Polygon Discloses Security Vulnerabilities Fixed in Recent Hard Forks
Polygon disclosed several previously undisclosed security vulnerabilities that were fixed through two recent hard forks, which could have affected its proof-of-stake network. The vulnerabilities involved Polygon's Bor and…
Polygon disclosed several previously undisclosed security vulnerabilities that were fixed through two recent hard forks, which could have affected its proof-of-stake network. The vulnerabilities involved Polygon's Bor and Heimdall clients, including denial-of-service risks, validator resource exhaustion, and flaws affecting checkpoint and milestone processing. Polygon stated that these vulnerabilities were fixed through the Austin and Heimdall hard forks, with fixes tested privately before being deployed to mainnet and publicly disclosed. The most severe issue involved Heimdall, where crafted transactions could force validators to perform excessive processing work, disrupting the network. The Austin hard fork also fixed two denial-of-service risks in Bor that could slow block processing or cause node crashes. Polygon stated that these vulnerabilities were not exploited on mainnet, and fixes were proactively deployed before details were made public. Nodes running old client versions fell out of consensus after the hard fork activation height and had to upgrade to rejoin the network. All Polygon PoS nodes were required to upgrade to Bor v2.1.0, and validators and full nodes were required to upgrade to Heimdall v0.11.0, with both upgrades already effective on mainnet.
insigtX content is informational and educational, not investment advice.