an actively maintained project looks like from two different angles.
Source GitHub, read 2026-09-26
What shows it is running
- The LINK token contract holds deployed bytecode — 0x5149…86CA, read with eth_getCode, at block 26059950
- The repository is still being worked on — 490 commits over the 90 days to 2026-09-26, 68 distinct Git identities, last on 2026-09-25
- The core repository goes public
- Start of the 90-day window we measured
- Most recent commit at the time of reading
- This page, checked and published
Where does it actually run?
On Ethereum, where we read the token contract ourselves, and on dozens more. Chainlink's own documentation lists the LINK token as deployed on eighty-six blockchain mainnets, from Arbitrum to Solana. Which network a given application actually uses decides who has to keep a node running for it to work.
Unlike Bitcoin, which lives on a single chain it defines, Chainlink is built to sit on top of whichever chain asks for it. We counted 86 mainnet listings on the project's own contract page, each with its own deployed LINK token, rather than take a directory's summary figure on trust.
We verified the Ethereum deployment ourselves, reading deployed bytecode at the address the documentation names, and read the same address confirmed in Chainlink's own documentation, not only in a third-party aggregator, which is the reverse of the gap we found on Pendle's token contract.
Beyond LINK, staking deposits tracked by DefiLlama sit at roughly 608 million dollars on Ethereum alone, a third-party figure we did not measure ourselves.
Source Ethereum · Chainlink Docs · DefiLlama, read 2026-09-26
Each network chip above matches a mainnet named in Chainlink's own contract documentation, checked on 2026-09-26; the Ethereum deployment carries the extra weight of bytecode we read ourselves.
What the token actually does
LINK pays for oracle services and secures the network through staking. Whoever calls a Chainlink service pays node operators in LINK; part of that revenue funds a strategic reserve. There is no vote attached to holding it: the documentation describes payment and staking, never governance.
The documentation gives LINK three jobs, and voting is not one. It pays for oracle services: a developer who wants a price feed, a random number or a cross-chain message pays in LINK, and node operators are compensated in it for delivering. Payment Abstraction lets a user pay in something else, converted to LINK behind the scenes, and part of what accumulates funds a strategic reserve the project describes as built from both on-chain and off-chain revenue.
Source Chainlink Docs, read 2026-09-26
The second job is security, and it is a deposit against bad behaviour, not a ballot. Node operators and other holders can lock LINK into staking, and the deposit can be cut if a node misses its performance requirements; in exchange, stakers earn rewards. Nowhere does the documentation describe a vote that changes a protocol parameter.
Supply is fixed rather than scheduled. Reading the contract ourselves returned 1,000,000,000 LINK, matching the maximum the project states, and 748,099,970.42 of that circulates according to CoinGecko. No new tokens are minted on a timer: the full amount was created once, and nothing we found describes a further release schedule.
Source Ethereum · CoinGecko, read 2026-09-26
- What the token is forDirectly verified
- How many existDirectly verified
- How new ones appearNot verified
- Who received themNot verified
- Who can change the rulesNot verified
- Which contract is the official oneDirectly verified
The KLEAR3 rating
3.7out of 5
Each axis gets 0 to 5 from the facts in the register, against thresholds written in advance. The overall score is their weighted average, and it only appears once at least 5 of the 6 axes rest on a measured fact.
- Audits ×1.3
- Open code ×1.2
- Business model ×1.1
- Token alignment ×1
- Governance ×1
- Maturity ×0.7
- Open code4
public repository · 155 published releases · 490 commits in 90 days
What holds it back licence unresolved: readable but not reusable
- Audits3
code reviewed in the open: 490 commits in 90 days, 8 years in production
What holds it back no report in our registry · no report opened: we do not know what they found
- Business model5
business model published by the protocol · paid by les développeurs et organisations qui utilisent les services Chainlink · collected by les opérateurs de nœuds qui exécutent ces services · une partie alimente la Chainlink Reserve, une réserve stratégique de LINK
- Governancenot measured
What holds it back decision mechanism not established
- Token alignment2
supply capped at 1 billion · 75% already in circulation
What holds it back emission schedule unknown
- Maturity5
8 years of public code · 1 network verified by us · 12 networks in total
We rate the protocol: how it is built, how much of it can be checked, how its token lines up. Never an investment. A high score is not advice to buy, and a low one is not advice to sell.
What we could not establish
Three things. We found no distribution breakdown for the billion tokens minted at launch, no audit report inside this specific repository, and no named leadership: only four GitHub accounts are public members of the organisation behind it. None of that means the absence is a red flag by itself.
Chainlink's documentation states what the token is for, not who first held it: we found no page breaking the initial billion LINK down by category (team, investors, ecosystem). That is a different gap from the one we found on XRP, whose issued and circulating figures simply diverge with no explanation offered: here nothing is offered at all, so we could not establish where the original allocation went.
The organisation lists four public members on GitHub, which is neither anonymous nor a named leadership team; most contributors keep their organisation membership private, which GitHub allows and which this figure cannot see through.
Source GitHub, read 2026-09-26
Frequently asked questions
Does Chainlink have its own blockchain?
No. Chainlink is a network of nodes that runs on top of other blockchains rather than one of its own. It reads and reports data on Ethereum, and on the dozens of other mainnets where its contracts are deployed, which is the opposite of most entries in this series.
The documentation names eighty-six blockchain mainnets that carry a LINK token contract, and Chainlink's oracle services run on most of them independently. A service reading a price feed on Base does not depend on Ethereum being available, which is the point of building this way.
We verified the token itself only on Ethereum, reading its bytecode and its total supply directly from a public node. The other eighty-five networks come from Chainlink's own page, not from a chain we queried ourselves, and this page says so rather than blurring the two.
Is LINK a governance token?
No. Chainlink's own documentation gives LINK exactly three jobs: paying for oracle services, backing a staking mechanism that can be slashed, and funding a strategic reserve. Nowhere does it describe a vote that changes how the protocol works, which is unusual for a token this size.
Node operators and other holders can lock LINK to help secure the network, and they earn rewards for it, but they cannot lose that stake for disagreeing with a decision, only for failing a performance requirement. That is a security deposit, not a ballot.
All one billion LINK were minted once, in 2017, and total supply read from the contract today matches that figure exactly. No new tokens appear on a schedule, and no team allocation is still vesting that we could find, which removes a common source of governance pressure entirely.
Has Chainlink been audited?
Not inside this repository, as far as we could find. There is no audits folder here, and the folder the licence file points to for the Solidity contracts has moved to a separate repository we did not have time to check. What does exist is a large, long-running bug bounty.
Chainlink runs its own program on Immunefi, live since May 2021, paying up to three million dollars for a critical smart contract bug. A bounty is not the same evidence as a dated report: it rewards whoever finds a flaw first, it does not say nobody has looked.
What we counted instead: 490 commits from 68 identities in the last ninety days, on a repository open since 2017. That is not a substitute for an audit report, and this page does not pretend it is one, but it is a different kind of evidence worth naming.
Where to read on, at the source — every address answered 200 on 2026-09-26.
Read next: our profile of Ethereum covers the chain where we verified LINK's own contract, and our Arweave profile shows the opposite design, a network built to live on its own chain rather than sit on top of others.
Ask an assistant to summarise it and check what it claims.