Polygon Patched Security Flaws in Latest Hard Forks, Maintaining Network Integrity
Polygon has disclosed multiple security vulnerabilities in its proof-of-stake (PoS) infrastructure, including issues that could have allowed for node-to-node denial-of-service and validator processing bottlenecks.
The problems were addressed ahead of public disclosure through two recent hard forks, Austin and Kyoto, and corresponding client upgrades. The Bor client was affected by two denial-of-service related risks tied to block handling, while a specially crafted transaction could have forced validators to perform excessive processing work with the Heimdall client.
Polygon stated that none of the vulnerabilities were observed being exploited on mainnet, and the fixes were deployed proactively before detailed vulnerability information was released. The company requires Bor v2.10.0 for PoS nodes and Heimdall v0.11.0 for validators and full nodes to maintain connectivity and consensus participation.
The disclosure is explicit about the operational consequences for participants who do not update, with nodes running older versions of either Bor or Heimdall falling out of consensus and needing to upgrade to return to the canonical network.