Polygon discloses security flaws fixed in recent hard forks

요약:Polygon disclosed previously private security flaws that posed denial-of-service and validator risks after fixes were deployed through two hard forks.

Polygon has disclosed several previously private security vulnerabilities that could have disrupted its proof-of-stake network, after deploying fixes through two recent hard forks.

The vulnerabilities affected Polygon‘s Bor and Heimdall clients and included denial-of-service risks, validator resource exhaustion and flaws affecting checkpoint and milestone processing, according to a Thursday disclosure from Polygon Labs’ Validators Support Team.

Polygon said the flaws were fixed through the Austin and Kyoto hard forks, which were deployed privately and tested before being activated on mainnet and publicly disclosed.

The most severe issue involved Heimdall, where a specially crafted transaction could force validators to perform excessive processing work, potentially disrupting the network. The Austin hard fork separately addressed two denial-of-service risks in Bor that could have slowed block processing or caused nodes to crash.

None of the vulnerabilities were observed being exploited on mainnet, according to Polygon, which said the fixes were deployed proactively before details were made public.

Nodes running older versions of either client past the hard fork activation heights have already fallen out of consensus and must upgrade to rejoin the canonical network, according to the disclosure. Bor v2.10.0 is required for all Polygon PoS nodes, while Heimdall v0.11.0 is required for validators and full nodes, with both upgrades already active on mainnet.

POL, Polygons native token formerly known as MATIC, was trading around $0.10 at the time of writing, down about 4% over the past week but up 44% over the past month and 2.3% year to date, according to CoinGecko data.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

폴리곤, 최근 하드포크에서 수정된 보안 취약점 여러 건 공개

다음

약 75,000,000달러 규모의 Tectonic 익스플로잇 이후 Cronos 네트워크 중단