CASABLANCA, August 31, 2026
Polygon has disclosed a batch of security and liveness flaws in the clients that run its proof-of-stake chain after quietly fixing them through two hard forks, warning that nodes on older software are no longer on the canonical network.
The Aug. 27 disclosure says the Austin hard fork on Bor v2.10.0 and the Kyoto hard fork on Heimdall v0.11.0 were first deployed privately, tested on the Amoy testnet and activated on mainnet before their details were made public. Polygon said it did not observe any of the flaws being exploited on mainnet.
The most serious issue, according to Polygon, could have let one specially crafted transaction force costly, correlated decoding work across the validator set. Separate Austin fixes addressed block-processing paths that could have temporarily stalled the chain or crashed peers.
That makes this a successful patch-and-disclose event, not a confirmed theft. Polygon reported no stolen assets, affected wallets, attack transactions or user-fund losses as of its latest review. The practical risk now is for operators that missed the upgrades.
POL traded near $0.094 when checked Aug. 31, up about 32% from a month earlier, according to CoinGecko market data. The Crypto Fear and Greed Index stood at 62, or Greed, as the disclosure reached a market already focused on infrastructure resilience.
POL
POLPolygon Discloses Austin and Kyoto Security Fixes
In its technical release review, Polygon said Austin closed two denial-of-service paths in Bor, the execution client for Polygon PoS.
One fix puts a hard per-block limit on the gas consumed by state-sync events—operations used for L1-to-L2 bridge deposits. Before the change, enough expensive events in one block could have consumed sufficient processing time to transiently stall the chain, Polygon said.
Austin also removed Bor’s TxDependency wire field. A malicious block producer could have inserted an arbitrarily large blob in that field, causing peers that processed an otherwise valid sibling block to crash. Polygon says parallel execution does not depend on trusting that producer-provided hint, so the field could be removed without changing downstream behavior.
Kyoto’s broader set of changes focuses on Heimdall, Polygon PoS’s consensus and validator layer. Its key protection caps the nesting depth of google.protobuf.Any messages. Without that limit, Polygon said an attacker could make a cheap transaction that forces every validator to perform substantial decode work. The updated software rejects overly nested input consistently in the mempool and consensus paths.
The package also caps fee-coin lists and hardens checkpoint signatures, milestone-range votes and replay protection for several L1 event types. These are liveness and validation protections, not a change to POL supply or an upgrade to an application contract.
No Exploit or Onchain Loss Was Reported
Polygon’s own assessment is unusually specific on the point that matters most to holders and users: neither Austin’s block-processing vectors nor Kyoto’s validator-resource issue was observed causing a mainnet disruption before the patches were activated.
The company did not publish attacker addresses, theft totals, victim counts, affected-wallet counts or a recovery plan because it did not identify a live exploit. That separates the news from the recent Cosmos EVM incident, where a post-mortem described an estimated $5.72 million drained across six networks.
It also differs from a chain outage after an active exploit, such as MANTRA’s halt after an EVM-module attack. Polygon’s report describes vulnerabilities that were fixed before a reported attack, not a retrospective explanation of missing funds.
That distinction does not make the disclosure trivial. A denial-of-service path can interrupt transaction confirmation, bridge operations and application availability even without enabling an attacker to take custody of tokens. But it does mean readers should not treat the bug descriptions, which were published after activation, as proof that funds were compromised.
Polygon Nodes Must Upgrade to Rejoin Canonical Chain
For infrastructure operators, the response is not optional. Polygon says Bor v2.10.0 is mandatory for all Polygon PoS nodes, while Heimdall v0.11.0 is mandatory for validators and full nodes. Both are already active on mainnet.
The release review says an operator that continues past the activation heights on earlier software has already forked away from the canonical chain and needs to upgrade and catch up. The stated upgrade path is a binary update; Polygon says no state migration or full resynchronization is required for normally updated operators.
That operational message is the reason the story has a wider audience than a conventional technical changelog. A public RPC provider, exchange, bridge operator or validator on stale software may show an outdated chain view or fail to participate correctly until it moves to the required versions.
Polygon later posted Bor v2.10.1 for Amoy and mainnet, reinforcing that operators should follow the project’s current release channel rather than stop at the original disclosure. Users do not ordinarily need to run those clients themselves, but they should expect providers to complete the maintenance promptly.
The Fear and Greed Index was 62, or Greed, on Aug. 31.
Fear & Greed Index
Aug. 31, 2026Polygon’s disclosure offers a straightforward takeaway: the chain says it fixed a potentially disruptive set of client flaws before they were exploited, but the protection only applies to operators that have moved onto the active Bor and Heimdall releases.
Stay up to date
Get the latest crypto insights delivered to your inbox
Primary sources and further reading
| Source | Title |
|---|---|
| | Polygon Community Forum: Austin and Kyoto security releases review |
| | Polygon Community Forum: Bor v2.10.1 for Amoy and Mainnet |
| | CoinGecko: POL market data |
| | Alternative.me: Crypto Fear and Greed Index |
Fact-checked by: Daily Crypto Briefs Fact-Check Desk
Related Articles
Frequently Asked Questions
Did Polygon suffer a hack or lose user funds?
Polygon said none of the disclosed Austin and Kyoto flaws were observed being exploited on mainnet. It did not report theft, onchain loss, affected wallets or user-fund losses in its security review.
Which Polygon software versions are now required?
Polygon says Bor v2.10.0 is mandatory for all Polygon PoS nodes, while Heimdall v0.11.0 is mandatory for validators and full nodes. Operators on earlier versions must upgrade and catch up to the canonical chain.
What did the Polygon Kyoto hard fork fix?
Kyoto added a limit on deeply nested protobuf Any messages, capped fee-coin lists and hardened checkpoint, milestone and L1-event processing. Polygon identified the nested-message issue as the most severe item in the batch.
Why were the Polygon flaws disclosed after the upgrades?
Polygon said it privately rolled out and validated the consensus-affecting fixes before making the details public, a process intended to reduce the chance that attackers could target nodes before the network was protected.



