Arbitrum’s Stylus activation pause targets AI-assisted attack risks
0
0

Arbitrum’s Security Council moved to block new Stylus contract activations on Arbitrum One and Nova starting October 2, 2026, in what the network described as an emergency response to increasingly sophisticated AI-assisted attacks. The Arbitrum Stylus activation pause does not touch contracts already running on the network, but it stops developers from turning on fresh WebAssembly-based programs until further notice, according to the Security Council’s action report.
Key takeaways
- Arbitrum’s Security Council paused new Stylus contract activations on Arbitrum One and Nova on October 2, 2026, citing AI-assisted attack risks.
- The restriction was implemented by raising activation gas costs to a prohibitively expensive level, a configuration change that required no ArbOS upgrade.
- Existing Stylus contracts keep running, and ordinary Solidity deployment and execution on Arbitrum are untouched.
- No theft of user funds has been detected despite the identified bugs and attack vectors.
- A separate safeguard for BoLD’s one-step proofs could delay pending withdrawal messages from Arbitrum One to Ethereum.
- Reopening Stylus activations depends on a future timeline set jointly by the Arbitrum Foundation and ArbitrumDAO.
Emergency Pause on New Stylus Contract Activations
The core of this action is narrow but deliberate: Arbitrum is not shutting anything down; it is blocking the door to new entries. The Security Council’s October 2 move specifically targets Stylus contract activation, the step that makes a WebAssembly program executable on the chain, without touching code that is already live.
Details of the Pause Implementation
Rather than pushing a software upgrade, the Council chose a simpler lever: gas pricing. It raised the activation gas requirement to a level the Council itself called “prohibitively expensive,” effectively pricing new activations out of reach without altering the underlying protocol. This matters because it means the fix required no upgrade to ArbOS, the operating software that runs Arbitrum One and Nova — the Council treated this purely as a configuration change, something that can be reversed quickly once the risk is addressed.
Scope and Impact on Developers
For builders already on Stylus, the practical distinction is between storing code and making it usable. Deployment, which stores a program onchain, is unaffected. Activation, the step that turns that stored code into something executable, is what’s frozen. New contract instances that reuse an already-valid activation of identical program code can still launch normally.
What’s blocked is anything needing a fresh start: a new application version, an expired program trying to reactivate, or any Stylus contract that needs reactivation following a version change. Before a program actually lapses, its developers retain the option of prolonging its active status via the permissionless keepalive renewal mechanism — meaning that programs nearing expiration aren’t automatically finished, as long as the responsible team renews on time.
Crucially, ordinary Solidity contract deployment and execution on Arbitrum remains unaffected. The vast majority of everyday Arbitrum activity — Solidity-based DeFi protocols, dApps, and token contracts — continues as normal. This is a Stylus-specific intervention, not a network-wide freeze.
Reason for the Pause: AI-Assisted Attack Risks
Arbitrum attributed the restriction to a rising threat: increasingly sophisticated, AI-assisted attacks built around hand-crafted WebAssembly programs that sidestep the standard Stylus compiler toolchain. In other words, attackers aren’t necessarily writing malicious Rust or C code and compiling it the normal way — they’re crafting raw WebAssembly bytecode designed to exploit edge cases the compiler would normally prevent.
According to the Council, the known bugs tied to this risk primarily threaten chain liveness rather than user assets — think denial-of-service conditions that could stall parts of the network, not drain wallets. No attack permitting theft of user funds had been discovered, a distinction the Council was careful to spell out. This matters for anyone holding assets on Arbitrum: the risk profile here is about network stability and uptime, not direct loss of funds.
Still, the fact that custom, AI-generated WebAssembly can probe for weaknesses outside the normal toolchain is itself notable. It suggests attackers are using automated tooling to find corner cases human reviewers or standard compilers might miss — a pattern that blockchain security teams across the industry are likely watching closely as AI-assisted exploit development becomes more common.
Additional Security Safeguards and Operational Effects
Alongside the Stylus freeze, the same October 2 emergency action installed a separate protection for Arbitrum One’s BoLD one-step proofs, the mechanism used to resolve disputes during challenge periods on the chain’s settlement process.
BoLD’s One-Step Proofs Protection
This protection targets a particular case: when two contradictory answers are submitted for the same step within an open challenge, and the one-step proof system ends up validating both, a conflict arises during settlement. The new guard puts Arbitrum One’s settlement to Ethereum on hold if that conflict condition is triggered, giving the Council room to deploy a fix before resuming normal settlement.
Potential Transaction Delays on Ethereum
Arbitrum says Arbitrum One continues processing transactions normally even if this hold is triggered. The catch is for messages moving from Arbitrum One to Ethereum that haven’t yet been confirmed — including withdrawals. Those would have to wait while the Council resolves the conflict and resumes settlement. Installing the guard doesn’t automatically pause withdrawals on its own; the delay only kicks in if the specific conflicting-proof condition is actually met.
This is worth flagging for anyone planning to bridge assets off Arbitrum One in the near term: a withdrawal that would normally settle on Ethereum within the usual window could, in a worst-case scenario, sit pending longer than expected.
Outlook on Reopening and Future Decisions
There’s no fixed date yet for when new Stylus activations will resume. The October 2 report and developer notice left the timeline open, with the Council saying the Arbitrum Foundation will work alongside ArbitrumDAO to decide both the timing and the manner of restoring activations.
That open-endedness puts Stylus-focused developers in a holding pattern. Teams with active contracts can keep operating and renewing through keepalive mechanisms, but anyone planning to launch new Stylus applications or push major version updates will need to wait for the Foundation and DAO to settle on next steps.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
0
0
Securely connect the portfolio you’re using to start.






