Polygon has disclosed several previously undisclosed security vulnerabilities that were recently fixed through two hard forks named Austin and Kyoto. The flaws could affect the company's proof-of-stake network. The vulnerabilities were found across the Bor and Heimdall clients, with issues ranging from denial-of-service risks to exhaustion of validator resources. There were also defects affecting checkpoint and milestone processing. Polygon said that all fixes were tested privately before they were deployed to mainnet and before the company went public with the details. The most severe problem concerned Heimdall. Specially crafted transactions could force validators to perform excessive processing work, which in turn could disrupt network operations. The Austin hard fork separately fixed two denial-of-service risks in the Bor client, both of which could slow down block processing or lead to node crashes. Polygon also stated that none of these flaws had been exploited on mainnet, and that the patches were completed proactively before any vulnerability details were publicly disclosed.
Polygon has disclosed that several security vulnerabilities not previously made public were patched in two recent hard forks, Austin and Kyoto. The flaws could have affected its proof-of-stake network, the company said. The issues were found across the Bor and Heimdall clients, covering denial-of-service risks, exhaustion of validator resources, and defects that could impair checkpoint and milestone processing.
According to Polygon, the fixes were tested privately before being deployed to mainnet and before any public disclosure. The most serious issue involved Heimdall, where specially crafted transactions could force validators to carry out excessive processing work and disrupt the network. In addition, the Austin hard fork fixed two denial-of-service risks in the Bor client that could slow block processing or cause node crashes. Polygon also said the vulnerabilities had not been exploited on mainnet, and that the remediation was completed proactively ahead of the public release of vulnerability details.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.