Polygon Crypto deployed two coordinated arduous forks, Austin on Bor v2.10.0 and Kyoto on Heimdall v0.11.0, to shut denial-of-service, resource-exhaustion and consensus-hardening dangers throughout its Polygon PoS consumer stack. Each upgrades had been rolled out privately and validated on the Amoy testnet earlier than mainnet activation, based on a Polygon discussion board publish printed August 27.
No mainnet disruption was noticed from the vulnerabilities Austin addressed, and each forks had been already lively on Amoy and mainnet by the point the disclosure went public.

The sequencing issues: Polygon fastened the problems, confirmed the fleet was secure, then defined what had been damaged – not the opposite method round.
Polygon Crypto: What Austin and Kyoto Truly Mounted
Austin closed two Bor block-processing DoS paths. State-sync occasions, which deal with L1-to-L2 bridge deposits, execute contract code and precompiles identical to atypical transactions, however their fuel consumption beforehand wasn’t metered in opposition to a tough per-block cap.
A block carrying sufficient state-sync occasions, or one particularly costly one, may make processing gradual sufficient to transiently stall the chain. Austin added an specific per-block fuel certain to shut that hole.
The second Austin repair eliminated Bor’s TxDependency wire area totally. The sphere was a parallel-execution trace with no measurement restrict, that means a block producer may stuff an arbitrarily giant blob into an in any other case legitimate sibling block and crash any peer that attempted to course of it.
Polygon Labs patched a batch of safety flaws in its PoS community by way of two non-public arduous forks, Austin on Bor and Kyoto on Heimdall, earlier than disclosing them publicly. The necessary element is the working mannequin: consensus-affecting fixes had been rolled out quietly, validated on the… pic.twitter.com/Sezi5VENW0
— TheFrogMaxi
(@thefrogmaxi) August 31, 2026
Since parallel execution doesn’t want friends to belief a producer’s trace to perform appropriately, eradicating the sector price nothing downstream.
Kyoto’s most extreme repair focused deeply nested google.protobuf.Any fields in Heimdall transactions. With out a cap, a single cheaply-crafted transaction may power each validator to carry out disproportionately costly decode work concurrently, a permissionless strategy to impose pricey, correlated load throughout all the validator set.
Kyoto added a byte-level pre-scan enforced identically at mempool admission and on the consensus path, so a transaction can’t slip by way of one test and get rejected by the opposite.
Kyoto additionally bundled smaller hardening fixes: a cap on fee-coin counts, normalized checkpoint signature restoration bytes, idempotent dealing with of repeated producer-downtime messages, milestone vary votes certain to the signed father or mother hash, checkpoint-window continuity checks, non-halting future-span creation, and injective replay keys for topup, clerk and stake L1 occasions.
All of it’s inert beneath the fork top – regular visitors sees no behavioral change. That form of layered validation hardening echoes broader business efforts to shore up transaction-processing edge circumstances earlier than they’re exploited, comparable in spirit to protocol-level modifications aimed toward rising transaction-security threats elsewhere within the business.
Make Your Prediction Rely With $25 For Free on Kalshi
Why Bor and Heimdall Each Wanted Patching
Austin activated at Amoy block 44,120,000 and mainnet block 91,949,700. Kyoto activated at Amoy top 42,252,000 and mainnet top 51,533,000.
Bor handles block execution whereas Heimdall runs consensus, and Kyoto’s fixes span ABCI, milestone, bor, stake, topup, clerk and bridge processing, that means the patch touched checkpoint finality, milestone accounting and L1-event replay logic abruptly.
Bor v2.10.0 is necessary for all nodes; Heimdall v0.11.0 is necessary for all validators and full nodes. Each are plain binary upgrades with no state migration or genesis change required for operators already present.
Enormous applause to the @0xPolygonLabs safety workforce
Quietly patched DoS flaws by way of the Austin & Kyoto arduous forks—zero downtime, zero exploits, zero consumer affect.
That is how battle-tested infrastructure operates. Safety first, noise later.$POL #Polygon https://t.co/jIESwxvLxC
— Delli Babu | $POL
![]()
(@DelliBabu_POL) August 30, 2026
That’s a definite case from nodes nonetheless operating pre-fork binaries previous the activation heights: these have already forked off canonical consensus and must improve and roll again to resync, reasonably than merely updating in place.
Coordinated consumer upgrades of this type carry actual operational stakes for any high-throughput chain, a dynamic enjoying out elsewhere as networks weigh state progress and execution danger in opposition to improve cadence, see the continuing debate round Ethereum’s Glamsterdam improve path.
For Polygon PoS, the takeaway is simple: the vulnerabilities had been resource-exhaustion and consensus-edge-case dangers, not correctness failures, and each had been resolved earlier than any exploitation was noticed on mainnet.
The Finest Merchants Round Use It: AI Copy Buying and selling Bots From CryptoHopper
The publish Polygon Crypto Secures Bor and Heimdall Shoppers Earlier than Disclosure appeared first on Cryptonews.
(@thefrogmaxi) August 31, 2026
$POL #Polygon https://t.co/jIESwxvLxC
(@DelliBabu_POL) August 30, 2026