Arbitrum Pauses New Stylus Activations After AI-Assisted Attacks
Key Takeaways
- •The Arbitrum Security Council halted new Stylus contract activations on Arbitrum One and Nova on Oct. 2, 2026, after AI-assisted tools made it easier to construct malicious hand-crafted WebAssembly code.
- •The restriction was implemented by setting the WASM activation gas requirement to 2^64 – 1, a configuration change that makes new activations economically impractical without requiring a software upgrade.
- •Existing Stus contracts remain fully operational and renewable through the permissionless keepalive mechanism, with the ArbOS 61 upgrade ensuring none expire before Aug. 20, 2027.
- •A newly deployed OspSoundnessGuard can pause settlement between Arbitrum One and Ethereum if the BoLD one-step proof system accepts two conflicting answers for the same execution step.
- •Arbitrum has not identified any attack enabling the theft of user funds and has not announced when Stylus activations will be restored.

Arbitrum has temporarily halted new Stylus contract activations on Arbitrum One and Nova after AI-assisted development tools lowered the barrier to crafting attacks against hand-built WebAssembly programs. The emergency measure blocks new Stylus contracts from being activated, but it does not stop existing contracts from running or prevent users from interacting with applications already deployed on the networks.
The Arbitrum Security Council — the emergency-response body empowered under ArbitrumDAO's governance framework to act on security matters — completed the emergency action at 11:30 EST on Oct. 2, 2026. Alongside the pause, the response introduced an additional safeguard for Arbitrum One's one-step proof mechanism under BoLD, the system used to validate the chain's state before it is settled to Ethereum.
The intervention is designed to keep new hand-crafted WASM programs from entering the network while Arbitrum investigates vulnerabilities that could affect chain availability, all without disrupting existing Stylus applications or Solidity-based development.
AI Tools and the Attack Scenario
Stylus lets developers write smart contracts as WebAssembly programs rather than relying solely on the Ethereum Virtual Machine execution path. WebAssembly is an open standard built for fast, sandboxed execution in web browsers, and it has since been adopted as a smart contract execution format on other major blockchain platforms as well. Most Stylus contracts pass through the platform's compiler tooling, but the attack scenario identified by Arbitrum involved manually crafted WASM code capable of bypassing that toolchain.
According to the Arbitrum Foundation, AI-assisted tools have increased the ability to build more sophisticated programs capable of producing unexpected behavior. The identified programs could potentially degrade network performance and affect other users. Arbitrum has not identified any attack that would enable the theft of user funds.
Existing Stylus Contracts Remain Active
The restriction targets activation rather than execution. Existing Stylus contracts will continue to run until their expiration, and users can keep calling them. Developers can also renew active contracts the existing permissionless keepalive mechanism.
That distinction means applications already operating on Arbitrum are not being shut down under the emergency measure. Their on-chain activity can continue even though new Stylus deployments cannot currently be activated.
The ArbOS 61 upgrade renewed every active Stylus contract on Arbitrum One, ensuring that none will expire before Aug. 20, 2027. However, reactivating a contract after expiration, or deploying an updated version that requires a fresh activation, remains subject to the pause.
Solidity development is unaffected. Developers can continue deploying and executing Solidity contracts through the EVM as usual.
Gas Configuration Makes New Activations Impractical
Arbitrum implemented the restriction through a configuration change rather than a new network software release. The Security Council called ArbOwner.setWasmActivationGas on each affected chain and set the activation requirement to 2^64 – 1, the largest value a 64-bit unsigned integer can hold.
The configuration makes new Stylus activations economically impractical while leaving the underlying execution infrastructure and already-active contracts fully operational. This approach allowed Arbitrum to restrict the vulnerable entry point without requiring an ArbOS upgrade or a separate external audit for the activation change itself.
The activation mechanism remains technically available, but the required gas level places it beyond practical use. Restoring normal Stylus activation will require another configuration decision, and Arbitrum has not announced when that change will occur.
Additional Protection Added for BoLD
The emergency response also addressed Arbitrum One's one-step proof system under BoLD. Arbitrum One settles to Ethereum through a challenge-based validation model in which posted state claims can be disputed before they become final, and the one-step proof is designed to resolve such disputes by verifying a single execution step directly rather than through successive rounds of counter-claims. A newly deployed OspSoundnessGuard can receive two conflicting answers concerning the same step in an open challenge. If the proof system accepts both answers, the guard can pause settlement between Arbitrum One and Ethereum, temporarily preventing the network from finalizing its state on Ethereum until the conflicting proof issue is resolved.
The safeguard has been designed with limited authority. A new PauseExecutor contract can pause the guard but holds no broader powers. The Foundation said the guard contracts underwent an external audit.
Arbitrum characterized the measure as precautionary. The Foundation has not indicated that the one-step proof issue was exploited against the production network.
A Temporary Deployment Constraint for Developers
For developers, the immediate impact is concentrated on new Stylus activations. Existing Stylus contracts can keep running and can be renewed, while new versions requiring activation must wait. EVM and Solidity applications remain unaffected.
The pause creates a temporary trade-off: developers must delay new Stylus deployments while Arbitrum investigates the attack surface, while users of existing applications can continue using active contracts without needing to withdraw.
Arbitrum is expected to work with ArbitrumDAO on the timing and process for restoring Stylus activations. No end date has been announced, and the Foundation has not disclosed how many contracts or projects are directly affected.
The incident underscores a growing security challenge for blockchain development as AI-assisted programming tools make sophisticated attack construction more accessible. For Arbitrum, the response is narrowly focused on network availability and the integrity of its settlement process rather than any evidence of a direct threat to user funds.