Polygon Unveils Vulnerabilities Fixed by Austin and Kyoto Hard Forks
Polygon has revealed the vulnerabilities fixed by its recent hard forks, Austin and Kyoto. The updates addressed several security issues that could have slowed down the network, crashed nodes, or forced validators to perform costly computational work.
Austin targeted Bor, the client responsible for producing Polygon PoS blocks, fixing two denial-of-service risks. One vulnerability came from state sync operations from Ethereum to Polygon, which could consume excessive gas and cause node crashes. The other weakness was due to an unbounded field called TxDependency, which was removed from the format transmitted between nodes.
Kyoto mainly protected Heimdall, the other major component of the Polygon PoS network. It fixed a vulnerability that allowed attackers to send specially crafted transactions, causing validators to perform excessive calculations. The update also enforced a maximum depth threshold for transaction structures and fixed issues related to checkpoints, milestones, and events from Ethereum.
Polygon deployed Austin and Kyoto quietly before publicly disclosing the details, with no exploitation observed on the mainnet. The fixes were preventive measures aimed at avoiding potential security breaches in the future.