Polygon Discloses Security Flaws Fixed in Austin and Kyoto Hard Forks

2 hour ago 2 sources neutral

Key takeaways:

  • Responsible disclosure after hard forks reduces selloff risk, but mandatory upgrades strain operators.
  • POL's muted price reaction suggests market treats patched vulnerabilities as non-event, favoring stability.
  • Monitor validator upgrade compliance and POL momentum; delayed node upgrades could create short-term friction.

Polygon has publicly disclosed a series of previously private security vulnerabilities affecting its proof-of-stake network after fixes were deployed through two coordinated hard forks, Austin and Kyoto. The fixes targeted the network’s Bor execution client and Heimdall validator coordination client, addressing denial-of-service risks, validator resource exhaustion, and weaknesses involving checkpoint and milestone processing.

According to Polygon, the patches were initially deployed privately and tested before being activated on mainnet. Technical details were released only after the network had been upgraded, reducing the window in which attackers could have exploited the vulnerabilities. The Austin hard fork targeted Bor and resolved two denial-of-service paths: one that could cause excessive computational demands during block processing, and another that could crash nodes under certain conditions.

The Kyoto hard fork addressed a wider set of issues in Heimdall. The most severe vulnerability involved specially crafted transactions that could force validators to perform excessive processing work. Because a malicious transaction could be relatively cheap to construct while imposing large computational costs on the validator set, Polygon added limits designed to reject transactions exceeding expected processing thresholds.

Polygon said none of the vulnerabilities were observed being exploited on mainnet, and no user assets were lost. The changes are already active on Polygon PoS mainnet. Node operators must upgrade to Bor v2.10.0 and Heimdall v0.11.0; nodes that remain on older client versions have fallen out of consensus and must upgrade before they can rejoin the canonical chain.

The disclosure highlights the operational burden for infrastructure providers, exchanges and staking operators running Polygon nodes, as the upgrades are mandatory rather than optional security patches. POL, Polygon’s native token formerly known as MATIC, was trading around $0.10 at the time of writing, down about 4% over the previous week but up roughly 44% over the past month and 2.3% year-to-date. The limited price reaction suggests traders did not treat the disclosure as evidence of an active compromise.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.