Polygon shipped two hard forks before telling anyone what they fixed

Polygon Labs quietly released two hard forks that fixed a number of security issues in its proof-of-stake (POS) network.
The layer-2 network finally shared the details in a forum post. All node operators have to upgrade or they will be kicked out of the network consensus.
Austin fork stops nodes from sending the TxDependency field
The worst bug was in Heimdall, which is the software that coordinates Polygon validators.
Heimdall bundles the contents of each transaction inside a wrapper called, google.protobuf.Any, according to a forum post by Parvez03.
A wrapper can sit inside another, just like how boxes can be packed inside other boxes. However, in this analogy, thereโs no cap on how many layers deep wrappers could go.
An attacker could create a single transaction stacked with those layers for almost no cost. This makes validators waste computing power to unpack it.
Polygon described the flaw as โa permissionless way to force costly, correlated work across the whole validator set.โ
The Kyoto hard fork upgraded the Heimdall software to v0.11.0.
โฆ Continue reading the full article at the original source below.



