Polygon discloses security flaws fixed in recent hard forks

Summary

Polygon disclosed several previously private security vulnerabilities in its proof-of-stake network and said they were fixed before public release through two hard forks, Austin and Kyoto. The bugs affected the Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion, and issues in checkpoint and milestone processing. The most serious flaw was in Heimdall: a specially crafted transaction could trigger excessive validator work and potentially disrupt the network. Austin addressed two Bor denial-of-service issues that could have slowed block processing or crashed nodes. Polygon said none of the vulnerabilities were seen on mainnet and that the fixes were deployed proactively after private testing. Nodes still running older client versions past the fork heights are now out of consensus and must upgrade to rejoin the network. Required versions are Bor v2.10.0 and Heimdall v0.11.0.