Polygon Operators Must Upgrade After Fixed Flaws Revealed
Polygon disclosed fixed security flaws in Bor and Heimdall, requiring node operators to upgrade while no mainnet exploitation was observed.
Polygon has disclosed several previously private security vulnerabilities affecting its proof-of-stake network, revealing the flaws only after deploying fixes through the Austin and Kyoto hard forks. The issues included denial-of-service risks and validator resource exhaustion, but Polygon said none were observed being exploited on mainnet.
What the disclosure covers
The vulnerabilities affected Polygon’s Bor and Heimdall clients, according to a Thursday disclosure from Polygon Labs’ Validators Support Team. The problems spanned denial-of-service risks, validator resource exhaustion, and flaws affecting checkpoint and milestone processing.
The most severe issue involved Heimdall, where a specially crafted transaction could have forced validators to perform excessive processing work, potentially disrupting the network. Separately, the Austin hard fork addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash.

Polygon said the fixes were deployed and tested privately before being activated on mainnet and disclosed publicly, a sequencing choice the team framed as proactive rather than reactive. That timeline matters: it means the vulnerabilities were closed before anyone outside the core team knew they existed, cutting off the window an attacker would have needed to exploit them.
The pattern echoes a broader theme playing out across the industry this year, where teams increasingly patch quietly and disclose after the fact rather than publishing vulnerability details before a fix is live. It’s a similar logic to how bridge and cross-chain infrastructure operators have handled incidents like the Coreum bridge exploit, where the sequencing of disclosure versus remediation shaped how much damage got done. Chainlink’s work with FRNT on stable token infrastructure has similarly leaned into pre-emptive security reviews as a baseline expectation rather than a response to failure.
What node operators need to know
The practical consequence for anyone running Polygon infrastructure is straightforward but non-negotiable: nodes running older versions of either client past the hard-fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network.
Bor v2.10.0 is now required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes. Both upgrades were already active on mainnet at the time of Polygon’s disclosure, meaning any operator still on the prior versions isn’t just behind on updates – they’re technically off the network’s canonical chain.
That kind of hard deadline isn’t unique to Polygon. Validator and node-operator coordination has become a recurring theme across proof-of-stake networks this year, with teams like Solana pushing infrastructure changes such as its move toward faster slot times that similarly demand operators stay current or risk falling out of sync with the rest of the network.
POL price context
POL, Polygon’s native token formerly known as MATIC, was trading around $0.10 at the time the disclosure was published. According to CoinGecko data cited in Polygon’s original reporting, the token was down about 4% over the past week, up 44% over the past month, and up 2.3% year to date.

Nothing in Polygon’s disclosure ties those price moves directly to the vulnerability news – the monthly gain in particular predates the disclosure by weeks and likely reflects broader token dynamics rather than security sentiment. Investors weighing the disclosure should separate the technical story from the price action: a security team disclosing already-fixed flaws is a different signal than one scrambling to patch an active exploit, and POL holders tracking daily moves should read the two threads independently rather than assuming one explains the other.
Follow CoinNews on X and Telegram for ongoing coverage of network security disclosures and POL market moves.