Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Polygon Fixes Security Vulnerabilities Through Recent Hard Forks

Polygon has disclosed security flaws affecting its Bor and Heimdall clients that were resolved through the Austin and Kyoto hard forks, with no evidence of exploitation on mainnet.
1 week ago 30 views
Polygon Fixes Security Vulnerabilities Through Recent Hard Forks

Polygon has disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake network after deploying fixes through two recent hard forks.

The vulnerabilities affected Polygon's Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion, and flaws affecting checkpoint and milestone processing, according to a disclosure from Polygon Labs' Validators Support Team.

Vulnerabilities Addressed

The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. The Austin hard fork separately addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash.

Polygon said the flaws were fixed through the Austin and Kyoto hard forks, which were deployed privately and tested before being activated on mainnet and publicly disclosed.

Network Requirements

Nodes running older versions of either client past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network. Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes, with both upgrades already active on mainnet.

None of the vulnerabilities were observed being exploited on mainnet, according to Polygon, which said the fixes were deployed proactively before details were made public.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.