Polygon has disclosed a group of security vulnerabilities in its proof-of-stake network after first deploying fixes through two recent hard forks. The issues affected the Bor and Heimdall clients and, according to the project, could have disrupted network operations through denial-of-service conditions, validator resource exhaustion and flaws tied to checkpoint and milestone processing.

The company said it handled the fixes privately, testing them before activating the Austin and Kyoto hard forks on mainnet and only then publishing details. Polygon added that it did not observe any of the vulnerabilities being exploited on mainnet.

Issues affected both core PoS clients

The disclosure covers problems in both of Polygon PoS’s main software components, Bor and Heimdall. Polygon said the flaws created several categories of risk, including denial-of-service scenarios, excessive validator workload and weaknesses in the way checkpoint and milestone-related processes were handled.

Among the disclosed issues, Polygon described the most serious as a Heimdall vulnerability in which a specially crafted transaction could force validators to carry out unusually heavy processing. In practice, the project said, that could have disrupted the network by consuming validator resources.

Austin and Kyoto carried the fixes

Polygon said the vulnerabilities were remediated through the Austin and Kyoto hard forks. Rather than announcing the flaws in advance, the team said it deployed the changes privately and tested them before switching them on across mainnet.

Austin also addressed two separate denial-of-service risks in Bor. According to Polygon, those issues could have slowed block processing or caused nodes to crash if triggered.

No mainnet exploitation reported

In its disclosure, Polygon said it had not seen evidence that any of the vulnerabilities were used against the live network. The project presented the delayed disclosure as a proactive security measure, with technical details released only after the relevant fixes were already active.

That sequence is significant for network operators because the hard forks are no longer optional maintenance updates. Once the activation heights passed, nodes that continued running older client versions fell out of consensus, meaning they no longer tracked the canonical chain.

Required versions for rejoining the network

Polygon said all Polygon PoS nodes now need Bor v2.10.0, while Heimdall v0.11.0 is required for validators and full nodes. Both versions are already live on mainnet as the supported software following the two upgrades.

For operators still on earlier releases, the next confirmed step is to upgrade to the required versions in order to rejoin the canonical network. The disclosure does not report any exploitation, but it makes clear that legacy versions cannot remain in consensus after the hard fork changes took effect.

Source: cointelegraph.com