Polygon Reveals Security Flaws After Deploying Fixes Through Hard Forks
Polygon has revealed security flaws in its Proof-of-Stake network after deploying fixes through hard forks Austin and Kyoto. The vulnerabilities affected Bor and Heimdall, including denial-of-service paths in block processing.
Austin closed two resource-exhaustion paths, one involving the state-sync mechanism and another related to the TxDependency field. These issues could have degraded network availability if triggered.
The Kyoto hard fork addressed a broader set of problems affecting consensus processing, including a crafted-transaction attack that could force costly processing across Heimdall validators.
Polygon chose a patch-first approach, withholding technical details while patches were privately distributed and tested. The company reported no exploitation on mainnet before the fixes were deployed.