Polygon Fixes Security Flaws Through Hard Forks
Polygon has disclosed multiple security vulnerabilities on its proof-of-stake (PoS) network that were fixed through hard forks. The issues affected the Heimdall and Bor clients, including potential denial-of-service attacks, validator resource exhaustion, and errors in checkpoint and milestone processing.
The most severe vulnerability was found in the Heimdall client, where a specially crafted transaction could have imposed excessive computational load on validators and disrupted network operations. Polygon also identified two DoS vulnerabilities in the Bor client that could have slowed block processing or forced nodes to shut down.
Polygon resolved the issues through the Austin and Kyoto hard forks. It withheld the details until the fixes were completed, then disclosed them after deployment, testing, and mainnet activation were finished.