Polygon Discloses Security Flaws Patched Through Two Hard Forks
Key Takeaways
- •The disclosed vulnerabilities affected Polygon's Bor execution client and Heimdall consensus client, including denial-of-service risks and validator resource exhaustion.
- •Fixes were deployed and tested through the Austin and Kyoto hard forks before technical details were publicly released, following coordinated disclosure practice.
- •A specially crafted transaction targeting Heimdall could have overloaded validators and disrupted network operations, while two Bor denial-of-service flaws could slow block processing or crash nodes.
- •Polygon stated it found no evidence that any of the vulnerabilities were exploited on the mainnet.
- •Nodes must upgrade to Bor v2.10.0 and Heimdall v0.11.0 or they have fallen out of consensus with the canonical Polygon network.

Polygon has publicly disclosed several previously undisclosed security vulnerabilities that could have disrupted its proof-of-stake network, after fixes were deployed and tested through two hard forks ahead of any public disclosure.
According to a disclosure from Polygon Labs' Validators Support Team, the vulnerabilities affected Polygon's Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion, and weaknesses involving checkpoint and milestone processing. Bor is Polygon's execution client, derived from Go Ethereum (Geth), while Heimdall is the consensus-layer client, built on Tendermint and Cosmos SDK technology, which handles checkpointing to Ethereum and milestone production — meaning flaws in either component can affect different layers of the network's operation.
Polygon said the flaws were resolved through the Austin and Kyoto hard forks. The upgrades were initially deployed privately, allowing developers and validators to test the fixes before they were activated on the mainnet. Technical details were released only after the corrective measures were already in place, reducing the window in which attackers could have exploited publicly available information on the live network. This approach follows the broader industry practice of coordinated (responsible) disclosure, which many blockchain projects and security researchers use to ensure patches are widely deployed before vulnerability details become public.
Critical Heimdall Vulnerability Could Overload Validators
The most serious issue identified involved Heimdall, a component responsible for important functions within the Polygon PoS architecture. A specially crafted transaction could have forced validators to perform an unusually large amount of processing work, potentially exhausting validator resources and disrupting network operations. Because validators are essential to maintaining consensus, excessive computational demands could have affected the network's ability to process transactions and maintain normal operations.
The disclosure also identified two separate denial-of-service vulnerabilities in Bor, another core Polygon client. Those issues were addressed through the Austin hard fork and could have slowed block processing or caused affected nodes to crash.
Together, the vulnerabilities demonstrated several ways in which carefully constructed network activity could have placed pressure on individual nodes or interfered with core blockchain operations. However, Polygon stated that it had not observed evidence that any of the disclosed vulnerabilities had been exploited on the mainnet. The absence of known exploitation was significant because the issues were fixed before their technical details became public, limiting the period in which attackers could have developed exploits from public information.
Older Nodes Must Upgrade to Rejoin Network
Polygon warned operators running older versions of the Bor or Heimdall clients that they must upgrade if their nodes had passed the relevant hard-fork activation heights. Nodes that failed to adopt the required versions had already fallen out of consensus with the canonical Polygon network and could not participate normally until their software was updated.
Polygon requires Bor v2.10.0 for all Polygon PoS nodes, while validators and full nodes must run Heimdall v0.11.0. Both versions have already been activated on the mainnet. The mandatory upgrades are designed to keep validators and full nodes aligned with the patched network and prevent outdated software from continuing to participate in consensus after the hard-fork changes.
The disclosure also highlights the importance of maintaining multiple independently operated blockchain clients and keeping validator infrastructure current as new security risks emerge. Vulnerabilities affecting consensus-related software can have consequences beyond individual applications, since disruptions may affect transaction processing and network availability. Polygon's decision to disclose the issues only after deploying and testing the fixes gives developers and node operators the information needed to understand why the upgrades were required.
At the time of the report, POL, Polygon's native token formerly known as MATIC, was trading near $0.95 and had declined about 7.8% over the previous 24 hours, according to market data cited in the report. The token's movement occurred as Polygon addressed the security disclosures, although the reported vulnerabilities had not been linked to any observed mainnet exploitation.
The network's immediate priority remains maintaining consensus across upgraded nodes and ensuring validators continue operating on the patched software as the security review progresses.
Source: CoinTrust