Polygon Fixes Security Flaws in Coordinated Hard Forks
Polygon has disclosed several security vulnerabilities affecting its proof-of-stake network that were fixed through two coordinated hard forks, Austin and Kyoto. The vulnerabilities, which included denial-of-service risks and validator resource exhaustion, affected Polygon's Bor and Heimdall clients.
The Austin hard fork addressed two denial-of-service paths in Bor, Polygon's execution client, while the Kyoto hard fork targeted a wider set of issues in Heimdall, including a vulnerability that could have forced validators to perform excessive processing work. Polygon added limits to reject transactions exceeding expected processing thresholds.
Polygon said none of the vulnerabilities were observed being exploited on mainnet and that the fixes were deployed proactively before their technical details were released publicly. The private rollout reduced the period during which attackers could have known about the weaknesses while large numbers of nodes remained exposed.