(Advertisement)

top ad mobile advertisement
news3h ago

Polygon Patches Serious Network Security Flaws

Polygon has disclosed multiple security vulnerabilities in its proof-of-stake network's Bor and Heimdall clients, fixed quietly through the Austin and Kyoto hard forks before public disclosure. No mainnet exploitation was found.

Polygon Patches Serious Network Security Flaws

(Advertisement)

native ad1 mobile advertisement

Polygon Labs has disclosed a series of security vulnerabilities that, if exploited, could have seriously disrupted its proof-of-stake network. The flaws were quietly patched through two hard forks before any details were made public, a deliberate sequencing intended to prevent bad actors from acting on the information before fixes were in place.

What the Vulnerabilities Involved

The vulnerabilities affected Polygon's Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion, and flaws affecting checkpoint and milestone processing, according to a disclosure from Polygon Labs' Validators Support Team.

The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. On the Bor side, the problems were equally concerning. L1-to-L2 state-sync events were effectively un-metered, meaning they could consume block resources without the gas accounting that normally limits runaway computation. The Austin fork introduced per-block gas bounds to cap that exposure. A second issue involved unbounded TxDependency data, a structure Bor uses internally to track transaction ordering. Without limits on how large that structure could grow, a crafted input could stall block processing or crash connected peers entirely.

How Polygon Responded

Polygon Labs patched the vulnerabilities through two hard forks, Austin on its Bor client and Kyoto on Heimdall, rolled out privately and validated on testnet before mainnet activation. The fixes landed in the Austin and Kyoto upgrades, which activated on the Polygon proof-of-stake mainnet on August 29, with a community forum post describing the technical details following two days earlier.

None of the vulnerabilities were observed being exploited on mainnet, according to Polygon, which said the fixes were deployed proactively before details were made public. The approach reflects a recognised best practice in blockchain security: disclosing vulnerabilities only after patches are live reduces the window during which attackers could act on public information.

The hard forks carry an immediate practical requirement for node operators. Polygon PoS nodes must upgrade to Bor v2.10.0, while validators and full nodes must move to Heimdall v0.11.0. After the hard fork activation heights, nodes running older client versions will fall out of consensus and must upgrade to rejoin the canonical chain.

Sources:
Cointelegraph: Polygon Patches DoS Risks in Austin, Kyoto Hard Forks
Decrypt: Polygon Quietly Patched Security Flaws in Two Hard Forks Before Disclosing Them
Crypto Briefing: Polygon Discloses Security Flaws Fixed in Austin and Kyoto Hard Forks

Latest News

Read More...

Author

Soumen Datta profile photoSoumen Datta

Soumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.

Join our newsletter

Sign up for the very best tutorials and the latest Web3 news.

Subscribe Here!
BSCN

BSCN

BSCN RSS Feed

BSCN is your destination for all things crypto and blockchain. Discover the latest cryptocurrency news, market analysis, and research covering Bitcoin, Ethereum, altcoins, memecoins and everything in between.

Polygon Patches Serious Network Security Flaws | BSCN Breaking News