Polygon has disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake network, after deploying fixes through two recent hard forks.
The vulnerabilities affected Polygon’s Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion and flaws affecting checkpoint and milestone processing, according to a Thursday disclosure from Polygon Labs’ Validators Support Team.
Polygon said the flaws were fixed through the Austin and Kyoto hard forks, which were deployed privately and tested before being activated on mainnet and publicly disclosed.
The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. The Austin hard fork separately addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to…