Polygon reveals PoS network flaws patched through recent hard forks

Polygon reveals PoS network flaws patched through recent hard forks

N
News Editor
2026-08-29 20:28:51
Polygon has disclosed a set of previously nonpublic security vulnerabilities affecting its proof-of-stake network after fixes were deployed through the Austin and Kyoto hard forks. According to a Thursday notice from Polygon Labs’ Validators Support Team, the issues involved the Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion, and flaws tied to checkpoint and milestone processing. The company said the updates were rolled out privately, tested, and only then activated on mainnet before the vulnerabilities were made public. Polygon added that it did not observe any of the flaws being exploited on mainnet. The most serious issue involved Heimdall, where a specially crafted transaction could have forced validators into excessive processing work. Austin also fixed two Bor denial-of-service bugs that could have slowed block handling or crashed nodes. Nodes still running old software past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network. Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes. CoinGecko data showed POL trading around $0.10 at the time of writing.

Polygon has disclosed several previously private security vulnerabilities that affected its proof-of-stake network after pushing fixes through two recent hard forks.

In a Thursday disclosure from Polygon Labs’ Validators Support Team, the company said the issues touched both the Bor and Heimdall clients. The list included denial-of-service risks, validator resource exhaustion, and flaws tied to checkpoint and milestone processing.

Austin and Kyoto carried the fixes

Polygon said the vulnerabilities were patched through the Austin and Kyoto hard forks. The changes were deployed privately and tested before they were activated on mainnet and then disclosed publicly.

The most serious issue involved Heimdall. According to Polygon, a specially crafted transaction could have forced validators to carry out excessive processing work, creating a risk of network disruption.

The Austin hard fork also fixed two denial-of-service risks in Bor. Those bugs could have slowed block processing or caused nodes to crash.

No exploit seen on mainnet

Polygon said none of the vulnerabilities were observed being exploited on mainnet. The company described the rollout as proactive, with fixes deployed before technical details were released.

The disclosure also said nodes running older versions of either client beyond the hard fork activation heights have already fallen out of consensus. Those nodes must upgrade to rejoin the canonical network.

Required versions are already live

All Polygon PoS nodes are required to run Bor v2.10.0, according to the disclosure. Heimdall v0.11.0 is required for validators and full nodes. Both upgrades are already active on mainnet.

POL price snapshot

CoinGecko data showed POL, Polygon’s native token formerly known as MATIC, trading around $0.10 at the time of writing. The token was down about 4% over the past week, up 44% over the past month, and up 2.3% year to date.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.