Polygon Secretly Fixes Critical Bugs in Execution and Consensus Clients
Polygon Labs quietly fixed two critical bugs in its infrastructure before publicly disclosing them. The first bug, found in Bor, Polygon's execution client, allowed a crafted transaction to cause validators to do more work than the sender paid for. This could have led to a denial-of-service attack and potentially frozen the entire chain.
The second bug was found in Heimdall, the consensus client that handles validator-side work and checkpointing. A sender could build a cheap transaction that forced validators to spend heavily on decoding, causing resource exhaustion.
Polygon fixed these bugs through two hard forks: Austin for Bor v2.10.0 and Kyoto for Heimdall v0.11.0. The fixes were shipped after a private rollout and Amoy testnet validation. The details of the fixes were published once the fleet was safe.
The disclosure was late by design, with Polygon choosing to patch first and explain afterward. This decision has sparked debate, with some arguing that open networks require transparency in security matters.