Polygon Labs, the developer behind the Polygon proof-of-stake (PoS) blockchain, has released two critical hard forks to address significant security vulnerabilities found in its network. The company disclosed details about these upgrades—which include the Austin and Kyoto forks—in a newly published forum post, and called on all node operators to update their software or risk being removed from the network consensus.
Polygon upgrades network with Austin and Kyoto hard forks, patches critical security bugs
Kyoto fork strengthens validator security
The most severe flaw was discovered in Heimdall, which is the coordination software used by Polygon validators. Heimdall is responsible for organizing validator activity to secure the network. The vulnerability stemmed from how Heimdall handled transaction data, placing each transaction inside a wrapper called google.protobuf.Any.
This structure allowed attackers to stack multiple nested wrappers inside a single transaction, causing validators to expend excessive computing power to unpack the transaction with little cost to the attacker. Polygon Labs called it “a permissionless way to force costly, correlated work across the whole validator set.”
The Kyoto hard fork upgraded Heimdall to version 0.11.0 and implemented a byte-level pre-scan mechanism that rejects any transaction exceeding a set nesting threshold. This filter is enforced both when transactions enter the mempool and during block proposal, ensuring that only valid transactions are processed efficiently.
Kyoto adds a byte-level pre-scan that rejects a transaction once its nesting passes a threshold, enforced identically at mempool admission (CheckTx) and on the consensus path (ProcessProposal).
Polygon’s dual checks occur both when a transaction arrives and when validators assemble a new block to confirm.
Mini dictionary: Heimdall is Polygon’s validator orchestration software, essential for coordinating consensus and security in the network’s PoS framework.
Austin fork targets Denial-of-Service risks
The Austin hard fork addressed two denial-of-service vulnerabilities in Bor, Polygon’s transaction execution client. One risk was related to “state-sync events,” which are responsible for processing deposits from Ethereum (Layer 1) to Polygon (Layer 2). These events could have executed unlimited contract code and precompiles per block, as there was previously no cap on gas usage per block.
To prevent this, the Austin fork introduced a strict per-block gas limit on state-sync events.
Another vulnerability involved the TxDependency field, which lacked a maximum size limit. A malicious validator could fill this field with excessive data, potentially crashing every node that tried to process the affected block. The Austin upgrade eliminates the TxDependency field from the communication format entirely, closing off this attack vector.
| Kyoto | Heimdall (validator coordination) | Nesting limit for transaction wrappers | 0.11.0 | Heimdall height 51,533,000 |
| Austin | Bor (transaction execution) | State-sync block gas cap, TxDependency field removal | 2.10.0 | Bor block 91,949,700 |
Network health and node upgrade requirements
Polygon Labs confirmed that, to the best of its knowledge, none of the security issues were exploited on the mainnet before the upgrades were activated. The required software versions are Bor v2.10.0 for all nodes and Heimdall v0.11.0 for validators and full nodes. Any node running old software has already been separated from the main Polygon chain.
These updates are simple binary upgrades, meaning operators do not need to conduct state migrations, change the genesis file, or perform full resynchronizations.
POL, the token for the Polygon ecosystem, traded at $0.09, falling 9.3% in the past 24 hours. However, its price remained stronger over the 30-day period, rising 25.8% based on CoinGecko data.
Polygon previously experienced a mainnet outage in July, when Heimdall V2 went offline for approximately one hour. Polygon Labs continues to respond to such challenges and implement network improvements as needed.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
The “American Mining Dream” of Bitcoin Mining Firms Shattered! Miners Shift to AI Data Center Construction, Scarce Electricity Becomes Key to Valuation Reshaping
Due to the rapid development of artificial intelligence and the crash in cryptocurrencies, Donald Trump's plan to concentrate bitcoin mining activities in the United States is collapsing. Compared to October last year, the computing power consumed by bitcoin mining has decreased by 18%.

The "tax-free dividend" for data centers changes! Over ten US states reassess tax incentives, AI computing power expansion faces new obstacles
For AI computing power investment themes, policy changes primarily affect where to build, at what cost, and when investment returns can be realized. Ohio's data center incentives cover computing equipment, cooling systems, power equipment, and some building materials, so adjustments could impact the entire facility.

86% of S&P 500 Components Beat Earnings Expectations! AI Boom Fuels S&P 500 Profit Growth, Full-Year Growth Forecast Raised to 32%
The full-year profit expectations for the S&P 500 Index are rising, supported by the artificial intelligence boom and stronger-than-expected earnings performance in the first half of the year.

From daily leverage to hourly leverage! The lesson from South Korea is still fresh, Wall Street is once again testing even more extreme retail trading tools
Defiance ETFs has filed documents with the U.S. Securities and Exchange Commission (SEC), planning to launch a series of leveraged funds that aim to double the gains or losses of certain individual stocks—not on a daily basis, but calculated hourly.

