Polygon ’s Blockchain Hard-Forked Without Warning To Closed-Source Genesis. Why?
What’s going on at Polygon? There seems to be a disturbance in the force over there. Is the Ethereum Layer 2 project alright? Are they doing everything above board or is there something sinister going on? Are they even d...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
What’s going on at Polygon? There seems to be a disturbance in the force over there. Is the Ethereum Layer 2 project alright? Are they doing everything above board or is there something sinister going on? Are they even decentralized if they can hard-fork just like that? Or did they follow the proper procedures and their critics are just uninformed? Can we even answer all of those questions? Probably not. But we can present all the information available and let you all get to your own conclusions.
Are we all supposed to just shut up and forget about the fact that over a week ago Polygon hard-forked their blockchain in the middle of the night with no warning to a completely closed-source genesis and still haven't verified the code or explained what is going on?
— Nathan Worsley (@NathanWorsley_) December 15, 2021
Let’s start with DeFi Builder Nathan Worsley’s accusation. Or is he just requesting information? Worsley recently tweeted, “Are we all supposed to just shut up and forget about the fact that over a week ago Polygon hard-forked their blockchain in the middle of the night with no warning to a completely closed-source genesis and still haven’t verified the code or explained what is going on?”
Related Reading | Polygon: Ethereum’s Friend Is Looking To Make Big Strides
The “middle of the night” part is arguable since everyone is in different timezones and the Polygon blockchain is everywhere. However, he cleared up why the issue is important, “Until the code is verified there are no security guarantees about the billions of dollars in assets the chain currently secures.” And tweeted proof of everything else, “Here’s the commit that was hard-forked into production.”
Here's the commit that was hard-forked into production the middle of the nighthttps://t.co/qMunI4WZxx
— Nathan Worsley (@NathanWorsley_) December 15, 2021
To add credibility to his claim, DeFiance Capital’s Zhu Su joined the chorus asking for answers. “Was this to patch a critical bug? Why and how did this happen?”
Why am I seeing 100x more solana fud than discussion of this? Was this to patch a critical bug? Why and how did this happen? https://t.co/GhY3eTYNtm
— Zhu Su (@zhusu) December 15, 2021
Polygon Responds And Shows ReceiptsThe criticism got a response from Polygon’s co-founder Mihailo Bjelic. “We’re making an effort to improve security practices across all Polygon projects,” Bjelic tweeted. “As a part of this effort, we are working with multiple security researcher groups, whitehat hackers etc. One of these partners discovered a vulnerability in one of the recently verified contracts. We immediately introduced a fix and coordinated the upgrade with validators/full node operators. No funds were lost. The network is stable.”
2/2 ..vulnerability in one of the recently verified contracts. We immediately introduced a fix and coordinated the upgrade with validators/full node operators. No funds were lost. The network is stable.
A detailed blog post coming, we are finalizing additional security analyses.
— Mihailo Bjelic (@MihailoBjelic) December 15, 2021
Ok, that sounds reasonable. Bjelic also promised, “A detailed blog post coming, we are finalizing additional security analyses.” A question lingered in the air, though. And crypto enthusiast J. Vicente Correa asked it in the most direct way possible, “U can fork the chain by yourself and take all my funds as u wish?”
Absolutely not.
The network is run by validators and full node operators, and we have no control over any of these groups. We just did our best to communicate and explain the importance of this upgrade, but ultimately it was up to them to decide whether they will do it or not.
— Mihailo Bjelic (@MihailoBjelic) December 15, 2021
And Polygon’s Mihailo Bjelic answers in the most political way possible. “Absolutely not. The network is run by validators and full node operators, and we have no control over any of these groups. We just did our best to communicate and explain the importance of this upgrade, but ultimately it was up to them to decide whether they will do it or not.”
Fair enough. However…
MATIC price chart on Poloniex | Source: MATIC/USD on TradingView.com A Node Operator Has Some Criticism Of His OwnIn the same thread, Polygon node operator Mikko Ohtamaa blasted the way the company handled the whole thing and also showed receipts. “Next time it happens can you at least announce a critical update to all Polygon node operators. Now this looks super unprofessional and confusing for the community. It was not mentioned or pinned down in any major channels or publications.”
He got a response from Polygon’s other co-creator, Sandeep Nailwal. “This was a security update, and hence pre-public-announcement could’ve escalated things.”
Hey Mikko, this was a security update, and hence pre-public-announcement could've escalated things.
— Sandeep – Polygon – NAE (NOT Abandoning ETHEREUM) (@sandeepnailwal) December 15, 2021
Ok, that makes sense. However, Ohtamaa had more complaints. “Some bug fixes” for a critical patch is not good. If there is a critical fix you co-ordinate with validators.” Plus, he reinforced Nathan Worsley’s original complaint. “It’s really obvious it is a critical security bug if you do unannounced no notice hard fork in the middle of a weekend.”
It's really obvious it is a critical security bug if you do unannounced no notice hard fork in the middle of a weekend. So do not be dumb and think your users are dumb.
— Mikko Ohtamaa (@moo9000) December 15, 2021
According to Ohtamaa, “there are multiple open source projects out there” that have done similar operations in a more effective manner. Someone asked what could Polygon have done better. He answered with a series of simple steps.
- Prepare the patch privately.
- A few days before, announce a critical security fix is coming. All node operators need to be prepared.
- Distribute the patch at the preset time.
- Not downplay the criticality of the patch and make idiot-looking release notes.
Related Reading | How Polygon Sealed A $400M Deal To Get Ahead In The Ethereum ZK Rollup Race
So, is there something rotten at Polygon? We will have to wait for the “detailed blog post” Bjelic promised to know for sure.
Featured Image by Mae Mu on Unsplash - Charts by TradingViewWhy this matters
This blockchain story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on NewsBTCRelated market context
Polymarket Bettors Give Ethereum Just a 17% Shot at Reaching $3,000 in 2026
Traders on Polymarket and Kalshi are staking millions of dollars on where ethereum’s price lands before the end of 2026, with the...
Two Ethereum bridges lose $31.7M within hours as third protocol halts staking
AFX and the Verus-Ethereum bridge suffered about $31.69 million in combined losses within hours of each other, while B² Network se...
Nic Carter warns US may use quantum tech to compromise Bitcoin security
Nic Carter warns of potential quantum threats to Bitcoin security. Bitcoin reaching $200,000 by December 31, 2026 at 2.2% YES. The...
Ethereum Price Gaining Ground as Its SMA 30D Funding Rate Climbs Highest in Six Months
Ethereum price is approaching a key technical inflection point, trading at $1,880 after slipping about 0.3%, intensifying its bear...
Ethereum News: How a $67M ETH Short Reveals Hyperliquid’s Institutional Leap
In Ethereum news today, Fasanara Capital, a London-based quantitative asset manager, is holding a $67M ETH short on Hyperliquid vi...
BlackRock, Coinbase, Strategy Among Members of $15 Million Bitcoin Security Consortium
Nine institutional Bitcoin firms have formed the Bitcoin Security Consortium, pledging a combined $15 million over the next three...