Arbitrum halts Stylus activations amid AI-driven exploit fears

In an emergency action on October 2, Arbitrum’s Security Council temporarily blocked new Stylus contract activations on Arbitrum One and Nova, limiting programs and application updates that rely on fresh activation. According to the Council’s report, previously active Stylus applications continue to operate normally, and standard Solidity contract deployment and execution are unaffected.

Arbitrum explained that the precaution is a response to increasingly sophisticated AI-assisted attacks utilizing hand-crafted WebAssembly programs generated outside the standard Stylus compiler toolchain. The network noted that known Stylus bugs primarily present threats to chain liveness, such as denial-of-service risks, and emphasized that no attacks allowing the theft of user funds have been found.

Related Reading

Boltz’s shutdown shows the real danger of AI hacking is pushing crypto back into the hands of giant custodians

Transaction records across Ethereum, Arbitrum One, and Nova indicate successful execution on October 2 between approximately 15:30 and 15:31 UTC.

For developers, the situation hinges on the difference between storing code and making it usable. Stylus contracts execute WebAssembly programs, which require activation before they can run. Arbitrum’s documentation separates this step from deployment, which simply stores code onchain. Furthermore, new contract instances that use identical program code can utilize an existing activation as long as it remains valid.

The Council stated that any new application version demanding fresh activation cannot be made executable during the pause. Reactivating expired programs, or those requiring reactivation following a Stylus version change, is also blocked. Thus, the restriction targets activation rather than placing a blanket ban on deploying every new contract instance.

As outlined in the official pause notice, existing programs stay callable until they expire. Developers can also continue to extend active programs’ lifetimes prior to expiration by using the permissionless keepalive renewal mechanism, meaning renewal remains accessible even though reviving an already-expired program is prohibited.

The Council enforced the restriction by raising the activation gas requirement to a prohibitively high level. This adjustment was executed as a configuration change that required no upgrades to ArbOS, the operating software of the network.

Related Reading

Robinhood Chain kept producing blocks through a roughly 40-minute app disruption

When withdrawals could wait

The same emergency measure implemented a separate safeguard for BoLD’s one-step proofs on Arbitrum One. The guard pauses Arbitrum One’s settlement to Ethereum if anyone submits two conflicting answers to the exact same step of an open challenge and the one-step proof accepts both, according to the Council.

Arbitrum noted that Arbitrum One would keep processing normally during such a suspension. However, unconfirmed messages sent from Arbitrum One to Ethereum—including withdrawals—would be placed on hold while the Council deploys a fix and restores settlement. The mere installation of the guard does not pause withdrawals on its own; any delay depends entirely on its conflict condition being triggered.

Related Reading

Ethereum is not instant, but collateral could make it feel that way

For builders waiting to activate new Stylus code, a timeline for reopening has not yet been set. The October 2 report and developer notice do not provide a specific date, stating instead that the Foundation will collaborate with the ArbitrumDAO to determine the schedule and method for restoring activations.

Leave a Reply

Your email address will not be published. Required fields are marked *