Arbitrum’s Security Council temporarily blocked new Stylus contract activations on Arbitrum One and Nova in an October 2 emergency action, restricting programs and app updates that require fresh activation. Already-active Stylus applications can keep running, while ordinary Solidity contract deployment and execution remain unaffected, according to the Council’s action report.
Arbitrum attributed the precaution to increasingly sophisticated AI-assisted attacks involving hand-crafted WebAssembly programs outside the standard Stylus compiler toolchain. It said known Stylus bugs primarily threaten chain liveness, including denial-of-service risks, and that no attack permitting theft of user funds had been discovered.
The linked Ethereum, Arbitrum One and Nova transaction records show successful execution on October 2, around 15:30 to 15:31 UTC.
For builders, the distinction is between storing code and making it usable. Stylus contracts run WebAssembly programs, which need activation to become executable. Arbitrum’s documentation distinguishes that step from deployment, which stores code onchain. New contract instances using identical program code can reuse an existing activation, provided it is still valid.
A new application version requiring fresh activation cannot become executable during the pause. Reactivating an expired program, or one needing reactivation after a Stylus version change, is also blocked, the Council said. The scope is activation, rather than a blanket prohibition on deploying every new contract instance.
Existing programs remain callable until expiration. Developers can continue extending an active program’s lifetime through the permissionless keepalive renewal mechanism before it expires, according to the official pause notice. This leaves renewal available while reactivation of an already-expired program is blocked.


The Council said it implemented the restriction by raising the activation gas requirement to a prohibitively expensive level. It described this as a configuration change requiring no upgrade to ArbOS, the network’s operating software.
When withdrawals could wait
The same emergency action installed a separate safeguard for BoLD’s one-step proofs on Arbitrum One. Anyone can present two conflicting answers to the same step of an open challenge. If the one-step proof accepts both, the guard puts One’s settlement to Ethereum on hold, according to the Council.
Arbitrum says One would continue processing normally during that suspension. However, messages from One to Ethereum that have not yet been confirmed, including withdrawals, would have to wait while the Council deploys a fix and resumes settlement. Installing the guard does not itself pause withdrawals; the delay depends on its conflict condition being met.
For builders waiting to activate new Stylus code, reopening remains the next decision. The October 2 report and developer notice give no date, saying the Foundation will work with ArbitrumDAO on the timeline and manner of restoring activations.





Be the first to comment