Polygon Patches Security Flaws in Austin and Kyoto Hard Forks

By Bartek Hagan

(11 days ago)

2 min read

Share:

Polygon disclosed security vulnerabilities it fixed through two hard forks, Austin and Kyoto, deployed before public disclosure. The most severe flaw could have let one crafted transaction force costly work across every validator, but Polygon said no exploit hit mainnet.

Polygon Patches Security Flaws in Austin and Kyoto Hard Forks

Key facts

  • Polygon patched a batch of security flaws through two hard forks, Austin and Kyoto, before disclosing them.
  • The most severe flaw let a single crafted transaction force heavy work across the entire validator set.
  • Polygon said no flaw was exploited on mainnet, and the client upgrades are mandatory and already active.

Polygon patched flaws through two hard forks

Polygon disclosed on 27 August 2026 that it had fixed a batch of security vulnerabilities through two network upgrades. The Austin hard fork raised the Bor execution client to version 2.10.0. The Kyoto hard fork raised the Heimdall consensus client to version 0.11.0. Both upgrades were deployed privately and validated on the Amoy test network before mainnet activation. Polygon patched the weaknesses quietly, then released the technical details afterward.

A single transaction could overload every validator

The most severe flaw sat in Heimdall. A single crafted transaction with deeply nested data fields could force every validator to perform a large amount of decoding work at once. That surge of work could disrupt the network. The Kyoto fork also bundled several other consensus-hardening fixes, covering checkpoint signature handling, milestone voting, and duplicate downtime messages. The Austin fork separately closed two denial-of-service (DoS) risks in Bor. One flaw let bridge deposit events consume block resources without a limit. The other let a malicious block producer crash peer nodes by inserting an oversized data field into an otherwise valid block.

Polygon says no flaw reached mainnet

Polygon said none of the vulnerabilities were exploited on mainnet, and that all were resolved proactively before the details were made public. The upgrades are mandatory for node operators and already active on both the Amoy test network and mainnet. Validators and full-node operators both need the new client versions to stay in consensus. Nodes still running older software have forked off the canonical chain and must update to rejoin it. No state migration or resync is required.

POL trades near ten cents at publication

POL, the network's token, traded at $0.0951 at the time of publication, down 8.1% over the previous 24 hours (CoinPaprika, 31 August 2026). It had fallen 12.7% over the past seven days. Its market value stood near $1.01 billion. The token trades far below its March 2024 record high of $1.29. Trading volume over the prior 24 hours reached about $40 million.

Primary source: Source ↗

Cryptocurrencies are highly volatile and involve significant risk. You may lose part or all of your investment.

All information on Coinpaprika is provided for informational purposes only and does not constitute financial or investment advice. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions.

Coinpaprika is not liable for any losses resulting from the use of this information.

Share:
Go back to All News