Arbitrum pauses new Stylus activations over AI-assisted attack risks

Existing programs keep running, while a separate proof-conflict guard can delay unconfirmed withdrawals to Ethereum. The post Arbitrum pauses new Stylus activations over AI-assisted attack risks appeared first on CryptoSlate.

Arbitrum pauses new Stylus activations over AI-assisted attack risks

Arbitrum's Security Council temporarily blocked new Stylus contract activations on Arbitrum One and Nova in an October 2 emergency action, restricting programs and app updates that require fresh activation. Already-active Stylus applications can keep running, while ordinary Solidity contract deployment and execution remain unaffected, according to the Council's action report.

Arbitrum attributed the precaution to increasingly sophisticated AI-assisted attacks involving hand-crafted WebAssembly programs outside the standard Stylus compiler toolchain. It said known Stylus bugs primarily threaten chain liveness, including denial-of-service risks, and that no attack permitting theft of user funds had been discovered.

Related Reading

The linked Ethereum, Arbitrum One and Nova transaction records show successful execution on October 2, around 15:30 to 15:31 UTC.

For builders, the distinction is between storing code and making it usable. Stylus contracts run WebAssembly programs, which need activation to become executable. Arbitrum's documentation distinguishes that step from deployment, which stores code onchain. New contract instances using identical program code can reuse an existing activation, provided it is still valid.

A new application version requiring fresh activation cannot become executable during the pause. Reactivating an expired program, or one needing reactivation after a Stylus version change, is also blocked, the Council said. The scope is activation, rather than a blanket prohibition on deploying every new contract instance.

Existing programs remain callable until expiration. Developers can continue extending an active program's lifetime through the permissionless keepalive renewal mechanism before it expires, according to the official pause notice. This leaves renewal available while reactivation of an already-expired program is blocked.

Originally published by cryptoslate Aggregated for informational purposes. All rights belong to the original publisher.
← Back to all news

Be the first to know

Get deep dives, analysis and updates delivered straight to your inbox.