Polygon Labs’ Validators Support Team disclosed a set of serious network bugs this week, well after the fixes had already been tested and rolled out through two hard forks called Austin and Kyoto. The bugs lived in Bor and Heimdall, the two pieces of software that keep Polygon’s proof-of-stake network running, and one flaw in Heimdall was serious enough that a single crafted transaction could have forced validators to burn through an unusual amount of processing power, the kind of overload that risks slowing the whole network down, while two separate issues in Bor could have crashed nodes or backed up block processing.
Why Polygon Waited to Go Public
Polygon’s team tested and activated the fixes privately first, giving validators a window to upgrade before any technical details went public. That sequencing narrows the gap attackers could exploit, since publishing a vulnerability before it’s patched hands them a blueprint to work from.
Polygon reported no evidence that anyone exploited these bugs on the live network. The disclosure notes that limiting how long the technical details were public, by releasing them only after the hard forks had already activated, was a deliberate part of containing that risk.
What Validators and Node Operators Need to Do
Anyone running an older version of Bor or Heimdall that’s already past the hard fork activation height has fallen out of sync with the network and can’t participate normally until they update. Polygon requires Bor v2.10.0 across all Polygon PoS nodes, and Heimdall v0.11.0 for validators and full nodes, with both versions already live on mainnet.
The upgrade isn’t optional or gradual. Once a node passes the activation height on outdated software, it stops following the canonical chain entirely, which means missed rewards for validators and a node that’s effectively offline until the client is updated.
Austin activated at mainnet block 91,949,700 and Kyoto at block 51,533,000, according to Crypto Briefing’s coverage of the disclosure. Both upgrades were validated on the Amoy testnet before rolling out to mainnet, giving Polygon’s team a chance to catch problems before validators had to touch the changes directly.
Why This Matters Beyond Polygon’s Validators
Client bugs like this rarely stay contained to the validators running the software. Polygon’s proof-of-stake network depends on Bor and Heimdall staying patched and diverse across thousands of nodes, and a flaw that forces validators to overload is the kind of thing that can ripple outward into slower transactions or broader network instability if it isn’t caught in time.
If you’re new to how staking Polygon actually secures the network, that’s the mechanism these bugs put under strain.
What This Means for You: Polygon catching and patching this before disclosing it is the responsible version of how this is supposed to work, and it’s worth watching whether the network publishes a fuller post-mortem or bug bounty details in the weeks ahead. If you hold POL or use apps built on Polygon, there’s nothing to act on here directly, since the fixes are already live on mainnet. The takeaway is simply that the infrastructure got patched before it became a public target.

