Polygon Fixes Security Issues via Recent Hard Forks
Polygon Labs recently disclosed security issues affecting its Proof-of-Stake (PoS) network after fixing them through two hard forks. The company identified vulnerabilities in both Bor and Heimdall clients that could have disrupted network operation by increasing the workload of validators and other components, potentially leading to slowdowns or instability.
The most severe issue was found in Heimdall, where a specially crafted transaction could compel validators to perform excessive processing work, creating a realistic possibility of network disruption. In addition, Polygon pointed out two separate denial-of-service risks addressed by the Austin hard fork for Bor, which could slow block processing or cause nodes to crash.
Polygon emphasized that none of the disclosed vulnerabilities had been observed being exploited on mainnet and that the fixes were deployed privately first with testing before activation on mainnet. The company also stated that nodes running older client versions will fall out of consensus after the hard fork activation heights and must upgrade to rejoin the canonical chain.
The upgrades are already live on mainnet, requiring Bor v2.10.0 for all Polygon PoS nodes and Heimdall v0.11.0 for validators and full nodes. This highlights the importance of keeping client software current in a validator-driven system, as operational stability depends on more than just validator correctness.