Arbitrum has temporarily halted new Stylus contract activations on Arbitrum One and Nova after AI-assisted development tools lowered the barrier to creating attacks against hand-crafted WebAssembly programs. The emergency measure prevents new Stylus contracts from being activated but does not stop existing contracts from operating or users from interacting with applications already deployed on the networks.
The Arbitrum Security Council completed the emergency action at 11:30 EST on Oct. 2, 2026. The response also introduced an additional safeguard for Arbitrum One’s one-step proof mechanism under BoLD, which is used to validate the chain’s state before it is settled to Ethereum.
The primary objective of the intervention is to prevent new hand-crafted WASM programs from entering the network while Arbitrum investigates vulnerabilities that could affect chain availability, without disrupting existing Stylus applications or Solidity-based development.
Stylus allows developers to build smart contracts as WebAssembly programs instead of using only the Ethereum Virtual Machine execution path. Most Stylus contracts pass through the platform’s compiler tooling, but the attack scenario identified by Arbitrum involved manually crafted WASM code capable of bypassing that toolchain.
According to the Foundation, AI-assisted tools have increased the ability to develop more sophisticated programs capable of producing unexpected behavior. The identified programs could potentially degrade network performance and affect other users. Arbitrum has not identified an attack that would enable the theft of user funds.
Existing Stylus Contracts Remain Active
The restriction is focused on activation rather than execution. Existing Stylus contracts will continue to run until their expiration, while users can continue making calls to them. Developers can also renew active contracts through the existing permissionless keepalive mechanism.
This distinction means applications already operating on Arbitrum are not being shut down because of the emergency measure. Their on-chain activity can continue even though new Stylus deployments cannot currently be activated.
The ArbOS 61 upgrade renewed every active Stylus contract on Arbitrum One, ensuring that none would expire before Aug. 20, 2027. However, reactivating a contract after expiration, or deploying an updated version that requires a new activation, remains subject to the pause.
Solidity development is unaffected. Developers can continue deploying and executing Solidity contracts through the EVM as usual.
Gas Configuration Makes New Activation Impractical
Arbitrum implemented the Stylus restriction through a configuration change rather than a new network software release. The Security Council called ArbOwner.setWasmActivationGas on each affected chain and set the activation requirement to 2^64 – 1.
The configuration effectively makes new Stylus activations economically impractical while leaving the underlying execution infrastructure and already-active contracts operational.
The approach allows Arbitrum to restrict the vulnerable entry point without requiring an ArbOS upgrade or separate external audit for the activation change. The activation mechanism itself remains available, but the required gas level places it beyond practical use.
Restoring normal Stylus activation will require another configuration decision. Arbitrum has not announced when that change will occur.
Additional Protection Added for BoLD
The emergency response also addressed Arbitrum One’s one-step proof system under BoLD. A new OspSoundnessGuard can receive two conflicting answers concerning the same step in an open challenge.
If the proof system accepts both answers, the guard can pause settlement between Arbitrum One and Ethereum. This would temporarily prevent the network from finalizing its state to Ethereum until the conflicting proof issue is resolved.
The safeguard has been designed with limited authority. A new PauseExecutor contract can pause the guard but does not have broader powers. The Foundation said the guard contracts underwent an external audit.
Arbitrum characterized the measure as precautionary. The Foundation has not indicated that the one-step proof issue was exploited against the production network.
Developers Face a Temporary Deployment Constraint
For developers, the immediate impact is concentrated on new Stylus activations. Existing Stylus contracts can continue running and can be renewed, while new versions that require activation must wait. EVM and Solidity applications remain unaffected.
The pause creates a temporary trade-off: developers must delay new Stylus deployments while Arbitrum investigates the attack surface, while users of existing applications can continue using active contracts without the emergency measure itself requiring withdrawals.
Arbitrum is expected to work with ArbitrumDAO on the timing and process for restoring Stylus activations. No end date has been announced, and the Foundation has not disclosed how many contracts or projects are directly affected.
The incident highlights a growing security challenge for blockchain development as AI-assisted programming tools make sophisticated attack construction more accessible. For Arbitrum, the response is narrowly focused on network availability and the integrity of its settlement process rather than evidence of a direct threat to user funds.
