Polygon revealed that the vulnerabilities, which posed denial-of-service and validator resource risks, were patched before the project publicly disclosed them.