Conclusion First: The Off Switch Was a Config Value
On 2 October 2026 the Arbitrum Security Council executed an emergency upgrade, completed at 11:30 EST, that bundled two actions, and the action that turned Stylus off was not a code release. It was a configuration value. Action A placed a guard on the one-step proof for BoLD, the mechanism that lets Arbitrum One settle to Ethereum, and gave a new pause contract the power to halt that settlement. Action B paused activation of new Stylus contracts on Arbitrum One and Arbitrum Nova by raising a single gas parameter. The first shipped audited contracts and a new role. The second shipped nothing but a number. The Foundation states plainly that no user funds were at risk.

What Happened, in the Order It Happened
An emergency action reads best as a sequence, because the order of events tells you what was decided privately before anyone was told publicly. This upgrade went out over a single afternoon.
| Time (UTC) | What happened | Where it is written down |
|---|---|---|
| 2026-08-20 17:00 | ArbOS 61 activated on Arbitrum One and Nova, and it renewed every active Stylus contract. | Constitutional onchain vote and Arbitrum documentation. |
| 2026-10-02 | The Foundation notified the Security Council of a potential emergency action. | Forum post, Security Council Emergency Action – 2/10/2026. |
| 2026-10-02 15:30/15:31 | Execution completed at 11:30 EST, and the report was published on the Arbitrum governance forum. | Forum post, published 2026-10-02T15:31Z. |
| 2026-10-02 | The documentation notice Temporary pause on new Stylus activations went up, plus a banner telling builders to reactivate their Stylus contracts. | Arbitrum documentation notice. |
| 2026-10-02 to 2026-10-03 | ARB daily closes moved from $0.2030 on 2026-10-01 to $0.1997 and then $0.1959. | CoinGecko daily closes. |
| 2026-10-04 | The pause is still in effect, with no published reopening date. | Arbitrum documentation notice. |
Two of those rows repay a second read. The forum report carries the Foundation’s account of why the council moved, and the documentation notice is what builders were pointed at when their activations stopped working.
Switch One: A Guard That Can Freeze Settlement
The first switch is not a pause on Arbitrum One. It is a pause on the chain’s exit to Ethereum. The L1UpgradeExecutor gave a new pause contract, the PauseExecutor, the ability to pause and nothing else. That contract then granted the guard, the OspSoundnessGuard, the PAUSER_ROLE. Anyone can hand the guard two conflicting answers to the same step of an open challenge, and if the one-step proof accepts both, the guard has the pause contract put Arbitrum One’s settlement to Ethereum on hold.
The cost of that is the thing to price, and it is an availability cost, not a correctness fix. When the guard trips, Arbitrum One keeps processing as normal. What stops is the exit: messages from Arbitrum One to Ethereum that are not yet confirmed, which is to say withdrawals, must wait. The Foundation calls this a precautionary response to the rise of AI-assisted attacks, a way to halt a detectable class of attacks that exploit a bug in the one-step proof. An external audit covered the OSP Guard contracts.
Canal engineers learned this trade long before blockchains existed. A pound lock is a single gate that can hold a queue of barges to protect everything downstream, and its cost never shows up as a failed gate. It shows up as waiting tonnage. The guard is the same instrument: not a repair of the proof, but a brake on the settlement the proof protects, and its availability bill is paid in stuck withdrawals rather than downtime.
Switch Two: A Gas Value With the Power of an Off Switch
The second switch is smaller and stranger. Stylus runs WebAssembly programs on Arbitrum and supports Rust, C and C++. Unlike an EVM contract, a Stylus contract has a two-step lifecycle, and the two steps are the whole reason a number can behave like a power switch. Deployment stores the compressed WASM bytecode onchain at a contract address, and that is all it does; the code is present but inert. Activation is the second step, and it converts that bytecode into an executable Stylus program by registering it with the ArbWasm precompile at address 0x71.
In order, the lifecycle looks like this.
- Compile the contract to WebAssembly, the format Stylus executes.
- Deploy the compressed WASM bytecode, which stores it onchain without making it callable.
