Polygon has activated two coordinated hardforks across its proof-of-stake clients to address denial-of-service, resource-exhaustion and consensus-hardening risks, disclosing the changes after private rollout and validation on Amoy. Austin, shipped as Bor v2.10.0, adds a hard per-block gas bound for state-sync events and removes Bor's unbounded TxDependency wire field. Kyoto, shipped as Heimdall v0.11.0, limits deeply nested google.protobuf.Any data and fee-coin declarations while adding signature, checkpoint, voting, continuity, downtime-handling and L1-event replay protections. Austin activated at block 44,120,000 on Amoy and 91,949,700 on mainnet; Kyoto activated at heights 42,252,000 and 51,533,000, respectively. Polygon says the Austin vulnerabilities caused no observed mainnet disruption and that both forks were active on Amoy and mainnet before the August 27 forum disclosure. The upgrades are mandatory, but current operators need no state migration or genesis change; nodes that missed activation must upgrade and roll back to resynchronize.