Polygon Patches Critical Security Flaws in Austin and Kyoto Hard Forks
Polygon Labs has disclosed two security vulnerabilities that were patched in the Austin and Kyoto hard forks on its proof-of-stake mainnet. The fixes were quietly applied before any public announcement, with a community forum post detailing the technical details two days after the activation.
The first issue was with the Bor execution client, which had un-metered L1-to-L2 state-sync events that could consume block resources without gas accounting limits. This was fixed in the Austin hard fork, which upgraded the Bor client to v2.10.0 at mainnet block 91,949,700.
The second issue affected the Heimdall consensus client, which had byte-level nesting vulnerabilities in handling protobuf Any messages that could disrupt consensus messaging between validators. The Kyoto hard fork patched these checks at the byte level by upgrading the Heimdall client to v0.11.0 at block height 51,533,000.
Both upgrades were binary-only and did not require genesis file changes or state migration. Validators who have not updated their software are now operating outside canonical consensus and should upgrade immediately.