Polygon Fixes Critical Security Flaws in Recent Hard Forks
Polygon has disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake network. The flaws were fixed through two recent hard forks, Austin and Kyoto, which were deployed privately and tested before being activated on mainnet.
The vulnerabilities affected Polygon's Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion, and flaws affecting checkpoint and milestone processing. The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network.
Polygon said none of the vulnerabilities were observed being exploited on mainnet. However, nodes running older versions of either client past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network.