Polygon has disclosed several previously private security vulnerabilities affecting its proof-of-stake network clients, after deploying fixes through two hard forks that were tested and activated before any public announcement.
The disclosure, published by Polygon Labs' Validators Support Team on the project forum and covered by Cointelegraph and Decrypt, details vulnerabilities in the Bor and Heimdall clients, including denial-of-service risks, validator resource exhaustion and flaws in checkpoint and milestone processing.
The Most Severe Issue
The highest-severity finding involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. The fix shipped through the Kyoto hard fork, which rolled out Heimdall v0.11.0.
The Austin hard fork separately addressed two denial-of-service risks in Bor, the network's execution client, that could have slowed block processing or caused nodes to crash. Bor v2.10.0 is the required version for all Polygon PoS nodes.
Patch First, Disclose Later
Polygon said the fixes were deployed privately, tested, and activated on mainnet before details were made public — a coordinated-disclosure approach that left no window between public knowledge and available patches. According to the disclosure, none of the vulnerabilities were observed being exploited on mainnet.
The tradeoff is operational rather than cryptographic: node operators learned of the security releases only after the hard forks were already live, and nodes running older client versions past the activation heights have fallen out of consensus. Those operators must upgrade to rejoin the canonical network.
Why It Matters
Quiet hard forks are rare enough in the industry to be notable. Most vulnerability disclosures arrive with a patch, a window of exposure, and a race between operators and attackers. Polygon inverted the sequence — code first, explanation after — which eliminates the exploit window but requires the community to accept consensus changes introduced without prior public security review.
For validators and infrastructure operators, the episode is a reminder that client version currency is a security control in its own right. TrustGrade's registry tracks protocol security histories, including disclosure practices, as part of entity trust scoring.