Polygon Labs disclosed three security vulnerabilities affecting its proof-of-stake network, quietly deploying fixes through the Austin and Kyoto hard forks before revealing the issues publicly.
The flaws targeted Polygon's Bor and Heimdall clients and posed risks of denial-of-service attacks, validator resource exhaustion, and checkpoint and milestone processing failures. Polygon Labs' Validators Support Team issued the disclosure Thursday after privately fixing and testing the issues before activating the hard forks on mainnet.
The most severe vulnerability hit the Heimdall client. A specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the entire network.
The Austin hard fork addressed two separate denial-of-service risks in the Bor client. Both could slow block processing or crash affected nodes.
Polygon confirmed none of the vulnerabilities were exploited on mainnet. By deploying fixes before public disclosure, the team ensured network stability during the patching process.
Nodes running older versions of Bor or Heimdall past the hard fork activation heights fell out of consensus and must upgrade to rejoin the network. All Polygon PoS nodes now require Bor v2.10.0; validators and full nodes require Heimdall v0.11.0. Both upgrades are active on mainnet.
POL, Polygon's native token, traded around $0.10 Thursday. The token dropped 4 percent over the past week but rose 44 percent over the past month and 2.3 percent year to date.

