Polygon Labs discloses security vulnerabilities quietly patched in Austin and Kyoto hard forks

  • Polygon Labs disclosed PoS vulnerabilities fixed via Austin and Kyoto hard forks.
  • Bor v2.10.0 and Heimdall v0.11.0 address DoS, resource exhaustion, and processing errors.
  • Polygon reported no confirmed mainnet exploitation and required immediate node upgrades.

Polygon Labs has disclosed multiple security vulnerabilities on its proof-of-stake network that were resolved through the Austin and Kyoto hard forks before technical details were shared publicly. The Polygon Validators Support Team published the disclosure in an Aug. 27 forum post after consensus-affecting fixes were deployed privately, validated on the Amoy testnet, and activated on mainnet. The flaws affected the Bor execution client and the Heimdall consensus client and spanned denial-of-service paths, validator resource exhaustion from deeply nested protobuf messages, and checkpoint and milestone processing errors. Austin upgraded Bor to v2.10.0, introducing a per-block gas limit on L1-to-L2 state-sync events and closing an oversized TxDependency path that could let a malicious block producer crash peers. Kyoto moved Heimdall to v0.11.0 with a byte-level nesting check on google.protobuf.Any fields plus milestone, checkpoint, and L1 event replay hardening. Polygon reported no evidence of mainnet exploitation or disruption, said both upgrades are mandatory binary client updates requiring no state migration, and warned that operators on pre-activation software have already left canonical consensus. The fixes sit alongside prior PoS infrastructure work, including a September 2025 finality hard fork, the Rio upgrade, a May 2026 block-time cut to 1.75 seconds, and the completed MATIC-to-POL migration. Market reaction was muted: POL traded near $0.09983 on Aug. 30, down about 2.3% over 24 hours and 6.8% over seven days, roughly 60.8% lower year over year, with a market capitalization near $1.07 billion per CoinGecko data. Ordinary users need no wallet action once validators run the patched clients.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.