Key Highlights:
- The Arbitrum Security Council enacted an emergency pause on new Stylus contract activations across Arbitrum One and Arbitrum Nova on October 2.
- The preventive action addresses potential chain liveness threats posed by hand-crafted WebAssembly (WASM) programs, with no user funds currently at risk.
- Standard Ethereum Virtual Machine (EVM) and Solidity operations remain completely unaffected, and active Stylus contracts continue running normally.
Arbitrum Security Council Intervenes to Protect Network Stability
In an emergency intervention on October 2, the Arbitrum Security Council temporarily paused new Stylus contract activations across both Arbitrum One and Arbitrum Nova. According to an official notice published by the Arbitrum Foundation, the decision serves as a proactive security safeguard against hand-crafted WebAssembly programs capable of disrupting blockchain liveness.
Stylus, which made its debut in September 2024, is an execution environment designed to broaden the scope of decentralized application development. It allows programmers to write Ethereum-compatible smart contracts using languages such as Rust, which compile into WebAssembly (WASM). While Stylus offers network operators the ability to customize ecosystems and provides developers with tools to optimize performance-critical programs, unexpected risks related to custom WASM execution prompted rapid mitigation from ecosystem administrators.
Scope of the Stylus Contract Freeze
The administrative pause is specifically isolated to the activation process, which is the final step required to make a deployed Stylus contract callable and executable. Under this temporary restriction, software developers are prevented from activating newly deployed Stylus contracts or reactivating those that have lapsed. Consequently, the operational freeze halts the deployment of new Stylus-based applications as well as protocol upgrades relying on the framework.
Despite the freeze on new activations, active Stylus deployments remain unaffected. Existing contracts will continue to operate normally until their scheduled expiration dates. Within the Stylus framework, contract activations persist for a default duration of 365 days, and routine keepalive renewals remain fully permissionless. Crucially, the issue does not extend to traditional Ethereum Virtual Machine (EVM) architecture; the deployment, execution, and interaction of standard Solidity smart contracts continue without any interruption across both Arbitrum networks.
Denial-of-Service Concerns and Network Safety
The technical concern identified by the Arbitrum Foundation stems from hand-crafted WASM programs that could potentially trigger denial-of-service conditions and compromise the liveness of the chains. Maintaining network liveness ensures that transaction validation and block progression proceed without stalling or unexpected halts.
The Arbitrum Foundation’s published advisory clarified that the vulnerability profiles identified thus far are restricted to network availability. To date, all findings reviewed in connection with Stylus contracts have solely posed risks to liveness, and user funds have remained entirely secure throughout the incident.
Why This Matters
The swift action taken by the Arbitrum Security Council underscores the complex trade-offs inherent in expanding Ethereum Layer 2 environments beyond traditional EVM constraints. Introducing multi-language capabilities via WebAssembly significantly increases efficiency and broadens the developer talent pool to include Rust engineers, but it also expands the surface area for novel execution vectors.
Because the Security Council’s intervention targets chain liveness before malicious exploits could lead to downtime, Arbitrum avoided disruption to its broader DeFi and consumer ecosystems. The incident highlights the role of decentralized governance safeguards in mitigating early-stage infrastructure vulnerabilities while maintaining core Layer 2 operations without risking user capital.
Frequently Asked Questions
Are user funds or existing assets on Arbitrum at risk?
No. According to the Arbitrum Foundation, no user funds have been placed at risk. All reviewed vulnerabilities and technical findings regarding Stylus contracts are limited strictly to chain liveness risks.
Can developers still deploy standard Solidity and EVM smart contracts?
Yes. The temporary pause is exclusively confined to Stylus contract activations. Standard EVM operations, including the deployment and execution of Solidity-based contracts, remain completely functional across Arbitrum One and Arbitrum Nova.
What happens to Stylus smart contracts that are already live?
Previously activated Stylus contracts continue to execute and run normally until they reach their expiration period. Activation defaults to 365 days, and permissionless keepalive renewals are still active for existing deployments.




