Polygon Labs has published details of multiple security vulnerabilities that could have threatened the reliability of its Proof-of-Stake (PoS) network—after fixing the issues via two recent hard forks and then disclosing the underlying risks.
According to a Thursday disclosure posted by Polygon Labs’ Validators Support Team, the flaws impacted the network’s Bor and Heimdall clients and ranged from denial-of-service (DoS) vectors to bugs that could interfere with validator and checkpoint-related processing.
Key takeaways
- Polygon disclosed security issues affecting both Bor and Heimdall clients, including DoS risks and validator resource exhaustion.
- The fixes were delivered through two hard forks—Austin for Bor and Kyoto for Heimdall—and were tested before activation on mainnet.
- Polygon said it has seen no evidence of the vulnerabilities being exploited on mainnet.
- After the hard fork activation heights, nodes running older client versions will fall out of consensus and must upgrade to rejoin the canonical chain.
- Upgrades are already live on mainnet: Bor v2.10.0 for PoS nodes and Heimdall v0.11.0 for validators and full nodes.
What Polygon disclosed: Bor and Heimdall risks
In its security release, Polygon described vulnerabilities that could have disrupted network operation by increasing the amount of work validators and other components had to perform, potentially leading to slowdowns or instability.
The disclosure states that Heimdall carried the most severe issue. Polygon said that a specially crafted transaction could compel validators to carry out excessive processing work, creating a realistic possibility of network disruption.
For Bor, Polygon’s disclosure highlights two separate denial-of-service risks addressed by the Austin hard fork. While the release does not expand on every implementation detail in the summary provided, it characterizes the potential impact as slowing block processing or causing nodes to crash—outcomes that can degrade throughput and availability in a validator-driven system.
Alongside these issues, Polygon also pointed to flaws tied to checkpoint and milestone processing. These components are important in PoS systems that must consistently advance state and maintain coordination across epochs and consensus-critical milestones. Errors in those flows can create cascading failures if left unpatched.
How Polygon rolled out the fixes
Polygon said the vulnerabilities were addressed through two hard forks: Austin for the Bor client and Kyoto for Heimdall. The company added that the updates were deployed privately first, with testing before activation on mainnet, and that the details were made public only after the network upgrades were already in place.
Crucially for operators, Polygon indicated that none of the disclosed vulnerabilities had been observed being exploited on mainnet. The report frames the disclosure as a proactive measure—Polygon says it pushed the fixes before publishing the full technical details.
Upgrade requirements: staying in consensus after activation
Polygon also made the practical implications explicit: nodes that continue running older versions of either client past the hard fork activation heights will no longer be in consensus with the canonical network.
To avoid being cut off from the main chain, Polygon said that:
- Bor v2.10.0 is required for all Polygon PoS nodes.
- Heimdall v0.11.0 is required for validators and full nodes.
Polygon further stated that both upgrades are already active on mainnet, meaning operators who haven’t updated need to act promptly to ensure their infrastructure remains compatible with the post-fork network rules.
Why this matters for PoS operators and users
Hard forks can feel disruptive even when they’re planned, but this disclosure underscores a different dimension of PoS security: availability and resource pressure are not theoretical. Heimdall’s described transaction-based forcing of excessive validator work highlights how adversaries can sometimes target compute limits rather than attempting to directly rewrite or steal consensus control.
Similarly, Bor DoS risks—ranging from block processing slowdowns to potential node crashes—suggest that operational stability depends on more than just validator correctness. A network can degrade even if the core consensus mechanism remains intact, simply by overwhelming nodes with workload or triggering instability.
For end users, these incidents mostly affect the system indirectly through reliability: delays, degraded performance, or node downtime can reduce how smoothly transactions propagate and are confirmed. For validators and infrastructure providers, the key takeaway is more immediate: compatibility after hard fork activation is mandatory, and the disclosed issues increase the importance of keeping client software current.
Token performance remains separate from the engineering update
At the time of writing, Polygon’s native token, POL—formerly known as MATIC—was trading around $0.10, down about 4% over the past week but up 44% over the past month and 2.3% year to date, based on CoinGecko data.
Readers should watch next for validator/operator confirmations that post-fork upgrades are stable across the network—especially because Polygon’s disclosure emphasizes resource exhaustion and processing-path bugs that, even if not exploited, are the kinds of issues that can surface as infrastructure strain under load.






