Polygon Reveals Security Flaws Patched in Hard Forks, Says No Mainnet Exploitation Found
Forecast Trend Report by Period



Polygon has disclosed multiple security vulnerabilities found on its proof-of-stake network after patching them through hard forks. No cases of the flaws being exploited on the mainnet have been identified.
Cointelegraph reported on August 29 that Polygon Labs' validator support team outlined the vulnerabilities in an official report. The issues were found in the Bor and Heimdall clients. Key risks included potential denial-of-service attacks, validator resource exhaustion, and errors in checkpoint and milestone processing.
The most severe vulnerability was identified in the Heimdall client. A specially crafted transaction could have imposed excessive computational strain on validators and disrupted network operations. Polygon also found two denial-of-service vulnerabilities in the Bor client that could have slowed block processing or forced nodes to shut down.
Polygon said it resolved the issues through the Austin and Kyoto hard forks. Details of the vulnerabilities were kept private until the fixes were completed. The company disclosed them after deployment, testing and the mainnet rollout were finished. Polygon said it has not found any confirmed cases of exploitation on the mainnet so far.
Since the hard forks, nodes running older client versions have fallen out of the normal consensus process. They must upgrade to the latest versions to rejoin the network.
Polygon PoS nodes must update to Bor v2.10.0, while validators and full nodes must run Heimdall v0.11.0. Both versions are now active on the mainnet.