Arbitrum official notice explaining the temporary pause on new Stylus activations

Arbitrum Pauses New Stylus Activations as AI-Assisted Attack Risk Grows

• October 3, 2026 7:31 am • Comments

Arbitrum has temporarily shut the door on new Stylus contract activations across Arbitrum One and Nova after flagging a growing class of AI-assisted attack techniques.

The precaution is narrower than a network shutdown. Existing Stylus applications can continue running, ordinary Solidity contracts are unaffected, and developers can still extend an active program’s life through the network’s keepalive mechanism.

What developers cannot do for now is activate a new WebAssembly program, reactivate one that has expired, or activate a version that needs fresh approval after a Stylus upgrade.

A targeted pause, not a blanket stop

CryptoSlate reports that Arbitrum’s Security Council took the emergency action on October 2 after assessing risks from specially constructed WebAssembly programs outside the ordinary compiler route. The network raised the gas required for activation to a prohibitively expensive level, a targeted configuration change that did not require an ArbOS upgrade or interrupt normal Solidity execution.

Stylus lets developers run WebAssembly programs alongside Ethereum-compatible Solidity contracts. Deployment stores code onchain; activation makes that code executable.

The pause targets the second step.

That distinction means a developer may still create a new contract instance using program code that is already active and valid. Existing applications remain callable, and active programs can use permissionless keepalive renewal before they expire.

Arbitrum linked the move to increasingly sophisticated AI-assisted attacks using hand-crafted WebAssembly outside the normal Stylus compiler path. The known bug class is primarily associated with chain-liveness and denial-of-service risk.

The Council said it had not found an attack that enables theft of user funds.

The Council’s transaction records show the emergency changes executing on October 2 at roughly 15:30 to 15:31 UTC across Ethereum, Arbitrum One, and Nova. That timing provides an onchain checkpoint for the restriction rather than leaving the pause as a policy announcement alone.

Developers can still store new code and reuse an activation that remains valid for identical program code. The practical bottleneck appears when an application needs a genuinely fresh activation, an expired program must be reactivated, or a version change invalidates the earlier activation.

A second guard could delay some withdrawals

The emergency action also installed a separate safeguard around BoLD one-step proofs on Arbitrum One. If conflicting answers to the same step of an open challenge are both accepted, settlement from Arbitrum One to Ethereum would pause while the Council deploys a fix.

Arbitrum One would continue processing transactions during that condition, but unconfirmed messages to Ethereum—including withdrawals—could be delayed. Installing the guard did not itself pause withdrawals; the delay only happens if the conflict condition is triggered.

The network has not set a reopening date for new Stylus activations. The Foundation and ArbitrumDAO are expected to determine the timing and method after the risk is addressed.

For users, the practical message is restraint rather than panic: normal network activity continues, existing Stylus software remains available, and Solidity contracts operate as before. For builders preparing new Stylus code, however, the activation gate is closed until Arbitrum is satisfied that the new attack surface is contained.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.