Polygon discloses flaws patched in Austin and Kyoto forks
Polygon Labs disclosed it quietly patched security vulnerabilities in its Bor and Heimdall clients through Austin and Kyoto hard forks, with fixes rolled out before public disclosure.
Polygon Labs disclosed on Aug. 29 that it had quietly patched security vulnerabilities through two hard forks: Austin on the Bor client and Kyoto on Heimdall. The fixes were rolled out privately, validated on the Amoy testnet, and activated on mainnet before the details became public, according to Decrypt’s report on Polygon’s disclosure.
The Austin fork closed two denial-of-service paths in block processing. One allowed a malicious block producer to crash peer nodes by filling a block with an oversized data field. Polygon says none of the vulnerabilities had been exploited on mainnet and that all were resolved proactively.
Kyoto addressed a broader group of consensus-hardening issues. The most severe, according to the disclosure, could have allowed an attacker to force costly, coordinated work across the entire validator set with a single crafted transaction. The affected areas included validator resource exhaustion as well as checkpoint and milestone processing, Cointelegraph reported.
That distinction matters for operators. Austin concerned Bor’s block-processing path, while Kyoto concerned Heimdall’s validator and consensus functions. Both upgrades are already active and mandatory: Bor v2.10.0 is required for all Polygon PoS nodes, and Heimdall v0.11.0 is required for validators and full nodes. Operators do not need to migrate state or resync.
POL holders were not identified as having lost funds, and Polygon reported no observed mainnet exploitation.
The disclosure also exposes a documentation gap. The available account identifies the Austin and Kyoto fixes by vulnerability class and client version, but it does not specify the individual EIPs, commits or code changes that closed each path. It also gives no exact activation dates for either fork beyond saying they were validated on Amoy before mainnet deployment. That limits outside assessment of whether the fixes changed transaction limits, validation logic or validator scheduling.
The steelman for Polygon’s approach is clear: consensus-affecting vulnerabilities were patched privately, tested before activation, and disclosed after the network was considered safe. The desk’s read is that this reduced the window in which an attacker could act, while leaving traders and node operators with less public detail about what changed and when.
POL was trading around $0.09983 Sunday, down 2.3% on the day and 6.8% on the week, according to Decrypt. Cointelegraph cited a decline of about 4% over the past week and a price near $0.10. The gap between those weekly figures is 2.8 percentage points: 6.8% minus 4%. Neither report links the move to the vulnerability disclosure.