Polygon has disclosed several previously private security vulnerabilities that affected its proof-of-stake network after pushing fixes through two recent hard forks.
In a Thursday disclosure from Polygon Labs’ Validators Support Team, the company said the issues touched both the Bor and Heimdall clients. The list included denial-of-service risks, validator resource exhaustion, and flaws tied to checkpoint and milestone processing.
Austin and Kyoto carried the fixes
Polygon said the vulnerabilities were patched through the Austin and Kyoto hard forks. The changes were deployed privately and tested before they were activated on mainnet and then disclosed publicly.
The most serious issue involved Heimdall. According to Polygon, a specially crafted transaction could have forced validators to carry out excessive processing work, creating a risk of network disruption.
The Austin hard fork also fixed two denial-of-service risks in Bor. Those bugs could have slowed block processing or caused nodes to crash.
No exploit seen on mainnet
Polygon said none of the vulnerabilities were observed being exploited on mainnet. The company described the rollout as proactive, with fixes deployed before technical details were released.
The disclosure also said nodes running older versions of either client beyond the hard fork activation heights have already fallen out of consensus. Those nodes must upgrade to rejoin the canonical network.
Required versions are already live
All Polygon PoS nodes are required to run Bor v2.10.0, according to the disclosure. Heimdall v0.11.0 is required for validators and full nodes. Both upgrades are already active on mainnet.
POL price snapshot
CoinGecko data showed POL, Polygon’s native token formerly known as MATIC, trading around $0.10 at the time of writing. The token was down about 4% over the past week, up 44% over the past month, and up 2.3% year to date.

