Polygon Reveals Security Vulnerabilities Resolved Through Recent Network Upgrades

Polygon Reveals Security Vulnerabilities Resolved Through Recent Network Upgrades

The security weaknesses presented denial-of-service threats and validator resource challenges but received patches prior to Polygon's public announcement of their existence.

Polygon has made public several security weaknesses that were previously kept confidential, which had the potential to cause significant disruptions to its proof-of-stake blockchain network, following the implementation of remedial measures via two hard forks executed in recent months.

The security weaknesses impacted both the Bor and Heimdall client software used by Polygon and encompassed risks related to denial-of-service attacks, exhaustion of validator computational resources, and issues that affected the processing of checkpoints and milestones, based on information shared Thursday by the Validators Support Team at Polygon Labs.

According to Polygon, the security issues received their remedies via the Austin and Kyoto network hard forks, both of which underwent private deployment and comprehensive testing phases prior to their activation on the mainnet and subsequent public disclosure of the vulnerability details.

The vulnerability carrying the greatest severity was found in Heimdall, where an attacker using a specifically engineered transaction could compel validators to execute an excessive amount of computational processing tasks, which carried the potential to cause widespread network disruption. Additionally, the Austin hard fork resolved a pair of denial-of-service vulnerability risks present in Bor that possessed the capability to degrade block processing speeds or trigger complete node failures and crashes.

According to Polygon's statement, none of these security vulnerabilities showed any evidence of active exploitation on the mainnet environment, and the organization emphasized that all protective fixes were rolled out in a proactive manner prior to making any vulnerability information available to the public.

Any nodes that continue operating older versions of either the Bor or Heimdall client software beyond the designated hard fork activation block heights have already experienced consensus failures and dropped off the network, requiring immediate upgrades to successfully reconnect with the canonical blockchain, as stated in the official disclosure. The Bor v2.10.0 software version is now mandatory for every Polygon PoS network node, while Heimdall v0.11.0 represents a required upgrade for all validator nodes and full nodes, with both of these software updates having already been activated and running on the mainnet infrastructure.

POL, which serves as Polygon's native cryptocurrency token and was previously identified by the ticker symbol MATIC, was experiencing trading activity around the $0.10 price level at the time of writing, reflecting approximately a 4% decline over the preceding seven-day period but demonstrating a 44% increase over the past month and showing a 2.3% gain year to date, based on market data provided by CoinGecko.

← Back to Blog