Polygon has rolled out two coordinated hard forks to strengthen the security of its proof-of-stake network, addressing several vulnerabilities that could have been used to disrupt nodes or force validators to perform expensive processing.
The fixes were introduced through the Austin and Kyoto hard forks before Polygon publicly disclosed the vulnerabilities. One of the most serious issues could have allowed an attacker to create a single transaction capable of forcing the network’s entire validator set to carry out substantial processing work.
Polygon’s Validators Support Team disclosed the security fixes in an Aug. 27 forum post, after the upgrades had already been tested and activated. The team said vulnerabilities affecting consensus were handled privately, tested on the Amoy testnet, and disclosed only after the mainnet infrastructure had been protected.
Importantly, Polygon said it found no evidence that any of the vulnerabilities had been exploited on mainnet.
Austin Fork Targets Block Processing Attacks
The first upgrade, the Austin hard fork, upgraded Polygon’s Bor execution client to version 2.10.0 and addressed two separate denial-of-service vulnerabilities.
The first issue involved state-sync events, which are used for Layer 1-to-Layer 2 bridge deposits. These events can execute contract code and precompiles, but previously there was no effective per-block gas limit controlling how much processing they could consume.
That created a potential avenue for exhausting network resources.
Austin introduced a limit on the amount of gas state-sync events can use within a block, reducing the possibility that attackers could overwhelm nodes through excessive processing.
The second vulnerability involved TxDependency data, which is processed when blocks are handled by nodes. A malicious block producer could provide an oversized data field, potentially triggering excessive memory allocation and causing peer nodes processing the block to crash.
Polygon classified both problems as block-processing denial-of-service vulnerabilities, rather than flaws that could directly compromise consensus correctness. The company said neither issue had caused any known disruption before the patches were deployed.
Kyoto Addresses a More Serious Validator Risk
The Kyoto hard fork focused on Heimdall, Polygon’s system responsible for validator coordination and other consensus-related functions. The upgrade moved Heimdall to version 0.11.0 and introduced several input-validation and consensus-hardening improvements.
The most serious vulnerability involved deeply nested google.protobuf.Any fields.
Heimdall transactions can contain messages wrapped inside Any fields, and those fields can themselves be nested. Without a limit on nesting depth, an attacker could construct a relatively inexpensive transaction containing extremely deep structures.
Processing that transaction could then force every validator to perform a large amount of decoding work.
Polygon said this created a permissionless attack path that could impose costly, coordinated processing across the validator set.
Kyoto addresses the issue by adding a byte-level scan that rejects transactions when nesting exceeds a defined threshold. The protection is applied at both the mempool admission stage and the consensus processing stage, helping ensure that a transaction cannot pass through one part of the system while being rejected by another.
The Kyoto upgrade also introduced fixes related to milestone accounting, checkpoint processing and the replay of Layer 1 events.
For example, failed future-span creation can now degrade and retry at the next boundary rather than blocking a milestone commit. New replay keys also address an edge case where different Layer 1 events could otherwise collide.
Older Polygon Nodes Have Already Fallen Out of Consensus
The Austin and Kyoto upgrades are now mandatory for operators who want to remain connected to Polygon’s canonical proof-of-stake network.
Polygon said Bor v2.10.0 is required for all nodes, while Heimdall v0.11.0 is required for validators and full nodes.
Operators that continued running versions released before the relevant activation heights have already forked away from canonical consensus. They must update their software to reconnect with the main Polygon chain.
The upgrades were delivered as binary software updates, meaning operators do not need to migrate their existing state, change the genesis configuration or perform a complete network resynchronization.
Nodes that have fallen out of consensus can update their software, roll back to the appropriate pre-hard-fork height and then catch up with the canonical chain.
Polygon Has Used Hard Forks Before
This is not the first time Polygon has relied on a hard fork to address problems affecting its proof-of-stake infrastructure.
In September 2025, Polygon carried out a hard fork after a software bug caused transaction finality delays of up to 15 minutes.
That incident affected validator synchronization and local fast finality, although block production and Ethereum checkpointing continued. Updates to Bor and Heimdall were deployed to restore milestone processing, state synchronization and consensus finalization.
A month later, Polygon introduced the Rio mainnet upgrade, which added witness-based stateless validation and a Validator-Elected Block Producer model as the network continued changing how transactions are processed and verified.
Network Performance Remains a Priority
Security has not been Polygon’s only focus. The network has also been working to increase performance as demand for blockchain transactions grows.
In May 2026, crypto.news reported that Polygon had reduced its average block time to 1.75 seconds, marking the first reduction in block time since the network launched.
Polygon software engineer Lucca Martins said the change increased theoretical throughput to approximately 3,260 transactions per second and allowed the network to process around 14% more payments per second.
The improvement was part of Polygon’s broader effort to handle higher transaction volumes driven by stablecoin payments and decentralized finance activity.
MATIC-to-POL Migration Also Completed
The latest security upgrades come after Polygon completed the transition from MATIC to POL, which is now the native gas and staking token for the Polygon PoS network.
The migration began in September 2024 under the Polygon 2.0 roadmap. MATIC held directly on Polygon PoS was converted into POL at a one-to-one ratio.
Under the original plan, POL was designed to serve as the network’s gas payment and staking token. Its potential utility was also expected to grow as Polygon developed its staking system and aggregated-chain architecture.
Polygon Labs has also undergone changes of its own.
In July, the company announced another round of job cuts while completing its integration of crypto exchange Coinme. Polygon Labs CEO Marc Boiron said the restructuring was intended to help the company reach profitability by 2027 as it increasingly moved toward a payments-focused business model.
POL Price Shows Little Reaction
Despite the disclosure of the security fixes, POL showed little positive reaction in the market.
The token was trading at approximately $0.09983 on Aug. 30, down around 2.3% over the previous 24 hours and 6.8% over the previous seven days, according to CoinGecko data included in the report.
POL remained about 60.8% below its price from a year earlier, with the token carrying a market capitalization of approximately $1.07 billion.
For Polygon, the latest hard forks highlight the continuing challenge of balancing security, scalability and network performance. As the blockchain handles more activity, protecting validators and preventing resource-heavy attacks remains just as important as increasing transaction speed.
Also read : Bitcoin Bounces Back as Weak U.S. Jobs Data Boosts Rate Cut Hopes
Bitcoin Reclaims $60K as Fed Chair Warsh Keeps Rate Plans Unclear