Polygon quietly patched critical flaws before disclosure
Polygon quietly patched critical security flaws in two hard forks before disclosing them.

The update
Polygon Labs has disclosed that it fixed a batch of security vulnerabilities through two recent hard forks—Austin on the Bor client and Kyoto on Heimdall—that were deployed privately and validated on testnet before mainnet activation. The fixes closed denial-of-service paths in block processing and a more severe flaw that could have forced costly, coordinated work across the entire validator set via a single crafted transaction. Polygon states that none of the flaws were observed being exploited on mainnet and that all were resolved proactively. Both upgrades are now mandatory for node operators and are already active, requiring no state migration or resync.
Why it matters
This disclosure highlights the tension between proactive security maintenance and network transparency. While the proactive patching likely prevented potential disruptions, the lack of prior public disclosure raises questions about how users and validators are informed of critical changes to the network’s consensus mechanisms. It also underscores the importance of client diversity in maintaining a resilient proof-of-stake network.
What to watch
- Whether other blockchain networks have engaged in similar undisclosed security patching practices.
- How the community responds to Polygon’s explanation that this follows standard practice for consensus-affecting fixes.
- Updates on the security posture of Polygon’s other clients and the broader ecosystem.
Sources
- decrypt.co — Details on the Austin and Kyoto hard forks, the specific vulnerabilities patched, and Polygon's statement on exploitation.
- cointelegraph.com — Confirmation of the denial-of-service risks in Bor and the validator resource exhaustion issue in Heimdall.
