Polygon Fixes Critical Security Flaws in Recent Hard Forks
Polygon Labs has disclosed several previously private security vulnerabilities in its proof-of-stake network that could have caused disruptions. The flaws, which affected Polygon's Bor and Heimdall clients, included denial-of-service risks, validator resource exhaustion, and issues affecting checkpoint and milestone processing.
The vulnerabilities were fixed through the Austin and Kyoto hard forks, deployed privately and tested before being activated on mainnet and publicly disclosed. The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work.
Polygon said none of the vulnerabilities were observed being exploited on mainnet, but nodes running older versions of either client past the hard fork activation heights have fallen out of consensus and must upgrade to rejoin the network. The required upgrades are Bor v2.10.0 for all Polygon PoS nodes and Heimdall v0.11.0 for validators and full nodes.