Polygon Discloses Unreported PoS Vulnerabilities Patched Via Austin And Kyoto Hard Forks, Mandates Client Updates

Polygon Labs has issued an pressing discover requiring all Polygon PoS node operators to improve their Bor and Heimdall shoppers following the activation of the Austin and Kyoto laborious forks.
The firm disclosed that a number of beforehand unreported safety vulnerabilities have been patched by these coordinated upgrades, stressing that nodes nonetheless working pre-fork software program have already deviated from canonical consensus and should catch as much as rejoin the community’s accepted historical past.
Austin activated on the mainnet at block 91,949,700 and requires Bor model 2.10.0 or later, whereas Kyoto activated at block top 51,533,000 and requires Heimdall model 0.11.0. The Kyoto mainnet fork went reside on 18 August 2026 at 10:10:31 UTC, with each laborious forks already lively on the Amoy testnet at earlier block heights. Polygon emphasised that these are plain binary upgrades requiring no state migration or genesis adjustments.
However, operators who handed the activation thresholds on outdated shoppers have fallen out of consensus and should set up the relevant launch, roll again to a pre-hardfork level if vital, and resync below official steerage to comply with the canonical chain once more.
Security Fixes and Network Hardening
The disclosed vulnerabilities affected Polygon’s execution and consensus layers individually. The Austin laborious fork on Bor addressed two denial-of-service vectors in block processing: an unbounded fuel consumption path throughout state-sync occasions from L1-to-L2 bridge deposits, and an unrestricted TxDependency extra-data discipline that might crash friends processing outsized blocks.
Since state-sync occasions execute contract code with out a mounted block-level ceiling, sufficiently expensive occasions may sluggish processing sufficient to transiently stall the chain. Austin resolved this by imposing a per-block fuel restrict on state-sync operations and eradicating the unbounded TxDependency discipline from the wire format completely.
Kyoto launched consensus-hardening measures throughout Heimdall’s transaction and checkpointing logic. The most extreme repair limits the nesting depth of google.protobuf.Any messages, stopping malicious actors from establishing low-cost transactions that power validators into costly decode work.
Additional patches cap fee-coin counts earlier than validation scans, normalize checkpoint signature restoration bytes to stop anchoring failures on Ethereum, and harden milestone voting, producer-downtime dealing with, and L1-event replay key uniqueness. Polygon confirmed that not one of the vulnerabilities have been exploited on mainnet, and the fixes have been privately validated on Amoy earlier than public deployment to make sure fleet security.
All node operators should deal with the upgrades as necessary. Bor serves as Polygon PoS’s execution shopper, whereas Heimdall manages consensus and checkpointing; sustaining present variations on each is important for community compatibility and continued participation.
The put up Polygon Discloses Unreported PoS Vulnerabilities Patched Via Austin And Kyoto Hard Forks, Mandates Client Updates appeared first on Metaverse Post.
