Polygon has quietly patched a series of critical denial-of-service vulnerabilities on its proof-of-stake blockchain, closing the security gaps before making the risks public and with no reported exploit on the mainnet. The fixes came through two coordinated hard forks, Austin and Kyoto, upgrading the software that handles block processing and validator coordination on Polygon. Those flaws could have let attackers overwhelm key parts of the network, slowing nodes, disrupting transaction processing, and putting consensus under strain.

Polygon tested the patches on its Amoy testnet, then activated them on mainnet before disclosing the technical details. That delay was deliberate: releasing specifics before most node operators updated would have given attackers a clearer target. By forking first, Polygon also forced old software out of consensus after the transition, reducing the window in which vulnerable nodes could threaten chain stability. No mainnet exploit was reported, and node operators now need the updated software.

Polygon’s pre-disclosure DoS patch is the infrastructure watchpoint. Whether the fix holds under real load will matter next.