Polygon Confirms Bor and Heimdall Fixes From Austin, Kyoto Forks, Says No Exploits
Two outlets confirm Polygon patched DoS flaws before disclosure; version numbers and POL's $0.10 price come from a single source.

Polygon has confirmed that two recent hard forks, named Austin and Kyoto, closed denial-of-service vulnerabilities on its Bor and Heimdall clients. Both reports reviewed for this story agree that the fixes went live on mainnet before Polygon told the public what they addressed. Polygon says none of the flaws were ever exploited.
What Two Sources Confirm
Decrypt and Cointelegraph independently describe the same underlying event: Polygon quietly deployed the Austin and Kyoto hard forks, tested and activated them on mainnet, and only afterward disclosed the security issues they had closed. Both outlets agree the fixes touched the Bor and Heimdall clients and involved denial-of-service risk. Both also report Polygon’s own claim that no vulnerability was observed being exploited on the live network.
That sequencing, patch first, disclose later, is a deliberate security practice, not a cover-up. It gives node operators time to upgrade before attackers can reverse-engineer a fix into a working exploit.
Single-Sourced Technical Detail
Cointelegraph provides additional technical detail not corroborated in the Decrypt material reviewed here, so it should be read as reported by that outlet rather than as independently confirmed. According to Cointelegraph, the disclosure came from Polygon Labs’ Validators Support Team on Thursday, and named three categories of flaw: denial-of-service risk, validator resource exhaustion, and issues affecting checkpoint and milestone processing.
The most serious of these, per that account, sat in Heimdall: a specially crafted transaction could reportedly force validators to perform excessive processing work, with the potential to disrupt the network. The Austin fork separately targeted two Bor-side denial-of-service paths that could have slowed block processing or crashed nodes outright.
Node Upgrade Requirements
Cointelegraph also reports specific version numbers: Bor v2.10.0 is required for all Polygon PoS nodes, and Heimdall v0.11.0 is required for validators and full nodes. Both upgrades are described as already active on mainnet. Nodes still running older client versions past the hard fork activation heights have reportedly fallen out of consensus and cannot rejoin the canonical chain until they upgrade.
Node operators who have not yet applied both upgrades are effectively running on a forked, non-canonical version of the network, according to the disclosure as relayed by Cointelegraph.
POL Price Context
POL, Polygon’s native token, was trading around $0.10 at the time of Cointelegraph’s report, down roughly 4% over the prior week but up 44% over the prior month and 2.3% year to date, per CoinGecko data cited by that outlet. This price figure appears in only one of the two reports reviewed, so it should be treated as a snapshot from that specific timestamp rather than a confirmed cross-source data point.
For validators and full-node operators, the actionable fact is not the token’s short-term move but the client versions: Bor v2.10.0 and Heimdall v0.11.0 are the confirmed requirements for staying on the canonical Polygon PoS chain following the Austin and Kyoto activations.
Sources
Related articles
Bitcoin-Gold Ratio Hits 18.17, Highest Since January, as CZ Flags Cycle Flip
The BTC/gold ratio climbs to 18.17, its highest level since January, as debt fears lift both assets and CZ floats a market-cap…
Liquid Network’s 4,019 BTC ($320M) Drain: What Two Sources Actually Confirm
Blockstream's Liquid sidechain lost 4,019 BTC (~$320M) in a peg-out. Two outlets confirm the figure; the on-chain "message" claim is single-sourced.
Liquid Sidechain Balance Falls From 4,200 BTC to 207 BTC After $320M Drain
Blockstream's Liquid federation wallet dropped to about 207 BTC after purported white-hat hackers withdrew roughly $320M; the sidechain is now paused.