started · updated
Polygon Labs patches PoS network vulnerabilities via hard forks
Polygon Labs has disclosed the patching of several security vulnerabilities within its Proof-of-Stake (PoS) network through two coordinated hard forks: Austin and Kyoto. The company followed a protocol of deploying the fixes privately and validating them on the Amoy testnet before activating them on the mainnet and subsequently making a public disclosure.
The Austin hard fork, which upgraded the Bor execution client to version 2.10.0, addressed two denial-of-service (DoS) vulnerabilities. These included a lack of gas limits on state-sync events and an oversized data field in TxDependency that could have caused peer nodes to crash.
The Kyoto hard fork, targeting the Heimdall client (v0.11.0), focused on consensus-hardening. The most significant flaw addressed was a vulnerability where a single, specially crafted transaction could have forced the entire validator set to perform excessive, costly computational work, potentially disrupting network operations.
Polygon stated there is no evidence that any of these vulnerabilities were exploited on the mainnet. Both upgrades are now mandatory for node operators, and nodes running outdated versions are considered to be outside the canonical consensus chain.
Entities
Amoy testnet · Bor · Heimdall · Pol · Polygon Labs
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] The Kyoto fork addressed consensus-hardening issues, including a flaw that could force costly work across the validator set. bitnewsbot.com · techxeber.az
- [● 2 SOURCES] None of the security flaws were observed being exploited on the mainnet. bitnewsbot.com
- [● 3 SOURCES] The Kyoto hard fork was applied to the Heimdall client. bitnewsbot.com · techxeber.az
- [● 3 SOURCES] The native POL token was trading at approximately $0.09983. bitnewsbot.com · techxeber.az
- [● 2 SOURCES] The Austin fork closed two denial-of-service paths in block processing. bitnewsbot.com
- [● 3 SOURCES] The Austin hard fork was applied to the Bor client. bitnewsbot.com · techxeber.az
- [● 2 SOURCES] Both hard fork upgrades are mandatory for node operators. bitnewsbot.com · techxeber.az
- [● 3 SOURCES] Polygon Labs patched security vulnerabilities using two hard forks. bitnewsbot.com · techxeber.az