Polygon PoS Discloses and Patches Bor and Heimdall Client Vulnerabilities
Polygon PoS fixed denial-of-service and validator exhaustion issues in Bor and Heimdall through the Austin and Kyoto hard forks with no reported exploitation.
Polygon PoS disclosed denial-of-service risks, validator resource exhaustion, and checkpoint or milestone flaws in its Bor and Heimdall clients.
The issues were resolved through the Austin and Kyoto hard forks after private testing and before public disclosure.
The most serious flaw allowed crafted transactions to force excessive validator processing on Heimdall.
The Austin fork also corrected two Bor denial-of-service vectors that could slow blocks or crash nodes.
No mainnet exploitation took place. Polygon Labs issued an upgrade notice for operators still running pre-fork node versions.
Unknowns
Exact counts of affected validators or users remain unstated. The interval between fork deployment and disclosure is not specified.