All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Crypto & Digital Assets

Polygon Patches Security Flaws via Two Hard Forks

Created at 30 Aug · 10:35 PM1 source↑ Market-relevant
IN SHORT

Polygon Labs has disclosed the patching of security vulnerabilities through two private hard forks, Austin and Kyoto, on its proof-of-stake network. The fixes addressed denial-of-service paths and a critical flaw that could have forced costly validator actions. The native token POL saw a slight decline.

Key Numbers

$0.09983POL token price Sunday
2.3%POL token daily decline
6.8%POL token weekly decline
60.8%POL token yearly decline
$1.07 billionPOL token market capitalization

Who's Involved

Polygon Labs
Developer that patched security vulnerabilities
Bor client
Client that received the Austin hard fork
Heimdall client
Client that received the Kyoto hard fork
Polygon Patches Security Flaws via Two Hard Forks

↳ Why This Matters

The proactive patching of vulnerabilities through private hard forks demonstrates Polygon's commitment to network security, aiming to prevent potential exploits and maintain validator integrity, which is crucial for user trust and the stability of its ecosystem.

Key facts

  • Polygon Labs fixed security vulnerabilities through two private hard forks: Austin (Bor client) and Kyoto (Heimdall client).
  • The Austin fork closed denial-of-service paths in block processing.
  • The Kyoto fork addressed a severe flaw allowing a single transaction to force costly validator work.
  • Fixes were validated on testnet before mainnet activation and disclosed publicly afterward.
  • No vulnerabilities were exploited on the mainnet.
  • The upgrades are mandatory for node operators.

Polygon Labs has revealed that it fixed a batch of security vulnerabilities in its proof-of-stake network through two hard forks that were rolled out privately before being disclosed publicly. In a forum post published Wednesday, the team detailed the fixes bundled into the Austin hard fork on its Bor client and the Kyoto hard fork on its Heimdall client. Both were deployed following what Polygon described as standard practice for consensus-affecting fixes: rolling them out quietly and validating them on the Amoy testnet before mainnet activation, then going public once the network was safe. The Austin fork closed two denial-of-service paths in block processing, including one where a malicious block producer could crash peer nodes by stuffing a block with an oversized data field. The Kyoto fork addressed a larger set of consensus-hardening issues, the most severe being a flaw that would have let an attacker force costly, coordinated work across the entire validator set using a single crafted transaction, cheap to build but expensive for the network to process. Polygon stressed that none of the flaws were observed being exploited on mainnet and that all were resolved proactively. Both upgrades are now mandatory for node operators and are already active, requiring no state migration or resync. The disclosures land during a pivotal stretch for Polygon, which completed the migration of its legacy MATIC token to POL, as part of a broader overhaul of its network architecture. The news did little to lift the price of POL, which was trading around $0.09983 on Sunday, down 2.3% over 24 hours, according to CoinGecko. The token has slid roughly 6.8% over the past week and is down about 60.8% over the past year, leaving it with a market capitalization near $1.07 billion despite gains over the past month.

Frequently asked questions

Polygon implemented the Austin hard fork on its Bor client and the Kyoto hard fork on its Heimdall client.

The fixes addressed denial-of-service paths in block processing and a critical flaw that could have forced costly, coordinated work across the validator set.

Polygon stressed that none of the flaws were observed being exploited on the mainnet.

Yes, both upgrades are mandatory for node operators and are already active.

What Happens Next

01Node operators must ensure their systems are updated to the mandatory hard forks.
02Further network upgrades and security audits are expected from Polygon Labs.
CME Headlines
  • Bitcoin futures break $80,000 as consumer confidence drops.
    25 Aug · 6:57 PM
  • Bitcoin futures break $80,000 as consumer confidence drops.
    25 Aug · 6:57 PM
  • Can Bitcoin's Long-Term Catalysts Overcome Recent Headwinds?
    24 Aug · 3:00 PM

How It Developed

Polygon Labs privately rolled out two hard forks, Austin and Kyoto, to address security vulnerabilities.
The Austin hard fork fixed denial-of-service paths in block processing on the Bor client.
The Kyoto hard fork addressed a flaw that could have forced costly coordinated work across validators.
Both forks were validated on the Amoy testnet before mainnet activation.
Polygon Labs disclosed the fixes publicly after ensuring network safety.
The vulnerabilities were not observed being exploited on the mainnet.
The upgrades are mandatory for node operators and are now active.
Polygon recently completed the migration of its legacy MATIC token to POL.

Sources

T1
Polygon Quietly Patched Security Flaws in Two Hard Forks Before Disclosing ThemDecrypt

Related Stories

Michael Saylor Hints at Resuming Bitcoin Buys After 2-Month Hiatus
30 Aug · 2:41 PM
Bitcoin ETFs See Outflows, Ending Inflow Streak as Ether Funds Continue Gains
30 Aug · 9:36 PM