Polygon Fixes Critical Security Flaws Ahead of Mainnet Exploitation
Polygon Labs has quietly patched critical security flaws in its proof-of-stake network through two hard forks, Austin and Kyoto. The fixes were rolled out privately before being made public on August 27. According to Polygon, the sequence of events is standard practice for consensus-affecting fixes.
Austin shipped in version 2.10.0 of Bor, the network's execution client, which closed two denial-of-service paths in block processing. The flaws included a field called TxDependency, an unbounded parallel-execution hint, that could let a block producer crash peer nodes with an oversized entry.
Kyoto, delivered in version 0.11.0 of the Heimdall consensus client, bundled eight hardening fixes. Among them was a fix for a single crafted transaction that could force every validator into heavy decode work at once, which Polygon called 'a permissionless way to force costly, correlated work across the whole validator set.'