Polygon Discloses DoS Vulnerabilities Fixed in Austin and Kyoto Hard Forks
Key Takeaways
- •Polygon disclosed security flaws in its Bor and Heimdall clients only after fixing them through the Austin and Kyoto hard forks, following a coordinated-disclosure practice.
- •The most severe vulnerability allowed a specially crafted transaction to force Heimdall validators into excessive processing, potentially disrupting the network.
- •Two denial-of-service risks in Bor could have slowed block processing or crashed nodes, threatening network availability though not fund safety.
- •Polygon reported that none of the vulnerabilities were exploited on mainnet before the fixes were deployed.
- •Nodes must upgrade to Bor v2.10.0 and Heimdall v0.11.0, as older versions have already fallen out of consensus.

Polygon has publicly disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake (PoS) network, after fixes were deployed through two recent hard forks. The coordinated-disclosure approach — fixing first, disclosing later — is a common practice among major blockchain teams to minimize the window in which attackers could exploit a known flaw.
According to a Thursday disclosure from Polygon Labs' Validators Support Team, the vulnerabilities affected Polygon's Bor and Heimdall clients and included denial-of-service (DoS) risks, validator resource exhaustion, and flaws in checkpoint and milestone processing. Bor serves as Polygon PoS's block-producing client, while Heimdall handles checkpointing to Ethereum, meaning both are core to the network's operation.
Polygon stated that the flaws were resolved via the Austin and Kyoto hard forks, which were deployed privately and thoroughly tested before being activated on mainnet and publicly disclosed.
The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. Separately, the Austin hard fork addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash. DoS vulnerabilities of this kind do not typically allow fund theft, but they can degrade network availability — a concern for the applications and users relying on Polygon PoS, which remains one of the more widely used Ethereum scaling networks.
Polygon reported that none of the vulnerabilities were observed being exploited on mainnet, noting that the fixes were deployed proactively before the details were made public.
The disclosure warned that nodes running older versions of either client past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network. Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes. Both upgrades are already active on mainnet.
POL, Polygon's native token formerly known as MATIC, was trading around $0.10 at the time of writing — down roughly 4% over the past week, up 44% over the past month, and up 2.3% year to date, according to CoinGecko data.
Magazine: SHRINCS BIP published: Quantum-secure Bitcoin comes with a catch