
AI-generated summary
Polygon is a proof-of-stake blockchain network that uses Bor and Heimdall clients for block production and validation. Security vulnerabilities in such clients could disrupt consensus and network stability.
Polygon has disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake network, after deploying fixes through two recent hard forks.
The vulnerabilities affected Polygon’s Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion and flaws affecting checkpoint and milestone processing, according to a Thursday disclosure from Polygon Labs’ Validators Support Team.
Polygon said the flaws were fixed through the Austin and Kyoto hard forks, which were deployed privately and tested before being activated on mainnet and publicly disclosed.
The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. The Austin hard fork separately addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash.
None of the vulnerabilities were observed being exploited on mainnet, according to Polygon, which said the fixes were deployed proactively before details were made public.
Nodes running older versions of either client past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network, according to the disclosure. Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes, with both upgrades already active on mainnet.
POL, Polygon’s native token formerly known as MATIC, was trading around $0.10 at the time of writing, down about 4% over the past week but up 44% over the past month and 2.3% year to date, according to CoinGecko data.

Bitcoin Knots is conducting a Sunday test to replace SHA-256d with BLAKE2b proof of work after its BIP-110 fork stalled, aiming to establish miner independence but facing unresolved questions about hash rate, infrastructure support, and economic viability.

Sen. Bernie Sanders pledged to introduce legislation targeting Flock Safety, warning that its AI-powered license plate readers are pushing the U.S. toward a surveillance state. He cited the company's deployment of over 120,000 cameras scanning 20 billion vehicles monthly and its ability to link vehicle data with personal databases. The announcement adds to a growing bipartisan backlash, with lawmakers and local governments already acting to restrict the technology amid privacy concerns.

Polygon Labs stated that nodes failing to upgrade past the Austin and Kyoto hardfork activation heights have fallen out of canonical consensus. The security review detailed fixes for resource-exhaustion risks in Bor and Heimdall clients.

Meta is testing maintenance robots from companies like Watney Robotics, Kinova, and ABB to handle tasks in its AI data centers, raising concerns among workers about potential job displacement despite industry arguments regarding skilled-labor shortages.

Cities across the U.S., including Austin, San Marcos, Durham, Cave City, and Jersey City, are enacting restrictions on AI data center development due to concerns over water consumption, electricity demand, and land use, following a Ceres study showing power plants serving data centers withdraw 3.4 trillion gallons of freshwater annually.

Ripple is removing over 10,000 lines of unused XChainBridge code from the XRP Ledger to reduce attack surface while Lending Protocol V1.1 undergoes an AI-only security review via Sherlock’s Audit Engine, reflecting broader industry pressure to strengthen crypto defenses after $1.31 billion in losses from 344 incidents in H1 2026.