Polygon Quietly Patched Security Flaws in Two Hard Forks Before Disclosing Them

Summary

Polygon Labs quietly fixed multiple proof-of-stake network vulnerabilities with two private hard forks before publicly disclosing them. The Austin fork on the Bor client patched two denial-of-service issues in block processing, including a flaw where an oversized data field could crash peer nodes. The Kyoto fork on the Heimdall client addressed several consensus-hardening bugs, including one that could have let an attacker trigger expensive, coordinated validator-wide work using a single crafted transaction. The team said none of the issues were seen exploited on mainnet, and the fixes were tested on the Amoy testnet before deployment. Both upgrades are now mandatory for node operators, already active, and require no state migration or resync. The disclosure comes as Polygon continues its POL token transition and broader network overhaul, while POL remains under pressure in price and market value.