Polygon Patches Multiple Security Vulnerabilities Through Hard Forks
Polygon Labs has revealed that it has patched multiple security vulnerabilities in its proof-of-stake network, Polygon. The patches were deployed privately before being publicly disclosed on a forum post released on Wednesday.
The team bundled the fixes into two hard forks: Austin, which is part of the Bor client, and Kyoto, which is part of the Heimdall client. Both hard forks followed the standard procedure for consensus-affecting fixes, with testing on Amoy, the testnet, before activation on mainnet.
Austin fixed two denial-of-service (DoS) paths in block processing, including a vulnerability that allowed malicious validators to crash nodes by filling large field data. Kyoto addressed a broader range of consensus hardening issues, including a critical flaw that enabled attackers to force the entire validator set to perform expensive and coordinated work with just one crafted transaction.
Polygon emphasized that none of these vulnerabilities were observed being exploited on mainnet, but were actively resolved before their public disclosure. The upgrades are now mandatory for node operators and have taken effect without requiring state migration or re-syncing.