Fintech & Crypto Alerts · Quinn Barrett · 29 August 2026

Polygon discloses security flaws fixed in Austin, Kyoto forks

Polygon discloses security flaws fixed in Austin, Kyoto forks

Polygon discloses security flaws in Bor and Heimdall that could have disrupted its proof-of-stake network, after deploying fixes through the Austin and Kyoto hard forks. The vulnerabilities posed denial-of-service and validator resource risks but were patched before public disclosure, and none were observed being exploited on mainnet.

The Thursday disclosure from Polygon Labs' Validators Support Team confirmed that both hard forks were deployed privately, tested, and activated on mainnet before details were made public. For operators and users tracking Fintech & Crypto Alerts, the episode underscores how major chains quietly ship consensus-critical fixes before wider disclosure.

Key Takeaways

What security flaws did Polygon disclose?

According to Polygon Labs, the vulnerabilities affected both core clients powering Polygon PoS. Issues included denial-of-service risks, validator resource exhaustion, and flaws touching checkpoint and milestone processing.

The most severe problem sat in Heimdall, Polygon's consensus client. A specially crafted transaction could compel validators to perform excessive processing work, potentially disrupting network operations. Separately, the Austin hard fork addressed two denial-of-service vectors in Bor, the execution client, that could have slowed block processing or caused nodes to crash.

Polygon emphasized that none of the vulnerabilities were observed being exploited on mainnet. The team said fixes were deployed proactively, ahead of any public details.

How did the Austin and Kyoto hard forks fix the issues?

Polygon routed the patches through two coordinated hard forks rather than routine client releases. The Austin fork targeted Bor, while Kyoto addressed Heimdall. Both upgrades were rolled out privately, validated, and then activated on mainnet before the disclosure went live.

That sequencing mirrors standard practice for consensus-affecting security work: patch first, confirm the fleet is safe, then explain what was fixed. Polygon reported the hard forks as the mechanism that closed the disclosed gaps across both client layers.

What must node operators do now?

Any node still running older Bor or Heimdall builds past the hard-fork activation heights has already fallen out of canonical consensus, according to the disclosure. Operators must upgrade to rejoin the accepted chain history.

Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is mandatory for validators and full nodes. Polygon confirmed both upgrades are already active on mainnet. Full technical context is available in the CoinTelegraph report and Polygon's own validator guidance.

Why does this matter for the Polygon network?

Proof-of-stake networks depend on synchronized, hardened client software. Undisclosed denial-of-service and resource-exhaustion bugs can threaten liveness even when they do not directly steal funds. Polygon's proactive patching limited that exposure window.

POL, Polygon's native token formerly known as MATIC, was trading around $0.10 at the time of reporting, down about 4% over the past week but up roughly 44% over the past month and 2.3% year to date, according to CoinGecko data cited in the disclosure coverage. The security news arrived alongside routine market moves rather than an exploit-driven selloff.

← Open in blast feed