News Report Technology
August 31, 2026

Polygon Discloses Unreported PoS Vulnerabilities Patched Via Austin And Kyoto Hard Forks, Mandates Client Updates

Polygon Discloses Unreported PoS Vulnerabilities Patched Via Austin And Kyoto Hard Forks, Mandates Client Updates

Polygon Labs has issued an urgent notice requiring all Polygon PoS node operators to upgrade their Bor and Heimdall clients following the activation of the Austin and Kyoto hard forks. 

The company disclosed that several previously unreported security vulnerabilities have been patched through these coordinated upgrades, stressing that nodes still running pre-fork software have already deviated from canonical consensus and must catch up to rejoin the network’s accepted history.

Austin activated on the mainnet at block 91,949,700 and requires Bor version 2.10.0 or later, while Kyoto activated at block height 51,533,000 and requires Heimdall version 0.11.0. The Kyoto mainnet fork went live on 18 August 2026 at 10:10:31 UTC, with both hard forks already active on the Amoy testnet at earlier block heights. Polygon emphasized that these are plain binary upgrades requiring no state migration or genesis changes. 

However, operators who passed the activation thresholds on outdated clients have fallen out of consensus and must install the applicable release, roll back to a pre-hardfork point if necessary, and resync under official guidance to follow the canonical chain again.

Security Fixes and Network Hardening

The disclosed vulnerabilities affected Polygon’s execution and consensus layers separately. The Austin hard fork on Bor addressed two denial-of-service vectors in block processing: an unbounded gas consumption path during state-sync events from L1-to-L2 bridge deposits, and an unrestricted TxDependency extra-data field that could crash peers processing oversized blocks. 

Since state-sync events execute contract code without a fixed block-level ceiling, sufficiently costly events could slow processing enough to transiently stall the chain. Austin resolved this by imposing a per-block gas limit on state-sync operations and removing the unbounded TxDependency field from the wire format entirely.

Kyoto introduced consensus-hardening measures across Heimdall’s transaction and checkpointing logic. The most severe fix limits the nesting depth of google.protobuf.Any messages, preventing malicious actors from constructing cheap transactions that force validators into expensive decode work. 

Additional patches cap fee-coin counts before validation scans, normalize checkpoint signature recovery bytes to prevent anchoring failures on Ethereum, and harden milestone voting, producer-downtime handling, and L1-event replay key uniqueness. Polygon confirmed that none of the vulnerabilities were exploited on mainnet, and the fixes were privately validated on Amoy before public deployment to ensure fleet safety.

All node operators must treat the upgrades as mandatory. Bor serves as Polygon PoS’s execution client, while Heimdall manages consensus and checkpointing; maintaining current versions on both is essential for network compatibility and continued participation.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

More articles
Alisa Davidson
Alisa Davidson

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

Shufti, Jumio, Sumsub, And Beyond: Top 6 Identity Verification And Compliance Platforms To Know In 2026

Shufti, Sumsub, Incode, Veriff, Persona and Jumio compared on compliance lifecycle coverage, pricing transparency and fraud detection ...

Know More

2026 AI Market Claims Vs SEC Fillings: Linkmate Analysis

Is the AI market really all just PR talk or there's a deeper math going on in ...

Know More
Read More
Read more
Gate Update: CoinGecko Confirms Liquidity Lead as Gate Launches Stock Event Contracts and Deepens Multi-Asset Infrastructure
Digest News Report Technology
Gate Update: CoinGecko Confirms Liquidity Lead as Gate Launches Stock Event Contracts and Deepens Multi-Asset Infrastructure
September 18, 2026
Algorithmic Trading For Every Level: Arcanum’s Mikhail Ivanov On The Platform’s New Terminal, Institutional Milestones, And A Third Algorithm Coming This Fall
Interview Business Technology
Algorithmic Trading For Every Level: Arcanum’s Mikhail Ivanov On The Platform’s New Terminal, Institutional Milestones, And A Third Algorithm Coming This Fall
September 18, 2026
Bankr Enables Crypto Wallets And Onchain Financial Activity For Muse Agents
News Report Technology
Bankr Enables Crypto Wallets And Onchain Financial Activity For Muse Agents
September 18, 2026
From Institutional Finance To Agentic AI: Inside The Lineup For HSC Conference Seoul 2026
Hack Seasons Business Lifestyle Markets News Report Technology
From Institutional Finance To Agentic AI: Inside The Lineup For HSC Conference Seoul 2026
September 18, 2026