Crypto
Home›Crypto›Market Structure›Polygon discloses security flaws patched in recent har…
Polygon discloses security flaws patched in recent hard forks
Polygon said the issues were fixed via its Austin and Kyoto hard forks before public disclosure, and older client versions have fallen out of consensus and must upgrade to rejoin the network.
Polygon has disclosed multiple previously private security vulnerabilities that affected its proof-of-stake network, saying it addressed the problems through fixes deployed in two recent hard forks before the details were published. The vulnerabilities involved its Bor and Heimdall clients and included denial-of-service and validator resource risk, as well as flaws tied to checkpoint and milestone processing, according to a disclosure from Polygon Labs’ Validators Support Team.
Polygon said the most severe issue related to Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting network operations. The Austin hard fork, deployed separately, addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash.
Polygon stated that none of the vulnerabilities were observed being exploited on mainnet and that the fixes were deployed proactively before details were made public. It also said nodes running older versions past the hard fork activation heights have fallen out of consensus and must upgrade, with Bor v2.10.0 required for all Polygon PoS nodes and Heimdall v0.11.0 required for validators and full nodes, both already active on mainnet.