Polygon Labs has disclosed that it patched multiple security vulnerabilities in its proof-of-stake network through two hard forks: Austin on the Bor client and Kyoto on the Heimdall client.
The upgrades were deployed privately and validated on Polygon’s Amoy testnet before being activated on mainnet. Polygon said the approach followed its standard procedure for consensus-affecting security fixes: implement the changes quietly, confirm network stability, and disclose the vulnerabilities after the network was protected.
Polygon hard forks address denial-of-service vulnerabilities
The Austin hard fork fixed two denial-of-service vulnerabilities in block processing. One flaw could have allowed a malicious block producer to crash peer nodes by filling a block with an oversized data field.
The Kyoto hard fork addressed a broader group of consensus-hardening issues. The most serious vulnerability could have allowed an attacker to trigger costly, coordinated processing across the entire validator set with a single crafted transaction that was inexpensive to create but expensive for the network to process.
Polygon said it found no evidence that any of the vulnerabilities had been exploited on mainnet and that the issues were resolved proactively. Both upgrades are now mandatory for node operators and are active across the network. The hard forks do not require a state migration or node resynchronization.
POL price remains under pressure
The security disclosures come during a pivotal period for Polygon, which has completed the migration from its legacy MATIC token to POL as part of a broader overhaul of its network architecture.
The news did little to support the price of POL. The token was trading at approximately $0.09983 on Sunday, down 2.3% over 24 hours and 6.8% over the past week, according to CoinGecko.
POL has fallen about 60.8% over the past year. Its market capitalization stood near $1.07 billion despite gains over the past month.

