Polygon has disclosed a batch of previously secret security vulnerabilities that could have disrupted its entire proof-of-stake network — and revealed that it quietly fixed them first through two hard forks named Austin and Kyoto, according to a disclosure from Polygon Labs’ Validators Support Team reported by Cointelegraph.
By Diego Rivera | August 30, 2026
The Story: Fix First, Tell Later
The flaws sat in the two pieces of software that keep Polygon running: Bor, the client that produces blocks, and Heimdall, the component validators use to checkpoint the network’s state onto Ethereum. Think of them as the engine and the ledger-keeper of the Polygon machine.
According to the disclosure, the vulnerabilities included denial-of-service risks, validator resource exhaustion and flaws in checkpoint and milestone processing. In plain terms: an attacker could have crafted transactions that forced validators to do enormous amounts of unnecessary work, potentially slowing the network to a crawl or crashing nodes outright. The most severe issue, in Heimdall, could have let a single specially crafted transaction disrupt network operations.
Crucially, none of the flaws were ever exploited on mainnet. Polygon deployed the fixes privately, tested them, and only went public once the upgrades were already live — the standard “responsible disclosure” playbook that security teams use so attackers never get a head start.
The Catch: Upgrade or Get Left Behind
Here is the part that matters to anyone running Polygon infrastructure. The Austin and Kyoto hard forks are already active on mainnet, and nodes still running old versions of Bor or Heimdall have fallen out of consensus — meaning they are now following the wrong version of the network and must upgrade to rejoin. Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes.
- Bor v2.10.0 — mandatory for all Polygon PoS nodes.
- Heimdall v0.11.0 — mandatory for validators and full nodes.
- Both upgrades — already live on mainnet.
What About the POL Price?
Ordinary holders had a reasonable question this week: is my money safe? The market’s answer was a shrug. POL, Polygon’s native token (the renamed MATIC), was trading around 0.10 USD at the time of the disclosure, down about 4 percent over the week but up roughly 44 percent over the past month, according to CoinGecko data cited by Cointelegraph.
That reaction makes sense. Security flaws that were patched before anyone could exploit them are a non-event for token holders — the drama already happened in private, and the fix shipped before the announcement. If anything, a clean coordinated disclosure is a sign of a mature security process, not a red flag.
Why This Keeps Happening
Polygon is far from alone. This has been a brutal stretch for cross-chain and infrastructure security: The Sandbox just pledged 1:1 repayments after a 700,000 USD bridge exploit, and a CoinGecko report this month counted billions in losses across the industry this year. The difference between those stories and Polygon’s is timing — Polygon’s flaws died quietly in a hard fork instead of exploding in a hack.
For a network that still anchors a large chunk of decentralized application activity, that discipline matters beyond Polygon itself. Enterprise partners and institutions eyeing tokenization projects tend to ask one question before anything else: who is watching the plumbing? A published, audited-style security review with named fixes — tied to a public forum post anyone can read — is the kind of paper trail that makes procurement officers comfortable. It turns an uncomfortable admission into evidence of competence.
It is also a reminder of what hard forks actually are: routine network upgrades, not emergencies. The names change — Austin and Kyoto this time — but the pattern of “patch privately, activate, disclose” is how well-run chains stay ahead of attackers.
The Verdict
For regular investors, there is nothing to do here — no action needed, no funds at risk, no panic warranted. If you run a node or validator, update your software or you will silently drift off the network. For everyone else, file this one under quiet good news: a major chain caught its own bugs before the bad guys did, and the market barely noticed, which is exactly how it should work.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
quietly patching critical bugs via hard forks named austin and kyoto and only telling us months later. imagine if an attacker found one before the validators did, POL woulda been toast
That is the standard playbook though. You patch first, then disclose, otherwise you hand attackers a roadmap. Better than the projects that only tell us after the exploit drains the bridge.
patch first is right but there is a middle ground. coordinated disclosure within weeks, not months where only validators knew bor and heimdall were exposed
from what the post says the heimdall flaw needed a majority of validators anyway, so the attack cost was probably way above the payout. still too close for comfort
naming coordinated hard forks austin and kyoto is very punk rock of polygon. quiet fix, then the disclosure drop
@forkwatch POL holders found out from a blog post that the network they stake on nearly had critical bugs. wild tbh
Fix first, announce later is the correct order. Bor and Heimdall flaws could have been a bridge drain headline instead.
so validators knew for months while the rest of us found out from a cointelegraph article. love that for us
ran a bor node through both forks, zero downtime, credit where its due. but yeah finding out austin and kyoto were bug fixes months after the fact is the part that needs a better policy