Two batches of Polygon PoS security flaws affecting both the Bor execution client and Heimdall consensus client have been publicly disclosed, weeks after patches were silently deployed via back-to-back hard forks. No exploits hit mainnet, but the severity of the Heimdall issue in particular made the coordinated disclosure approach the less uncomfortable option.
What the Polygon PoS Security Flaws Actually Did
The worst of the vulnerabilities sat in Heimdall: a specially crafted transaction could force validators into excessive processing work, a classic resource-exhaustion vector that, at scale, could have disrupted checkpoint and milestone processing across the network.
The Austin hard fork addressed two separate denial-of-service risks in the Bor client. According to CryptoSlate, one involved an oversized TxDependency field in Bor’s wire format: a producer broadcasting that field could terminate peers receiving the data. Austin removed the field entirely rather than sanitising it. Polygon classified both Austin-related weaknesses as resource-exhaustion risks.
The Kyoto hard fork handled the Heimdall side. The official Polygon community forum post confirms the Kyoto Amoy testnet activation height was 42,252,000 and the mainnet activation height was 51,533,000. All Kyoto-gated behaviour is inert below that height, so nodes that upgraded before the fork carried no partial-state risk.
Sequencing: Testnet First, Disclosure After Activation
Both hard forks were validated on the Amoy testnet before touching mainnet, and public community-forum disclosure was timed to follow successful mainnet activation, according to Crypto Briefing. The Austin hard fork activated at Bor block 91,949,700; Kyoto activated at Heimdall height 51,533,000 on 18 August 2026 at 10:10:31 UTC.
The sequencing matters. Disclosing vulnerability specifics before the patch is live creates a race: any validator or node operator who reads the write-up before upgrading hands potential attackers a roadmap. Polygon’s approach inverted that window.
Nodes still running pre-fork versions have already dropped out of consensus and cannot rejoin the canonical chain without upgrading. The minimum required versions are Bor v2.10.0 for all PoS nodes and Heimdall v0.11.0 for validators and full nodes, per Polygon’s validator documentation. As of 28 August, the Bor GitHub releases page listed v2.10.1 as the most current build; v2.10.0 or later satisfies the Austin compatibility requirement.
One operational wrinkle for node runners: Docker Hub image publishing for Bor has been removed ahead of a 1 September 2026 sunset. Operators pulling images need to switch to the GitHub Container Registry (GHCR) instead. The Heimdall-v2 releases page covers the v0.11.0 changelog for anyone auditing what changed on the consensus side.
Austin and Kyoto are not isolated patches dropped into an otherwise quiet upgrade cycle. Crypto Briefing notes that Polygon also activated the Ithaca hard fork in July 2026, which targeted liveness improvements and payment reliability. Three hard forks in roughly two months on a PoS network with live validator economics is a pace that warrants attention from anyone tracking the chain’s upgrade cadence.
POL, the native token formerly known as MATIC, was trading around $0.10 at time of writing, off roughly 4% over the prior week but up 44% over the past month and 2.3% year to date, per CoinGecko data.
The immediate question for validators is straightforward: confirm your client versions, switch your image source to GHCR before 1 September, and monitor the forum thread for any follow-on patch notes. The broader question, as Polygon’s upgrade pace accelerates, is whether that rhythm reflects a maturing security posture or a backlog catching up with itself.
