Polygon Pushes Two Hard Forks to Patch PoS Flaws; POL Drops 6.8% Week

Polygon Pushes Two Hard Forks to Patch PoS Flaws; POL Drops 6.8% Week

N
News Editor
2026-08-30 22:36:14
Polygon Labs has disclosed that it fixed a set of vulnerabilities on its proof-of-stake network through two hard forks, with the fixes privately deployed before public disclosure. In a Wednesday forum post, the team explained the patches were delivered via the Austin hard fork on the Bor client and the Kyoto hard fork on the Heimdall client, following the standard process for consensus-affecting upgrades: testing on Amoy testnet, then disclosure after mainnet activation and safety checks. Austin addressed two denial-of-service paths in block processing, including a bug allowing a malicious block producer to crash peers with oversized field data. Kyoto handled broader consensus hardening; the most serious flaw let an attacker force the entire validator set into expensive coordinated work with one cheap transaction. Polygon said no vulnerability had been observed exploited on mainnet and all issues were proactively addressed. Both upgrades are mandatory and live, with no state migration or resync needed. The disclosure comes as Polygon completes its MATIC-to-POL migration as part of a broader architecture overhaul. POL traded around $0.09983 on Sunday, down 2.3% in 24 hours, about 6.8% over the week and 60.8% over the past year, with a market cap near $1.07 billion, according to CoinGecko.

Polygon Labs said it patched a batch of security vulnerabilities across its proof-of-stake network through two hard forks, with the fixes quietly deployed before the public got the details.

In a Wednesday forum post, the team said the patches were packed into the Austin hard fork on the Bor client and the Kyoto hard fork on the Heimdall client. Both followed the standard flow for consensus-affecting fixes: validation on the Amoy testnet first, then disclosure only after mainnet activation and network safety checks.

Austin and Kyoto: what each fork addressed

The Austin fork targeted two denial-of-service paths in block processing. That includes a bug where a malicious block producer could crash peers by filling in oversized field data.

Kyoto handled a broader set of consensus-hardening issues. The most severe one allowed an attacker to force the full validator set to carry out expensive, coordinated work with a single crafted transaction. Building the transaction was cheap; processing it was not.

No exploits observed, but operators must upgrade

Polygon emphasized that none of the vulnerabilities were observed being exploited on mainnet and that they were addressed proactively. Both upgrades are now mandatory for node operators and already live, with no state migration or resync required.

Timing and market reaction

The disclosure lands during a transition period for Polygon. The network has finished migrating legacy MATIC tokens to POL as part of a broader architecture overhaul.

The news did not lift POL. According to CoinGecko, POL traded at about $0.09983 on Sunday, down 2.3% in 24 hours, down about 6.8% over the past week and roughly 60.8% over the past year. Its market cap stood at about $1.07 billion.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.