Breaking
DENorwegens König Harald V. verstorben: Ein Rückblick auf sein Wirken und die Zukunft der MonarchieTRUkrayna Büyükelçisi Dışişleri Bakanlığına çağrıldıRUNiger defense forces suppress military mutiny in NiameyBRIncêndio em condomínio residencial mobiliza Corpo de BombeirosTRKiev yakınlarında İHA saldırısı: 37 ölü, soruşturma başlatıldıTRNijer'in başkenti Niamey'de silah sesleri ve güvenlik hareketliliğiCN云南发布地质灾害气象风险预警,多地滑坡泥石流风险高ARإلغاء تأشيرة وزيرة المالية العراقية السابقة طيف سامي وتطورات الوجود العسكري الأجنبيESLocalizada a salvo la ciudadana australiana Cara Severino tras las inundaciones en NepalCN吉尔吉斯斯坦各界热切期待习近平主席访问DENorwegens König Harald V. verstorben: Ein Rückblick auf sein Wirken und die Zukunft der MonarchieTRUkrayna Büyükelçisi Dışişleri Bakanlığına çağrıldıRUNiger defense forces suppress military mutiny in NiameyBRIncêndio em condomínio residencial mobiliza Corpo de BombeirosTRKiev yakınlarında İHA saldırısı: 37 ölü, soruşturma başlatıldıTRNijer'in başkenti Niamey'de silah sesleri ve güvenlik hareketliliğiCN云南发布地质灾害气象风险预警,多地滑坡泥石流风险高ARإلغاء تأشيرة وزيرة المالية العراقية السابقة طيف سامي وتطورات الوجود العسكري الأجنبيESLocalizada a salvo la ciudadana australiana Cara Severino tras las inundaciones en NepalCN吉尔吉斯斯坦各界热切期待习近平主席访问
BackPolygon Labs Warns Stale Nodes Fell Out of Consensus After Austin and Kyoto Hardforks
Polygon Labs Warns Stale Nodes Fell Out of Consensus After Austin and Kyoto Hardforks
Tech
CryptoSlate3 hours agoTech2 min read

Polygon Labs Warns Stale Nodes Fell Out of Consensus After Austin and Kyoto Hardforks

Polygon Labs reveals nodes failing to upgrade past August activation heights fell out of consensus, detailing security fixes in Austin and Kyoto hardforks.

Quick Look

  • Polygon Labs stated that nodes failing to upgrade past the Austin and Kyoto hardfork activation heights have fallen out of canonical consensus.
  • The security review detailed fixes for resource-exhaustion risks in Bor and Heimdall clients.

AI-generated summary

Why It Matters

Polygon activated the Austin and Kyoto hardforks in August to address client risks in Bor and Heimdall.

Font size

Polygon Labs said any Polygon PoS node that stayed on pre-hardfork Bor or Heimdall binaries past two August activation heights has already fallen out of canonical consensus. In practice, the stale node must upgrade and catch up before it can follow the network’s accepted history again.

The company’s Aug. 27 security review described a client-compatibility consequence. Polygon said it had not observed mainnet disruption from Austin and framed the disclosed changes as proactive fixes.

Bor is Polygon PoS’s execution client, while Heimdall handles consensus and checkpointing. Bor versions earlier than v2.10.0 are incompatible after Austin activated at mainnet block 91,949,700, a cutoff that applies to all Bor node roles.

Heimdall validators and full nodes need v0.11.0 after Kyoto activated at height 51,533,000. Polygon’s Heimdall release notice dates that mainnet activation to Aug. 18 at 10:10:31 UTC.

Austin and Kyoto addressed separate client risks

Austin capped the gas consumed while Bor processes state-sync events from L1-to-L2 bridge deposits. Those events execute contract code and precompiles, but their gas use was not previously counted against a fixed block-level ceiling.

Enough events, or one sufficiently costly event, could make block processing slow enough to stall the chain transiently.

The second weakness sat in Bor’s TxDependency extra-data field, a hint used for parallel execution. Because the producer-supplied field had no size limit, a block producer could place an arbitrarily large blob in an otherwise valid sibling block and crash peers that tried to process it.

Austin removed the field from the wire format, and Polygon classified both weaknesses as resource-exhaustion risks.

The public Bor v2.10.0 release records Austin’s mainnet and Amoy activation blocks. GitHub showed v2.10.1 as the latest Bor release when checked Aug. 28, while v2.10.0 or later provides Austin compatibility.

Operationally, one Austin path threatened delayed block processing, while the other could terminate peers receiving a producer’s oversized data field.

Kyoto’s highest-severity fix targets deeply nested google.protobuf.Any messages. A sender could cheaply construct one transaction that forced every validator to spend heavily on decoding. The hardfork added a byte-level nesting check at both mempool admission and block-proposal processing, keeping those paths consistent.

It separately capped fee-coin lists before an O(n) validation scan, and Heimdall’s integration permits one fee coin.

Other Kyoto changes address distinct edge cases. They normalize checkpoint signature recovery bytes so a valid signature cannot fail recovery on Ethereum and stall anchoring, make repeated producer-downtime messages idempotent, bind milestone-range votes to the signed parent hash, and prevent a failed future-span creation from blocking milestone commitment.

Replay keys for topup, clerk, and stake events were also made injective for out-of-range log indexes so distinct layer-1 events cannot silently shadow each other.

Both hardforks are plain binary upgrades with no state migration or genesis change, and nodes that had not diverged require no resync.

Operators already past the relevant height on an older client should install the applicable release, roll back to a pre-hardfork point if needed, and resync under Polygon’s guidance.

Open Questions

  • How many total nodes failed to upgrade before the activation heights?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

Cosmos EVM vulnerability exploited across six networks, exposing broader ecosystem risk
Developing·14 hours ago

Cosmos EVM vulnerability exploited across six networks, exposing broader ecosystem risk

A Cosmos EVM accounting flaw was exploited on six networks including MANTRA, TAC, and KiiChain, leading to approximately $2.87 million in losses via decentralized exchanges and $2.85 million via centralized venues. Cosmos Labs initially underestimated the flaw, believing it only affected six-decimal networks, but later found it vulnerable regardless of decimal configuration. The vulnerability impacted around 40 blockchains, with 13 chains patching before exploitation and 11 previously unknown deployments discovered. MANTRA suffered the largest disclosed loss of about 720.9 million tokens valued at $3.6 million, with no recovery as of Aug. 28. The incident prompted Cosmos Labs to revise its vulnerability triage and disclosure procedures.

CryptoSlate
2 min read
Circle Sets December 1 Deadline for CCTP V1 Deprecation, Gives Developers 95 Days to Migrate
Developing·15 hours ago

Circle Sets December 1 Deadline for CCTP V1 Deprecation, Gives Developers 95 Days to Migrate

Circle announced that developers using the first version of its Cross-Chain Transfer Protocol (CCTP V1) have until December 1 to migrate to CCTP V2, after which legacy contracts will stop processing USDC transfers. Burn limits will begin decreasing on October 31, with a phased wind-down through November. Aptos, Noble, and Sui are the only chains currently supported exclusively by CCTP V1.

CryptoSlate
2 min read
More on this topicpolygon