Polygon Quietly Fixes Security Flaws in Two Hard Forks Before Disclosure
Polygon Labs has quietly patched security flaws in its proof-of-stake network through two hard forks before disclosing them publicly. The team detailed the fixes bundled into the Austin and Kyoto hard forks, which were deployed following standard practice for consensus-affecting fixes.
The Austin fork closed two denial-of-service paths in block processing, including one where a malicious block producer could crash peer nodes by stuffing a block with an oversized data field. The Kyoto fork addressed a larger set of consensus-hardening issues, the most severe being a flaw that would have let an attacker force costly, coordinated work across the entire validator set using a single crafted transaction.
Polygon stressed that none of the flaws were observed being exploited on mainnet and that all were resolved proactively. Both upgrades are now mandatory for node operators and are already active, requiring no state migration or resync.