Polygon Quietly Fixes Security Flaws Before Public Disclosure
Polygon Labs quietly patched security vulnerabilities through two hard forks before disclosing them publicly. The Austin and Kyoto hard forks rolled out privately and validated on testnet before mainnet activation, according to a forum post by Polygon.
The fixes addressed denial-of-service paths in block processing and a more severe flaw that could have forced costly, coordinated work across the entire validator set via a single crafted transaction.
None of the flaws were observed being exploited on mainnet, and all were resolved proactively. Both upgrades are now mandatory for node operators and are already active, requiring no state migration or resync.