Polygon Reveals Security Flaws Only After Hard Forks Fixed Them
- Polygon disclosed vulnerabilities affecting both Bor and Heimdall after deploying the fixes.
- Austin closed two denial-of-service paths in Polygon PoS block processing.
- Kyoto addressed a broader set of consensus and input-validation weaknesses.
- Outdated nodes are already outside canonical consensus and must upgrade.
Polygon Labs has disclosed previously private vulnerabilities in its Proof-of-Stake network after fixes were already deployed through the Austin and Kyoto hard forks. The issues ranged from denial-of-service paths in the Bor execution client to a crafted-transaction attack capable of forcing costly processing across Heimdall validators. Polygon said it observed no exploitation on mainnet.
More notable than the disclosure itself is its timing. Polygon deliberately withheld technical details while patches were privately distributed and tested, reducing the period in which attackers could study a known vulnerability while validators remained exposed.
Polygon Patched First and Disclosed Later
Consensus vulnerabilities create a difficult disclosure problem.
โฆ Continue reading the full article at the original source below.



