Polygon discloses security flaws fixed in Austin and Kyoto hard forks

1 hour ago 1



Polygon Labs has disclosed a pair of security vulnerabilities that were quietly patched across two hard forks before the network said anything publicly. The fixes landed in the Austin and Kyoto upgrades, which activated on the Polygon proof-of-stake mainnet on August 29, with a community forum post describing the technical details following two days earlier. What was actually broken The Austin hard fork upgraded the Bor execution client to v2.10.0, activating at mainnet block 91,949,700. Kyoto upgraded the Heimdall consensus client to v0.11.0, activating at block height 51,533,000. On the Bor side, two categories of problems needed addressing. First, L1-to-L2 state-sync events were effectively un-metered, meaning they could consume block resources without the gas accounting that normally limits runaway computation. The Austin fork introduced per-block gas bounds to cap that exposure. The second Bor issue involved unbounded TxDependency data, a structure Bor uses internally to track transaction ordering. Without limits on how large that structure could grow, a crafted input could stall block processing or crash connected peers entirely. Heimdall’s problems were different in characte...

Read Entire Article