< Back to all clusters
[TECHNOLOGY] · United States · 12 sources

started · updated

Polygon Labs patches PoS network vulnerabilities via hard forks

Polygon Labs has disclosed the patching of several security vulnerabilities within its Proof-of-Stake (PoS) network through two coordinated hard forks: Austin and Kyoto. The company followed a protocol of deploying the fixes privately and validating them on the Amoy testnet before activating them on the mainnet and subsequently making a public disclosure.

The Austin hard fork, which upgraded the Bor execution client to version 2.10.0, addressed two denial-of-service (DoS) vulnerabilities. These included a lack of gas limits on state-sync events and an oversized data field in TxDependency that could have caused peer nodes to crash.

The Kyoto hard fork, targeting the Heimdall client (v0.11.0), focused on consensus-hardening. The most significant flaw addressed was a vulnerability where a single, specially crafted transaction could have forced the entire validator set to perform excessive, costly computational work, potentially disrupting network operations.

Polygon stated there is no evidence that any of these vulnerabilities were exploited on the mainnet. Both upgrades are now mandatory for node operators, and nodes running outdated versions are considered to be outside the canonical consensus chain.

Entities

Amoy testnet · Bor · Heimdall · Pol · Polygon Labs

Claims

What the coverage asserts, and how many sources carry each claim.