Polygon has finally explained what its Austin and Kyoto hard forks were hiding. Both updates fixed several security vulnerabilities that were kept private during their deployment. Some could slow down the network, crash nodes, or force validators to do very expensive computational work. Polygon claims to have observed no exploitation on the mainnet.

In brief
- Austin fixed two denial of service risks in Bor.
- Kyoto has hardened Heimdall against several attacks and validation errors.
- The patches had already been activated before their public disclosure.
Crypto: Austin closed two vulnerabilities in Bor
Polygon already knows about security hard forks. In 2025, the network had to fix a critical bug with an emergency update. Austin this time focused on Bor, the client responsible in particular for producing Polygon PoS blocks.
The first flaw concerned state sync operations coming from Ethereum to Polygon. These operations can execute code and consume gas. Unlike traditional crypto transactions, however, there was no strict limit on their total consumption in a block.
A sufficiently loaded block could therefore require too much work from the nodes. Polygon added a limit. The second weakness came from a field called TxDependency. It was used to aid parallel execution of transactions, but its size was not capped.
A block producer could theoretically create a huge field. Another node received the block. Then he could crash while trying to process it. Austin simply removed this field from the format transmitted between nodes.
Kyoto especially protected Heimdall
Kyoto concerned Heimdall, the other big brick in the Polygon PoS network. Polygon had already thoroughly modernized this component with Heimdall v2, presented as its most complex hard fork since 2020.
The most significant flaw came from specially crafted crypto transactions. Heimdall uses structures capable of containing others. With no depth limit, an attacker could stack these elements and send a transaction that was relatively simple to create.
Validators then had to perform a lot of calculations to decode it. Same job. On almost all validators. Kyoto now imposes a maximum depth and rejects transactions that exceed this threshold.
The update fixes also a list of costs that could previously become extremely long. Again, the goal was to prevent a user from causing unnecessary resource consumption.
Other fixes affect checkpoints, milestones and certain events from Ethereum. In particular, a valid checkpoint signature could arrive in a form that then failed when processed on Ethereum. No need to steal tokens to hinder a network. Wasting crypto validators’ time can already be enough.
Polygon had corrected before speaking
Polygon did not immediately release details. Austin and Kyoto were first deployed quietly, tested on Amoy and then activated on the mainnet. The explanations came later.
It’s voluntary. Publishing a flaw before validators had the fix would also have given instructions to attackers. Austin now requires Bor v2.10.0. Kyoto requires Heimdall v0.11.0 for validators and full nodes.
Polygon assures that none of the disclosed vulnerabilities have caused any known incidents on the mainnet. The corrections were therefore preventive. The network has greatly accelerated its updates over the past two years. By the end of 2025, Polygon had further deployed Madhugiri to reduce consensus time and increase performance. Austin and Kyoto tell another part of the work. No more speed this time. Simply doors that were best closed before someone tried to open them.
Operators remaining on an old version after the activation heights no longer follow the canonical chain. They need to update their software and then resync.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
