News · News

Arbitrum pauses Stylus activation without disclosing specific risks

Arbitrum's Security Council paused Stylus activation and installed a One-Step Proof guard for BoLD due to undisclosed "known risks," setting activation cost prohibitively high.

Arbitrum pauses Stylus activation without disclosing specific risks

Arbitrum’s Security Council executed an emergency action at 11:30 EST on October 2, installing a One-Step Proof guard for BoLD and preventing new Stylus contracts from being activated. The Arbitrum Foundation Forum notice cites known risks involving BoLD and Stylus, including concerns about AI-assisted attacks. The OSP Guard can pause settlement when conflicting answers pass at the same level — a condition where only one answer should be valid.

Developers cannot activate new Stylus contracts or qualifying upgrades, while existing contracts continue to execute. Users and protocol teams are left guessing.

The BoLD-side measure is a One-Step Proof Guard. Per the forum notice, it allows anyone to pause settlement of Arbitrum One on EETH$2,664.99▼1.25% if at least two conflicting answers pass at the same level when only one answer should be valid.

The action blocks new Stylus activations. The council calledArbOwner.setWasmActivationGas(2^64 - 1), setting activation cost high enough to be prohibitive. New Stylus contracts can’t be activated — including new versions of existing applications that require an activation step to ship.

Existing Stylus contracts keep running. ArbOS 61 renewed all active contracts on Arbitrum One, and none of them expires before August 20, 2027. From October 2, 2026, that’s 322 days out. Solidity and EVM contract deployment and execution are untouched by this action.

Teams deploying fresh Stylus code, or shipping upgrades requiring activation, are blocked. Users of already-active Stylus contracts retain execution through the stated expiration schedule.

The forum post does note that an external audit was conducted for the OSP Guard contracts, and that no audit was required for the Stylus deactivation since that step was a configuration change. Those are process assurances about the response itself — they say nothing about what triggered it.

Compare this to April 20, when the Security Council froze 30,766 ETH tied to the KelpDAO exploit, according to Crypto Briefing. That exploit had drained approximately $292 million on April 18; the emergency action at the time identified the affected funds and the exploit context clearly. The October notice identifies which systems were changed. The “known risks” that made those changes necessary remain undisclosed.

arbitrum bold kelpdao stylus
Nadia Rahman

Nadia Rahman

Markets Editor · 9 years covering crypto · Author page

Nadia Rahman is CoinScoop's Markets Editor. She covers Bitcoin, macro liquidity and the spot-ETF complex, and previously reported on rates and FX for a global newswire.

Disclosure: This article is independent journalism and is for information only — it is not financial advice. CoinScoop is reader-supported and may earn a commission from some links. Read our disclosure policy →