Crypto: Polygon Reveals Why the Austin and Kyoto Hard Forks Were Necessary

By: www.cointribune.com|2026/08/30 09:22:41

Polygon has finally explained what its Austin and Kyoto hard forks were hiding. The two updates addressed several security vulnerabilities that were kept private during their deployment. Some could slow down the network, crash nodes, or force validators to perform very costly computational work. Polygon claims to have observed no exploitation on the mainnet.

In Brief

  • Austin fixed two denial-of-service risks in Bor.
  • Kyoto strengthened Heimdall against several attacks and validation errors.
  • The fixes had already been activated before their public disclosure.

Crypto: Austin Closed Two Vulnerabilities in Bor

Polygon is already familiar with security hard forks. In 2025, the network had to fix a critical bug with an emergency update. This time, Austin focused on Bor, the client responsible for producing Polygon's PoS blocks.

The first vulnerability concerned state sync operations from Ethereum to Polygon. These operations can execute code and consume gas. Unlike traditional crypto transactions, there was no strict limit on their total consumption within a block.

A sufficiently loaded block could therefore demand too much work from the nodes. Polygon added a limit. The second weakness came from a field called TxDependency. It was used to assist in the parallel execution of transactions, but its size was not capped.

A block producer could theoretically create an enormous field. Another node would receive the block and could crash while trying to process it. Austin simply removed this field from the format transmitted between nodes.

Kyoto Primarily Protected Heimdall

Kyoto was concerned with Heimdall, the other major component of the Polygon PoS network. Polygon had already deeply modernized this component with Heimdall v2, described as its most complex hard fork since 2020.

The most significant vulnerability came from specially constructed crypto transactions. Heimdall uses structures capable of containing others. Without a depth limit, an attacker could stack these elements and send a relatively simple transaction to create.

Validators would then have to perform a lot of calculations to decode it. The same work. On almost all validators. Kyoto now imposes a maximum depth and rejects transactions that exceed this threshold.

The update also fixes a list of fees that could previously become extremely long. Again, the goal was to prevent a user from causing unnecessary resource consumption.

Other fixes affect checkpoints, milestones, and certain events from Ethereum. A valid checkpoint signature could notably arrive in a form that would then fail during processing on Ethereum. There’s no need to steal tokens to disrupt a network. Wasting crypto validators' time can already be sufficient.

Polygon Fixed Issues Before Speaking

Polygon did not immediately publish the details. Austin and Kyoto were first discreetly deployed, tested on Amoy, and then activated on the mainnet. The explanations came afterward.

This is intentional. Publishing a vulnerability before validators had the fix would also have given attackers the playbook. Austin now requires Bor v2.10.0. Kyoto requires Heimdall v0.11.0 for validators and full nodes.

Polygon assures that none of the disclosed vulnerabilities caused any known incidents on the mainnet. The corrections were therefore preventive. The network has significantly accelerated its updates over the past two years. By the end of 2025, Polygon had deployed Madhugiri to reduce consensus time and increase performance. Austin and Kyoto tell another part of the story. No more speed this time. Just doors that were better closed before someone tried to open them.

Operators who remained on an old version after the activation heights are no longer following the canonical chain. They must update their software and then resynchronize.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

Latest coin listings on WEEX

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com