Polygon Discloses Security Flaws Fixed in Hard Forks, Says No Mainnet Exploitation Found
Summary
- Polygon said it fixed multiple security vulnerabilities on its proof-of-stake (PoS) network through hard forks and disclosed the details afterward.
- Polygon said it resolved potential DoS attacks in the Heimdall and Bor clients, along with validator resource exhaustion and checkpoint and milestone processing errors, through the Austin and Kyoto hard forks.
- Polygon said there were no confirmed cases of exploitation on the mainnet, and that PoS nodes must upgrade to Bor v2.10.0, while validators and full nodes must move to Heimdall v0.11.0.
Forecast Trend Report by Period



Polygon disclosed multiple security vulnerabilities on its proof-of-stake, or PoS, network after fixing them through hard forks. It said it has found no cases of the flaws being exploited on the mainnet.
Cointelegraph reported on August 29 that Polygon Labs' validator support team detailed the vulnerabilities in an official report. The issues affected the Bor and Heimdall clients and included potential denial-of-service, or DoS, attacks, validator resource exhaustion, and errors in checkpoint and milestone processing.
The most severe vulnerability was found in the Heimdall client. A specially crafted transaction could have imposed excessive computational load on validators and disrupted network operations. Polygon also identified two DoS vulnerabilities in the Bor client that could have slowed block processing or forced nodes to shut down.
Polygon resolved the issues through the Austin and Kyoto hard forks. It withheld the details until the fixes were completed, then disclosed them after deployment, testing and mainnet activation were finished. So far, it said, no actual exploitation has been detected on the mainnet.
Following the hard forks, nodes running older client versions are no longer participating in the normal consensus process. They must upgrade to the latest versions to rejoin the network.
Polygon PoS nodes must upgrade to Bor v2.10.0. Validators and full nodes must use Heimdall v0.11.0. Both versions are now active on the mainnet.
YM Lee
20min@bloomingbit.ioCrypto Chatterbox_ tlg@Bloomingbit_YMLEE