Polygon PoS Fixes Security Issues Through Hard Forks
Polygon PoS has addressed multiple security issues through two hard forks, Austin and Kyoto. The updates were deployed first on a testnet, then on the mainnet after thorough testing.
The first fork, Austin, targeted vulnerabilities in the Bor software, which handles user transactions and block generation. Two issues were fixed: a problem with state-sync events that could have led to network downtime due to excessive processing, and an issue with TxDependency data, which could have caused nodes to crash if it exceeded a certain size.
The second fork, Kyoto, focused on the Heimdall software, responsible for validation and interactions with Ethereum. A critical vulnerability was fixed: an attacker could have created a deeply nested transaction structure that would force all validators to process a massive amount of data, leading to high processing loads.
Both forks also included other security enhancements, such as limiting the depth of transactions and the number of coin types that can be used for transaction fees. These updates are now live on Polygon's mainnet and testnet.