Polygon Discloses Security Flaws Fixed in Recent Hard Forks
Polygon has disclosed security vulnerabilities fixed in recent hard forks, affecting Bor and Heimdall clients and potentially disrupting the proof-of-stake network.
Intelligence analysis by Qwen 2.5 (3B)

Polygon, a blockchain platform, has disclosed security flaws in its Bor and Heimdall clients that were fixed through recent hard forks, preventing potential disruptions to its proof-of-stake network.
Polygon found some problems in its blockchain that could have made it crash. They fixed these problems in a special update, and now the blockchain is safer.
Analysis
{"heading_1":"Details of the Security Flaws","paragraph_1":"Polygon Labs' Validators Support Team disclosed that the vulnerabilities affected the Bor and Heimdall clients, including denial-of-service risks, validator resource exhaustion, and flaws in checkpoint and milestone processing.","paragraph_2":"The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network.","paragraph_3":"The Austin hard fork separately addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash.","paragraph_4":"Polygon stated that the flaws were fixed through the Austin and Kyoto hard forks, which were deployed privately and tested before being activated on mainnet and publicly disclosed.","paragraph_5":"Nodes running older versions of either client past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network.","paragraph_6":"Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes, with both upgrades already active on mainnet."}
Key points
- Polygon disclosed security vulnerabilities in its Bor and Heimdall clients
- The vulnerabilities included denial-of-service risks, validator resource exhaustion, and flaws in checkpoint and milestone processing
- The Austin and Kyoto hard forks were deployed to fix these vulnerabilities
- Nodes running older versions of either client must upgrade to rejoin the network
- Bor v2.10.0 and Heimdall v0.11.0 are now required for all Polygon PoS nodes and validators
The fixes should prevent any major disruptions to the Polygon network, ensuring a smooth and secure blockchain experience for users.
If the vulnerabilities had been exploited, it could have caused the network to crash, leading to potential loss of funds or data.



