Arbitrum’s Security Council temporarily stopped new Stylus contract activations on Arbitrum One and Nova on October 2, responding to unresolved denial-of-service risks involving specially constructed WebAssembly programs. The emergency action also installed a safeguard capable of pausing Arbitrum One’s settlement to Ethereum if its dispute system accepts contradictory proofs.
The council reported completing the changes at 11:30 a.m. Eastern on October 2. Linked Ethereum, Arbitrum One and Nova transaction records show successful executions at approximately 15:30–15:31 UTC that day.
The action restricts developers from making newly compiled Stylus programs callable, including application upgrades that require a fresh activation. It does not deactivate existing Stylus programs, stop ordinary Solidity contracts or establish that Arbitrum One itself has halted.
Stylus activation is paused, not execution
Stylus lets developers write Arbitrum smart contracts in languages that compile to WebAssembly, or WASM. Deploying one of those programs stores its code onchain, but a separate activation step prepares the code for execution. The council effectively disabled that step by setting the required activation gas to the maximum value representable by the relevant configuration parameter.
Consequently, developers cannot activate a new program, reactivate one that has expired or introduce a version that requires another activation. Programs already activated remain callable until expiration, and their developers can still extend their active period through the permissionless keepalive mechanism.
Arbitrum said an earlier ArbOS 61 upgrade renewed active programs on Arbitrum One, leaving none scheduled to expire before August 20, 2027. The date describes the current activation schedule reported by the council; it does not guarantee uninterrupted execution or eliminate risks unrelated to this measure.
The Foundation attributed its decision to increasingly sophisticated testing and attacks using hand-crafted WASM programs outside the standard Stylus compiler toolchain. It said reviewed findings could degrade network performance or availability. That explanation identifies the risk category, but the public notice does not disclose the underlying vulnerabilities, reproduction steps, affected code paths or a timetable for complete remediation.
Arbitrum’s documentation says the reviewed Stylus findings posed denial-of-service risks rather than risks to user funds. That is the project’s assessment, not an independent guarantee that every undisclosed vulnerability or deployed application is safe. No theft amount or affected-wallet count was disclosed in connection with the October 2 action.
A separate guard protects Ethereum settlement
The same emergency payload added a guard around the One-Step Proof component of BoLD, Arbitrum’s dispute mechanism. Anyone can invoke the guard by presenting two conflicting answers for the same step of an open challenge if the proof system accepts both when only one should be valid.
If that condition occurs, the guard can use a narrowly authorized pause contract to suspend Arbitrum One’s settlement to Ethereum. Arbitrum One would continue processing transactions, according to the council, but messages awaiting Ethereum confirmation—including withdrawals—would have to wait while the Security Council deployed a fix and resumed settlement.
Installing the guard did not itself pause withdrawals. It created a conditional circuit breaker for a publicly detectable proof failure. The official record says the guard contracts received an external audit, although the audit report and its testing scope were not linked in the disclosure.
Reopening remains unresolved
The two changes address different failure modes: the Stylus restriction reduces exposure to newly activated WASM programs, while the BoLD guard limits the consequences of contradictory one-step proofs. Neither establishes that an attack occurred, that settlement has been paused or that existing Stylus applications are vulnerability-free.
The Arbitrum Foundation said it would work with ArbitrumDAO on the conditions and timing for restoring activations. As of the October 3 publication cutoff, the official records supplied no reopening date. Developers can continue deploying and running Solidity contracts and using already-active Stylus code, but projects requiring a new Stylus activation remain blocked until another governance or emergency action changes the configuration.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

