Written by Nate Kostarstaff writerReviewed by Robert Lakinstaff editor
Written by Nate Kostarstaff writer
Reviewed by Robert Lakinstaff editor
Polygon discloses security flaws fixed in recent hard forks
Latest NewsPublishedAug 29, 2026
The vulnerabilities posed denial-of-service and validator resource risks but were patched before Polygon publicly disclosed them.

Polygon has disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake network, after deploying fixes through two recent hard forks.
The vulnerabilities affected Polygon’s Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion and flaws affecting checkpoint and milestone processing, as reported by a Thursday disclosure from Polygon Labs’ Validators Support Team.
Polygon stated the flaws were fixed through the Austin and Kyoto hard forks, which were deployed privately and tested before being activated on mainnet and publicly disclosed.
The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. The Austin hard fork separately addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash.
None of the vulnerabilities were observed being exploited on mainnet, as reported by Polygon, which stated the fixes were deployed proactively before details were made public.
Nodes running older versions of either client past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network, as reported by the disclosure. Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes, with both upgrades already active on mainnet.
POL, Polygon’s native token formerly known as MATIC, was trading around $0.10 at the time of writing, down about 4% over the past week but up 44% over the past month and 2.3% year to date, as reported by CoinGecko data.
Magazine: SHRINCS BIP published: Quantum-secure Bitcoin comes with a catch


Subscribe to daily byte-sized crypto news from Cointelegraph
Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
- Polygon
- Security
- Hard Fork
- Blockchain
More on the subject
Stellar tokenized RWA market more than quadruples to nearly $4B
1 hour ago
Nate Kostar
The Sandbox pledges 1:1 repayment after $700K bridge exploit
Aug 28, 2026
Ezra Reguerra
Tokenized deposits could raise US credit costs: Dallas Fed economists
Aug 27, 2026
Ezra Reguerra
Stellar tokenized RWA market more than quadruples to nearly $4B
1 hour ago
Nate Kostar
The Sandbox pledges 1:1 repayment after $700K bridge exploit
Aug 28, 2026
Ezra Reguerra
Tokenized deposits could raise US credit costs: Dallas Fed economists
Aug 27, 2026
Ezra Reguerra