Key Takeaways:
- Austin hard fork fixed two denial-of-service risks in the Bor client.
- Kyoto hard fork closed a Heimdall flaw that could overload validator processing.
- No mainnet exploitation observed; nodes must run Bor v2.10.0 and Heimdall v0.11.0.
Key Takeaways:

Polygon disclosed security flaws patched through the Austin and Kyoto hard forks, requiring Bor v2.10.0 and Heimdall v0.11.0 for all PoS nodes.
Polygon Labs' Validators Support Team detailed the fixes in a Thursday post on the project's governance forum, saying none of the vulnerabilities were observed exploited on mainnet.
The Austin fork addressed two denial-of-service risks in the Bor execution client that could slow block processing or crash nodes. The Kyoto fork closed a more severe Heimdall flaw where a crafted transaction could force validators into burdensome processing, risking network disruption. Independent researcher Nathan Worsley was involved in identifying the issues, and a $2.2 million bounty was tied to a missing balance check that could have allowed value to move without corresponding funds.
Nodes running older client versions past the activation heights have fallen out of consensus and must upgrade to rejoin the canonical chain. POL traded near $0.10, down about 4 percent over the past week but up 44 percent over the past month and 2.3 percent year to date, according to CoinGecko data.
The Austin hard fork, activated on Aug. 29, 2026, closed two denial-of-service vectors in Bor, the client responsible for block production on Polygon's proof-of-stake network. Polygon said the flaws could have degraded block processing or caused nodes to crash, depending on how an attacker triggered the problematic behavior. The fixes were deployed before technical details were released publicly, a responsible-disclosure pattern that narrows the window in which a published flaw could be weaponized.
The more severe issue sat in Heimdall, the consensus-layer client. A specially crafted transaction could have pushed validators into an excessive processing path, creating a network reliability risk because consensus participants must complete duties within strict performance limits. The Kyoto hard fork, corresponding to the Heimdall v0.11.0 release, resolved that vector. Polygon also flagged bugs tied to checkpoint and milestone processing, components that keep state advancing consistently across epochs.
Polygon requires Bor v2.10.0 for all PoS nodes and Heimdall v0.11.0 for validators and full nodes, both already active on mainnet after testing on the Amoy testnet. The chain hosts assets including PayPal's PYUSD stablecoin, raising the stakes for keeping node software current. For ordinary users, no action is required once validators adopt the patched software, since the change lives in the node layer rather than in wallets or approvals.
The disclosure reopens a familiar tension around Polygon's security practices: prompt remediation on one hand, delayed public detail on the other. Users transacting during the exposure window could not weigh a risk they did not know existed. The open question is follow-through — a hard fork only closes a hole once a supermajority of validators run the patched client, making the upgrade as much a test of Polygon's coordination as of its code.
This article is for informational purposes only and does not constitute investment advice.