Polygon Fixes Proof-of-Stake Network Flaws with Two Hard Forks
Polygon's proof-of-stake network recently underwent two hard forks to address security issues. The updates affected Heimdall and Bor, requiring all node operators to update their software to remain in consensus.
The most critical flaw was found in Heimdall, the software that coordinates validators. This vulnerability allowed low-cost transactions with wrapping layers to be created, causing validators to expend computing power to decode them.
The Kyoto hard fork updated Heimdall to version 0.11.0 and began rejecting transactions when the nesting level exceeded a limit. This check occurred both upon entry into the mempool and on the consensus path.
The Austin hard fork focused on Bor, Polygon's execution client. The update fixed two denial-of-service paths: one related to state sync events with a block gas limit, and another linked to the TxDependency field, which was removed from the transmitted format.