Polygon has disclosed several previously undisclosed security vulnerabilities that could have disrupted its proof-of-stake network, following the deployment of fixes through two hard forks that were tested and activated before details of the issues were made public.
The vulnerabilities affected Polygon’s Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion and weaknesses involving checkpoint and milestone processing, according to a disclosure from Polygon Labs’ Validators Support Team.
Polygon said the vulnerabilities had been addressed through the Austin and Kyoto hard forks. The upgrades were initially deployed privately, allowing developers and validators to test the fixes before they were activated on the mainnet. Details of the vulnerabilities were released only after the corrective measures were in place.
Polygon proactively fixed multiple vulnerabilities across its Bor and Heimdall clients through the Austin and Kyoto hard forks before publicly disclosing the security issues, reducing the risk of exploitation on the live network.
Critical Heimdall Vulnerability Could Overload Validators
The most serious vulnerability identified in the disclosure involved Heimdall, a component responsible for important functions within the Polygon PoS architecture. A specially crafted transaction could have forced validators to perform an unusually large amount of processing work.
Such an attack could have exhausted validator resources and potentially disrupted network operations. Because validators are essential to maintaining consensus, excessive computational demands could have affected the network’s ability to process transactions and maintain normal operations.
The disclosure also identified two separate denial-of-service vulnerabilities in Bor, another core Polygon client. Those issues were addressed through the Austin hard fork and could potentially have slowed block processing or caused affected nodes to crash.
The vulnerabilities demonstrated several ways in which carefully constructed network activity could have placed pressure on individual nodes or interfered with core blockchain operations. However, Polygon said it had not observed evidence that any of the disclosed vulnerabilities had been exploited on the mainnet.
The absence of known exploitation was significant because the vulnerabilities were addressed before technical details became public. Polygon’s approach allowed the network to receive the necessary software changes while limiting the period during which attackers could have used publicly available information to develop exploits.
Older Nodes Must Upgrade to Rejoin Network
Polygon also warned operators running older versions of the Bor or Heimdall clients that they must upgrade if their nodes had passed the relevant hard-fork activation heights.
Nodes that failed to adopt the required versions had already fallen out of consensus with the canonical Polygon network. This means those systems could not continue participating normally until their software was updated.
Polygon requires Bor v2.10.0 for all Polygon PoS nodes, while validators and full nodes must run Heimdall v0.11.0. Both versions have already been activated on the mainnet.
The mandatory client upgrades are designed to keep validators and full nodes aligned with the patched network, while preventing outdated software from continuing to participate in consensus after the hard-fork changes.
The disclosure highlights the importance of maintaining multiple independently operated blockchain clients and keeping validator infrastructure updated as new security risks are identified. Vulnerabilities affecting consensus-related software can have consequences beyond individual applications because disruptions may affect transaction processing and network availability.
Polygon’s decision to disclose the issues after deploying and testing the fixes also provides developers and node operators with information needed to understand why the upgrades were required.
At the time of the report, POL, Polygon’s native token formerly known as MATIC, was trading near $0.95 and had declined about 7.8% over the previous 24 hours, according to market data cited in the report. The token’s market movement occurred as Polygon addressed the security disclosures, although the reported vulnerabilities had not been linked to any observed mainnet exploitation.
The network’s immediate priority remains maintaining consensus across upgraded nodes and ensuring validators continue operating on the patched software as the security review progresses.







