Polygon Tackles Security Flaws with Stealthy Hard Forks
The Polygon network has quietly patched several serious security flaws before publicly disclosing them to the community. The team behind the network revealed that two hard forks, Austin and Kyoto, were deployed without prior communication to users, but they fixed critical issues that could have affected Bor and Heimdall users.
The vulnerabilities included validator resource exhaustion, milestone and checkpoint processing, and denial-of-service risks. The Austin hard fork targeted a couple of denial-of-service risks in Bor, which could cause a glitch in service speed. However, neither was a consensus-correction issue and did not disrupt the mainnet.
The Kyoto hard fork saw most changes introduced by the Polygon team. They removed the TxDependency wire field to ensure parallel execution doesn't rest on the producer's hint being accurate. Other changes included Fee-coin count cap, checkpoint signature recovery-byte normalization, milestone range voting bound to the signed parent hash, non-halting future-span creation, etc.
The team stated that all issues were resolved and validated before either hard fork activated. The fixes aimed to prevent possible exploitation and usage glitches as crypto network safety concerns linger.