Polygon has disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake network. The company revealed the issues after deploying fixes through the Austin and Kyoto hard forks.
The vulnerabilities affected Polygon’s Bor and Heimdall clients. They included denial-of-service risks, validator resource exhaustion, and weaknesses involving checkpoint and milestone processing. Polygon said it found no evidence that attackers exploited the flaws on mainnet.
Security fixes deployed before disclosure
Polygon patched the vulnerabilities before making their technical details public. The strategy allowed developers to test the fixes and activate them without giving potential attackers advance notice.
The most serious issue affected Heimdall, where a specially crafted transaction could force validators to perform excessive processing work. Such activity could have placed significant pressure on validators and potentially disrupted network operations.
The Austin hard fork addressed two separate denial-of-service risks in Bor. These flaws could have slowed block processing or caused affected nodes to crash.
Polygon said the upgrades were tested before activation on mainnet. The disclosure followed the successful deployment of the fixes, reducing the risk of public vulnerability details being used against unpatched nodes.
Node operators face upgrade requirement
The hard forks also created an immediate requirement for node operators. Nodes running older client versions after the relevant activation heights have fallen out of consensus and must upgrade to reconnect with the canonical Polygon network.
Polygon requires Bor v2.10.0 for Polygon PoS nodes. Validators and full nodes must also run Heimdall v0.11.0. Both versions are already active on mainnet.
The disclosure highlights the importance of coordinated security responses for blockchain networks. While Polygon avoided a confirmed mainnet exploit in this case, the affected vulnerabilities could have threatened network availability if attackers had discovered and exploited them first.
The Austin and Kyoto upgrades therefore served both as security patches and as critical maintenance steps for Polygon’s validator infrastructure.