SECURITY

Polygon discloses security flaws fixed in Austin and Kyoto hard forks; node upgrades now required

Aug 30, 2026 · SECURITY

Polygon on Aug 29 disclosed previously-private security vulnerabilities affecting its Bor and Heimdall clients. The fixes were shipped through the Austin and Kyoto hard forks. The issues included two denial-of-service risks in Bor that could slow block processing or crash nodes, validator resource exhaustion, and flaws in checkpoint and milestone processing. The most severe was in Heimdall: a crafted transaction could force validators into excessive processing. Polygon said no exploitation was observed on mainnet and that the fixes were deployed before public disclosure. Bor v2.10.0 is required for all Polygon PoS nodes and Heimdall v0.11.0 for validators and full nodes; both versions are active on mainnet. Nodes still on older versions past the hard fork heights have fallen out of consensus. POL traded near $0.10, down about 4% over the past week.

Polygon Labs Validators Support Team; Cointelegraph

Content on this page is for informational purposes only and is not financial advice.