Polygon discloses security flaws fixed in recent hard forks

cointelegraph2026-08-29 tarihinde yayınlandı2026-08-29 tarihinde güncellendi

Özet

Polygon has revealed previously undisclosed security vulnerabilities in its proof-of-stake network, which were fixed via the recent Austin and Kyoto hard forks. The flaws, affecting the Bor and Heimdall clients, included denial-of-service risks, validator resource exhaustion, and issues with checkpoint processing. The most severe involved a Heimdall vulnerability where a malicious transaction could overload validators and disrupt the network. Polygon stated the fixes were deployed privately and tested before mainnet activation, with no observed exploits. Nodes must upgrade to Bor v2.10.0 and Heimdall v0.11.0 to remain in consensus.

Polygon has disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake network, after deploying fixes through two recent hard forks.

The vulnerabilities affected Polygon’s Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion and flaws affecting checkpoint and milestone processing, according to a Thursday disclosure from Polygon Labs’ Validators Support Team.

Polygon said the flaws were fixed through the Austin and Kyoto hard forks, which were deployed privately and tested before being activated on mainnet and publicly disclosed.

The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. The Austin hard fork separately addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash.

None of the vulnerabilities were observed being exploited on mainnet, according to Polygon, which said the fixes were deployed proactively before details were made public.

Nodes running older versions of either client past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network, according to the disclosure. Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes, with both upgrades already active on mainnet.

POL, Polygon’s native token formerly known as MATIC, was trading around $0.10 at the time of writing, down about 4% over the past week but up 44% over the past month and 2.3% year to date, according to CoinGecko data.

Magazine: SHRINCS BIP published: Quantum-secure Bitcoin comes with a catch

İlgili Sorular

QWhat were the general security vulnerabilities disclosed by Polygon in their proof-of-stake network?

APolygon disclosed vulnerabilities that included denial-of-service risks, validator resource exhaustion, and flaws affecting checkpoint and milestone processing in their Bor and Heimdall clients.

QHow did Polygon fix the disclosed security vulnerabilities?

APolygon fixed the vulnerabilities through two recent hard forks named Austin and Kyoto, which were deployed privately, tested, and then activated on the mainnet before being publicly disclosed.

QWhat was the most severe security issue mentioned in the article?

AThe most severe issue was in the Heimdall client, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network.

QWhat versions of the clients are now required for nodes following the hard forks?

ABor v2.10.0 is required for all Polygon PoS nodes, and Heimdall v0.11.0 is required for validators and full nodes.

QWere any of the disclosed vulnerabilities exploited on the Polygon mainnet?

ANo, according to Polygon, none of the vulnerabilities were observed being exploited on the mainnet.

İlgili Okumalar

Don't Trust, Verify: Malicious AI Links Expose a Nightmare Reality for Crypto Industry Workers

Generative AI is becoming increasingly prevalent, with professionals in the digital assets and blockchain space regularly using it. However, this makes them prime targets for attackers seeking to steal sensitive, often irrevocable, information. Refi Hub co-founder Numa Lunah recently reported being "hacked" through a malicious link sent in a chat with the AI model Claude, which appeared to be a legitimate transcription app download. The link installed malware that attempted to steal all his data. While Numa claimed no sensitive data was leaked—as he wiped and reinstalled his laptop's OS—he later discovered a corrupted `SKILL.md` file in his backups, disguised as a style guide. This file contained hidden instructions to reload the malware and steal credentials whenever the AI accessed it. This incident highlights a new attack vector: LLMs providing malicious outputs. Microsoft Defender experts have previously warned about the evolution of cryptojacking attacks from SEO poisoning to "poisoning" LLM responses from models like Gemini, Claude, Copilot, and ChatGPT. Threats include malicious artifacts via context windows, chatbot-recommended download links, fake AI-branded installers, and infected source code or agent skills. For crypto professionals, the risk is heightened because they often manage irreplaceable secrets like seed phrases, private keys, exchange API keys, and wallet data. The article argues that the most dangerous vulnerability is human trust and complacency. A fundamental shift in security culture is needed: treating every AI suggestion as potentially hostile, regardless of its source. This isn't paranoia but a survival necessity. The key takeaway is that the threat lies not in vulnerable code but in the human instinct to trust convenient answers, a flaw no software patch can fix. Numa was saved only because he meticulously reviewed every configuration file before letting the AI interact with it—a level of caution most users likely neglect.

cryptonews.ru1 saat önce

Don't Trust, Verify: Malicious AI Links Expose a Nightmare Reality for Crypto Industry Workers

cryptonews.ru1 saat önce

Will the Fed Raise Interest Rates in September? Latest Probability Indicators Here!

Will the Fed raise interest rates in September? Market expectations have shifted significantly following cautious inflation remarks from Fed Chairman Kevin Warsh. The probability of a September rate hike has surged, with market-implied odds now around 55-56% for an increase, a sharp rise of about 20 basis points in a single day. The likelihood of rates remaining unchanged is approximately 55%, while a 25-basis-point hike is priced at about 46%. Chairman Warsh, speaking at the Jackson Hole symposium, acknowledged some positive summer inflation data but stated it does not indicate a substantial improvement in underlying inflation trends. He emphasized the need for clear and timely progress toward the Fed's inflation target, warning that further policy tightening may be necessary. Following his comments, U.S. Treasury yields rose sharply. The yield on the two-year note, highly sensitive to Fed policy expectations, increased about 8 basis points to 4.31%, reaching its highest level since late July. This surge reflects investor expectations of potential near-term monetary tightening. Key inflation and employment data due in the weeks leading up to the September 16th meeting are seen as crucial for final rate decision expectations. Persistently high inflation could increase the odds of a hike, while a significant slowdown in price pressures might bolster the case for holding rates steady.

cryptonews.ru3 saat önce

Will the Fed Raise Interest Rates in September? Latest Probability Indicators Here!

cryptonews.ru3 saat önce

İşlemler

Spot
活动图片