- Pay the activation data fee, separate from EVM deployment gas, which can be bumped with a default safety margin of 20 percent.
- Register the program with the ArbWasm precompile at 0x71, which turns the stored bytecode into a callable Stylus program.
- Call the program, remembering that a shared codehash lets a second copy deploy without activating again.
The parameter the council pulled is documented in the official precompile reference. setWasmActivationGas takes a uint64 and sets the constant gas charge applied before each Stylus contract activation. It can be raised to deter denial of service through activations, or set to a value exceeding the block gas limit to block all activation. The council set it to 2^64 – 1, the unsigned 64-bit maximum, a value no block can ever pay, and the call came from the ArbOwner precompile at 0x70, which only the chain owner can call.
The same configuration surface carries other tunables. The decompressed WASM size limit, MaxWasmSize, defaults to 128 KB and was raised to 256 KB at ArbOS 61 and later.
“AI-assisted tooling has led to an increasing number of sophisticated attacks on hand-crafted WASM programs that do not use the standard Stylus compiler toolchain.”
The Arbitrum Foundation, Security Council Emergency Action, 2 October 2026

The Foundation calls the Stylus action a configuration change that does not require an ArbOS upgrade. It also says no audit was required for the deactivation, because the change only updated a single parameter in the ArbOS configuration. It does not remove a feature; it prices the feature out of reach, the way a toll authority works when it would rather nobody drove the road for a while. It is not a deletion, it is a surcharge set past the ceiling, and that is why turning it back on is a matter of writing a smaller number.
What Stayed On: The Availability Ledger
The dangerous word in an emergency notice is the verb. Paused sounds total, and it is not. Read what the documentation lists as unchanged, and the pause shrinks to one step of a longer life.
| Actor | What changed for them | What still works |
|---|---|---|
| Existing users of an activated contract | Nothing changes at the call site, though the contract keeps its own expiry clock. | Calling an activated Stylus contract stays permissionless, and EVM behavior is untouched. |
| Developers with a deployed but not yet activated contract | They cannot activate it now, because the activation gas requirement is out of reach. | The bytecode still sits onchain at its address, and a shared codehash may already be activated elsewhere. |
| Developers maintaining an active contract | Nothing breaks today, but the expiry timer keeps running against them. | They can renew before expiry through keepalive, and by default the contract must be at least 31 days old. |
| Solidity and EVM developers | Nothing changed for them at all, and the pause never touched their path. | Deployment and execution of Solidity and EVM contracts are unaffected. |
| Chain owners running their own Arbitrum chain | The parameter is theirs to set, because the pause is a chain-owner action. | They can leave activation gas at its default of zero or raise it for their own chain. |

Notice what the ledger refuses to hide: an expired contract cannot be reactivated either, so the group that loses is the group standing at the door when it closed. A narrow pause is still a pause.
The Two Clocks, and What the Second One Measures
Stylus activation does not last forever. The default activation lifetime is 365 days, programTimeLeft returns the seconds until expiry, and keepalive is the payable path that resets the timer. By default a contract must be at least 31 days old before keepalive will renew it. Two clocks, one counting down and one holding the door.
Now do the sum the documentation hands you. ArbOS 61, named Elara, activated on Arbitrum One and Nova on 20 August 2026 at 17:00 UTC, and it renewed every active contract on Arbitrum One. Renewal adds the default lifetime, so 20 August 2026 plus 365 days lands on 20 August 2027. That is why the forwarding statement holds: no currently active contract on Arbitrum One expires before 2027-08-20.
The second clock is the one people misread. A 31-day minimum age before keepalive is not a safety mechanism and not a bug; it is a rationing rule for the renewal payment. It measures how long a program must exist before its owner may renew it, setting a floor on how often the extension fee can be paid. One clock tells you when the program dies. The other tells you when you are permitted to keep it alive, and it is the second clock that decides who is holding the timer.
