Polygon Fixes Security Flaws in Two Hard Forks
Polygon has taken proactive measures to address several previously undisclosed security vulnerabilities in its proof-of-stake network. The issues, affecting Polygon's Bor and Heimdall clients, included denial-of-service risks, validator resource exhaustion, and weaknesses involving checkpoint and milestone processing.
The vulnerabilities were fixed through the Austin and Kyoto hard forks, which were initially deployed privately to allow developers and validators to test the fixes before they were activated on the mainnet. The details of the vulnerabilities were released only after the corrective measures were in place.
The most serious vulnerability involved Heimdall, a component responsible for important functions within the Polygon PoS architecture. A specially crafted transaction could have forced validators to perform an unusually large amount of processing work, potentially disrupting network operations and exhausting validator resources.
Polygon's decision to disclose the issues after deploying and testing the fixes provides developers and node operators with information needed to understand why the upgrades were required. The network requires Bor v2.10.0 for all Polygon PoS nodes, while validators and full nodes must run Heimdall v0.11.0.