Arbitrum Pauses New Stylus Activations Over AI-Built WASM Risk

Arbitrum has stopped letting developers switch on new Stylus contracts. The chain's Security Council made the change on Friday, blocking fresh activations on both Arbitrum One and Arbitrum Nova, and gave its reason as AI-assisted attacks built on hand-crafted WebAssembly code. Nothing was stolen. The council said no attack it found could take user funds, and put the risk instead on denial of service against the chain's ability to keep producing blocks. No date was given for turning activations back on.
What Stylus is and what activation means
Stylus is Arbitrum's second contract environment, alongside ordinary Solidity. Developers write in Rust or C++, the code compiles to WebAssembly, and the compiled program then has to be activated before it can run, a step separate from deploying it to the chain. That separation is what made the pause possible without touching anything already live. Deployment still works. It is the activation step that is closed.
A gas price nobody can pay
The council did not ship a protocol upgrade. It raised the gas required to activate a Stylus program to a level no one would pay, through a configuration change that needs no ArbOS release and can be undone the same way. CryptoSlate and the Cryptonomist both describe that level as prohibitive; the ChainCatcher account carried by KuCoin puts it at the theoretical maximum. Those are two descriptions of one setting, and no account read here gives the number.
What the pause targets is narrower than Stylus as a whole. The council's wording, as CryptoSlate rendered it, points at hand-crafted WebAssembly programs written outside the standard Stylus compiler toolchain. Programs that went through that toolchain are not the stated concern.
The council said "no attack permitting theft of user funds had been discovered," in wording CryptoSlate and the Cryptonomist carried identically on Saturday.
What keeps running
Stylus programs already activated continue to execute until they expire, and the permissionless keepalive renewal that extends a program's life is still open, so a live application is not on a clock it cannot reset. Solidity contracts deploy and execute untouched. Both chains keep processing. CryptoSlate is the only account read here to spell out the full scope of what is blocked: new programs, updates that require reactivation, and expired programs being brought back.
A second guard, pointed at withdrawals
The same emergency action added something to BoLD, the dispute-resolution system Arbitrum One uses to settle back to Ethereum. The guard watches one-step proofs, the smallest unit a dispute can be narrowed down to. If two conflicting answers are both accepted at that step, settlement to Ethereum halts, which delays withdrawals that have not yet confirmed while the chain itself carries on. Crypto Briefing describes the guard as permissionless and as protection against soundness problems. No account read here says such a conflict has occurred.
Reopening is a DAO question
The Arbitrum Foundation will coordinate with ArbitrumDAO on when new activations resume, and three accounts say the same thing about the timing: there is none. The council's own report was not read directly here, so every detail above arrives through outlets, and the two timestamps they give for the action, 11:30 a.m. Eastern on Friday in Crypto Briefing and around 23:30 Beijing time in PANews, are one moment described twice. What nothing establishes is scale. How many Stylus programs are active, what they hold, and whether any hand-crafted WebAssembly program was ever found on either chain are all unanswered in the accounts read here. AI-assisted bug hunting reached other protocols earlier this year, including Core Lightning's confirmation of AI-found bugs in August, and Arbitrum's own traffic has been climbing on the back of Robinhood Chain's fee share. A liveness risk on a chain carrying that volume is the thing the council moved on.
Read also: Taiko Halts Its Ethereum Layer-2 After a $1.7M Bridge Exploit