Polygon disclosed PoS security fixes after privately deploying two hard forks

Polygon disclosed PoS security fixes after privately deploying two hard forks

N
News Editor
2026-08-30 22:33:01
Polygon Labs said it repaired a batch of security flaws in its proof-of-stake network through two hard forks that were deployed before any public disclosure. In a forum post published Wednesday, the company said the fixes were included in the Austin hard fork for the Bor client and the Kyoto hard fork for the Heimdall client. Polygon said it followed its standard process for consensus-related fixes by rolling them out quietly, validating them on the Amoy testnet, activating them on mainnet, and only then disclosing the details publicly once the network was safe. According to Polygon, the Austin fork closed two denial-of-service paths tied to block processing, including one in which a malicious block producer could crash peer nodes by packing a block with an oversized data field. The Kyoto fork addressed a broader set of consensus-hardening issues, including a more serious flaw that could have allowed an attacker to trigger expensive coordinated work across the full validator set with a single crafted transaction. Polygon said none of the flaws were seen exploited on mainnet, and both upgrades are now mandatory, already active, and require no state migration or resync. The disclosure comes after Polygon completed its legacy MATIC-to-POL migration. CoinGecko data cited in the report showed POL trading near $0.09983 on Sunday, down 2.3% over 24 hours, about 6.8% over the past week, and roughly 60.8% over the past year, with a market capitalization near $1.07 billion.

Polygon Labs said it fixed a batch of security vulnerabilities in its proof-of-stake network through two hard forks that were deployed privately before the company disclosed them publicly.

In a forum post published Wednesday, the team said the fixes were packaged into the Austin hard fork for its Bor client and the Kyoto hard fork for its Heimdall client. Polygon said both were rolled out under its standard practice for consensus-affecting fixes: deploy quietly, validate on the Amoy testnet, activate on mainnet, and disclose once the network was safe.

Austin and Kyoto addressed separate sets of issues

The Austin fork closed two denial-of-service paths in block processing. One of them would have allowed a malicious block producer to crash peer nodes by stuffing a block with an oversized data field.

The Kyoto fork dealt with a broader set of consensus-hardening issues. Polygon described the most severe one as a flaw that could have let an attacker force costly, coordinated work across the entire validator set using a single crafted transaction that was cheap to create but expensive for the network to process.

Polygon said none of the flaws were observed being exploited on mainnet and that the fixes were made proactively. Both upgrades are now active and mandatory for node operators, with no need for state migration or a resync.

Disclosure comes after the MATIC-to-POL migration

The disclosure arrives at a key point for Polygon. The network has completed the migration of its legacy MATIC token to POL as part of a broader overhaul of its network architecture.

The announcement did little to support the token’s price. According to CoinGecko, POL was trading around $0.09983 on Sunday, down 2.3% over the previous 24 hours.

Over a longer stretch, the token has fallen roughly 6.8% in the past week and about 60.8% over the past year. Even with gains over the past month, its market capitalization stood near $1.07 billion.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.