BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Polygon Patches Serious Network Security Flaws

Polygon Labs has disclosed a series of security vulnerabilities that, if exploited, could have seriously disrupted its proof-of-stake network. The flaws were quietly patched through two hard

AnonymousCryptoCompass newsroom
August 31, 2026
2 min read
NEWS
Polygon Patches Serious Network Security Flaws
CryptoCompass editorial visual for altcoins coverage.

Polygon Labs has disclosed a series of security vulnerabilities that, if exploited, could have seriously disrupted its proof-of-stake network. The flaws were quietly patched through two hard forks before any details were made public, a deliberate sequencing intended to prevent bad actors from acting on the information before fixes were in place.

What the Vulnerabilities Involved

The vulnerabilities affected Polygon's Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion, and flaws affecting checkpoint and milestone processing, according to a disclosure from Polygon Labs' Validators Support Team.

The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. On the Bor side, the problems were equally concerning. L1-to-L2 state-sync events were effectively un-metered, meaning they could consume block resources without the gas accounting that normally limits runaway computation. The Austin fork introduced per-block gas bounds to cap that exposure.A second issue involved unbounded TxDependency data, a structure Bor uses internally to track transaction ordering. Without limits on how large that structure could grow, a crafted input could stall block processing or crash connected peers entirely.

How Polygon Responded

Polygon Labs patched the vulnerabilities through two hard forks, Austin on its Bor client and Kyoto on Heimdall, rolled out privately and validated on testnet before mainnet activation.The fixes landed in the Austin and Kyoto upgrades, which activated on the Polygon proof-of-stake mainnet on August 29, with a community forum post describing the technical details following two days earlier.

None of the vulnerabilities were observed being exploited on mainnet, according to Polygon, which said the fixes were deployed proactively before details were made public. The approach reflects a recognised best practice in blockchain security: disclosing vulnerabilities only after patches are live reduces the window during which attackers could act on public information.

The hard forks carry an immediate practical requirement for node operators. Polygon PoS nodes must upgrade to Bor v2.10.0, while validators and full nodes must move to Heimdall v0.11.0.After the hard fork activation heights, nodes running older client versions will fall out of consensus and must upgrade to rejoin the canonical chain.

Sources:Cointelegraph: Polygon Patches DoS Risks in Austin, Kyoto Hard ForksDecrypt: Polygon Quietly Patched Security Flaws in Two Hard Forks Before Disclosing ThemCrypto Briefing: Polygon Discloses Security Flaws Fixed in Austin and Kyoto Hard Forks