What You Cannot Check From the Outside
Split the record into two columns, the part you can read off the chain and the part you take on a report’s word. On chain, the Arbitrum One transaction 0x9eb3a4be3ba777f9fc82250eddc10f8356731cc97c09a70801d30ce33322c652 succeeded in block 511,026,298. It is a Safe execTransaction from 0xa4b1cd457e5635b64ebc8c5be3a1ca7543f7984d to 0x423552c0f05baccac5bfa91c6dcf1dc53a0a1641. The inner calldata is a 32-byte value that is all zeroes except for the final eight bytes, 0xffffffffffffffff, the unsigned 64-bit maximum. One of the four logs is an OwnerActs event from the ArbOwner precompile at 0x70, the chain-owner precompile.
The first claim you cannot verify from those bytes is the AI attribution. The report blames AI-assisted tooling, and that is a statement about who wrote an attack. The four-byte selector of the inner call, 0xa0a32497, is not present in the public 4byte signature directory, so the method name setWasmActivationGas reaches you from the Foundation’s report and the precompile reference, not from a signature lookup. What an independent reader can check is the eight-byte value in the calldata.
The second claim is the reassurance that this was a liveness problem and not a money problem.
“To date, all Stylus findings from contracts that have been reviewed have only posed a denial-of-service risk to chain liveness and no user funds have been at risk.”
Arbitrum documentation, Temporary pause on new Stylus activations
Read that sentence for what it is. It is a claim drawn from reviewed contracts, and it is exactly as strong as the review behind it. Nothing on chain can confirm the absence of a fund-stealing bug, and the report’s own hedge, that the pause is precautionary, says the same.
The third claim is the market reaction, and a daily close is a poor witness. CoinGecko daily closes put ARB at $0.2030 on 2026-10-01, $0.1997 on 2026-10-02 and $0.1959 on 2026-10-03, a single-day move of about 1.6% from the first close to the second and roughly 3.5 percent across the two days. A widely circulated 6.5 percent figure could not be reproduced from those daily closes.
For scale, ARB traded at $0.204293 with a market capitalisation of about $1.386 billion and a market-cap rank of 69 on 2026-10-05, against an all-time high of $2.39, which that day’s price sits about 91.45 percent below. The same method would have told a tidy story about a finality upgrade on another chain, and a tidy story is not a measurement. The pause is one input into that price, and a daily close cannot tell you how much of the move it caused.
The Engineering Reading
Here is what this event is actually about. A live chain kept its one dominant off switch cheap, a gas value, and paid for the second switch, the settlement guard, in contracts and an audit. The cheap switch is the one worth studying, because a parameter that can disable a runtime without a release means the runtime’s availability rests on a role, not on a review. That is the debt worth naming: a two-step lifecycle and an activation timer are things you inherit, not bugs you fix. Every new runtime is a second-gate bill, and the gates run in order. Business functions come first, business performance second, business intelligence third, and most teams never clear the second one.

Ask the same five questions about any runtime in your own stack.
- What is your off switch, and is it a release or a value?
- Who holds the role that can flip it, and can that person be paged at 3am?
- When the switch is thrown, what keeps serving and what merely stops being created?
- When does the default the switch leans on expire on its own, and who owns the renewal?
- Which parts of this are on chain and which are a claim you have chosen to believe?
The lineage question runs underneath all five. Stylus came from a real hole: the EVM is expensive and awkward for work that wants general-purpose languages, so a WebAssembly runtime promised cheaper compute for Rust, C and C++ teams. It filled that hole and dug a new one, a runtime whose growth depends on an activation gate that one owner address can price out of existence. That is not a flaw in Stylus. It is the cost of admission to any runtime bolted onto a chain it does not control.
The trade-off this reading accepts is blunt. A configuration value that can switch off a runtime is worth having, because it is the emergency response that does not wait on a code release at three in the morning. A system with a cheap, reversible off switch and a named owner beats a system with no switch and a promise that it will never be needed.
The limit of the reading is equally plain. This review prices the two switches and the availability ledger, and it says nothing about which action was correct, because correctness depends on information no outsider holds: the unreviewed hand-crafted programs, the reviewed bugs, and the attacks the Foundation says are rising. From the outside you can read a block, a parameter and a daily close. You cannot read intent. That is the edge of what an outsider can check, and it is the right place to stop.






