Polygon Discloses Security Vulnerabilities Fixed in Austin and Kyoto Hard Forks

Polygon Discloses Security Vulnerabilities Fixed in Austin and Kyoto Hard Forks

N
News Editor
2026-08-30 21:06:35
Polygon has disclosed multiple security vulnerabilities that remained unpublicized until their fixes had already been completed. The issues were resolved through two hard forks, Austin and Kyoto, and could affect Polygon’s proof-of-stake network. The vulnerabilities spanned the Bor and Heimdall clients, including denial-of-service risks, validator resource exhaustion, and problems tied to checkpoint and milestone processing. Polygon explained that each fix was tested privately before it was deployed to mainnet and before public disclosure. The most severe case was in Heimdall: specially constructed transactions could force validators into excessive processing work and disrupt the network. The Austin hard fork also fixed two denial-of-service risks in Bor, which could slow block processing or crash nodes. Polygon also confirmed that the vulnerabilities were not exploited on mainnet. The fixes had been completed proactively ahead of the public release of vulnerability details. No exploitation has been observed, Polygon said. The disclosure arrives after the fixes had already gone live on mainnet.

Polygon has disclosed multiple security vulnerabilities that were fixed through the Austin and Kyoto hard forks. The issues were previously undisclosed and could have affected its proof-of-stake network.

Bor and Heimdall affected

The vulnerabilities were found in Polygon's Bor and Heimdall clients, including denial-of-service risks, validator resource exhaustion, and defects impacting checkpoint and milestone processing. Polygon said the fixes were tested privately before deployment to mainnet and before the public disclosure.

The most severe issue was in Heimdall. Specially crafted transactions could force validators to perform excessive processing work, disrupting the network.

Austin hard fork fixes

The Austin hard fork also addressed two denial-of-service risks in Bor. Those risks could slow block processing or crash nodes.

Polygon said the vulnerabilities were not exploited on mainnet. The fixes were completed proactively ahead of the public release of details.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.