Polygon Quietly Patches Critical Security Flaws in PoS Network

By José Oramas August 31, 2026 In Polygon, Security
Source: Adobe Stock
  • Polygon Labs said the Austin fork on the Bor client and the Kyoto fork on the Heimdall client fixed a batch of security and liveness flaws, including two denial-of-service paths in block processing.
  • The most severe flaw gave attackers a permissionless way to force costly, correlated decode work across the whole validator set with a single crafted transaction, according to the Aug. 27 disclosure.
  • Austin activated on mainnet Aug. 13 and Kyoto on Aug. 18, and Polygon said the flaws were addressed ahead of any exploitation on mainnet.

Polygon Labs revealed on Aug. 27 that two hard forks already active on its proof-of-stake network, Austin and Kyoto, had fixed a batch of security and liveness flaws, with details withheld until every fix was live on mainnet.

Polygon’s validator support team posted the disclosure to the project’s governance forum, stating the fixes were rolled out privately, validated on the Amoy testnet before mainnet activation, and made public “once the fleet was safe”. 

Polygon characterised that sequence as standard practice for consensus-affecting fixes and stated the flaws were addressed ahead of any exploitation, with every fix validated before the forks activated.

Austin shipped in version 2.10.0 of Bor, the network’s execution client, and closed two denial-of-service paths in block processing. Bridge deposits arriving from Ethereum carried no per-block gas cap, so a block loaded with enough of them could temporarily stall the chain. 

Advertisement

A second field in block data, an unbounded parallel-execution hint called TxDependency, let a block producer crash peer nodes with an oversized entry, and Austin removed the field entirely.

Read more: World Liberty’s USD1 Stablecoin Goes Live on Canton for Institutional RWA Settlements

Validator-Wide Attack Path Closed

Kyoto, delivered in version 0.11.0 of the Heimdall consensus client, bundled eight hardening fixes. Polygon ranked one above the rest: a single crafted transaction with deeply nested data fields could force every validator into heavy decode work at once, which the disclosure called “a permissionless way to force costly, correlated work across the whole validator set”, cheap for a sender to build and expensive for the network to process.

Other Kyoto items fixed a signature-formatting flaw that could stall the anchoring of Polygon checkpoints to Ethereum, capped unbounded fee lists in transactions, and bound validator milestone votes to the exact parent block they attest to.

Austin activated on mainnet at block 91,949,700 at 1:59 p.m. UTC on Aug. 13, and its public release notes appeared on GitHub about two hours later. Kyoto followed at Heimdall height 51,533,000 on Aug. 18, also ahead of its release notes, and the full forum write-up came nine days after that.

Both upgrades are mandatory for node operators, and Polygon described them as plain binary upgrades with no state migration or resync required. Nodes still running older versions past the fork heights have already fallen out of consensus, the disclosure noted.

Advertisement

The token replaced MATIC as the network’s native asset under the Polygon 2.0 overhaul, and Polygon Labs signed agreements to buy payments firm Coinme and wallet developer Sequence for more than US$250 million (AU$348 million) as it expands into regulated payments.

Read more: XRP Up 44% as Korean Bank Taps Ripple for Cross-Border Payments

José Oramas
Author

José Oramas

José is a journalist and translator with a keen interest in blockchain and cryptocurrencies.

You may also like