The Power to Pause
Arbitrum paused new Stylus activations while existing contracts kept running. ESMA set out how providers should exit non-compliant stablecoins. FinCEN withdrew two proposals. This week’s report examines what each intervention stops, who controls it and what continues.
Week in 60 Seconds
- Arbitrum: The Security Council paused new Stylus activations and added a separate safeguard for settlement to Ethereum. Existing contracts keep running. The Council says no Stylus attack discovered so far permits theft of user funds.
- ESMA: An 8 October opinion says authorised crypto providers should stop serving stablecoins that fail the EU's MiCA requirements. Existing exposure should be cleared within three months, and national supervisors may permit strictly limited exit services in the meantime.
- CrowdStrike: Publicly accessible folders on attacker-controlled servers revealed how an actor used AI security-testing tools against South Korean financial organisations. CrowdStrike names no group.
- NEAR Intents: The general manager says the roughly $3.8 million taken on 1 October was returned in full. That announcement does not establish that compensation has reached every affected user.
- FinCEN: Withdrawal of two crypto-related proposals was announced on 5 October and took effect on 6 October. The agency also withdrew the finding underlying its mixing proposal.
- Freeze Ledger: 47 freezes of $200K or more, worth $21.08M, with Thursday and Friday accounting for about four-fifths of the recorded value.
Arbitrum: Pausing New Stylus Activations, Guarding Settlement
On 2 October, Arbitrum's Security Council made two emergency changes. One limits which new contracts can go live. The other can delay settlement to Ethereum if a fault in Arbitrum's proof system is demonstrated.
The first change affects Stylus, one of the ways developers run smart contracts on Arbitrum. The Council made new activations prohibitively expensive on Arbitrum One and Nova by raising the required gas to its maximum setting. That stopped new activations without requiring a network software upgrade.
Already-active Stylus contracts keep running, and their renewals remain open to anyone. Contracts written in Solidity are unaffected. The report says an earlier upgrade renewed all active Stylus contracts on Arbitrum One through at least 20 August 2027. The pause does, however, prevent updated versions from being activated as new contracts.
The Foundation cited increasingly sophisticated, AI-assisted attacks using specially crafted WebAssembly programs, the format Stylus runs. These bypass the usual compiler tools and are designed to slow the chain for other users. The report identifies no specific attack or tool and says recent upgrades have patched several reported bugs. It says no Stylus attack discovered so far permits theft of user funds.
New Stylus activations are paused; the chain and its active contracts carry on.
The second change concerns BoLD, the system used to resolve disputes about Arbitrum's results. The new guard can be triggered by anyone, but only if they demonstrate that the proof system accepts two conflicting answers to the same step of a dispute. If that check succeeds, the guard pauses Arbitrum One's settlement to Ethereum. Its dedicated pause contract has no other power.
Arbitrum One would keep processing transactions; unconfirmed messages to Ethereum, including withdrawals, would wait. The report says the pause would give the Security Council time to deploy a fix. The Council describes the guard as a precaution against the growing risk of AI-assisted attacks. It says the guard contracts were externally audited but does not link the audit.
The Foundation says it will work with the ArbitrumDAO on when and how new Stylus activations resume.

ESMA: The Rule Reaches the Provider, Not the Chain
On 8 October, the European Securities and Markets Authority, ESMA, published an opinion on stablecoins that do not meet MiCA, the EU's crypto regulation. It addresses national supervisors and the authorised crypto businesses they oversee. It names no token and changes nothing on a blockchain.
ESMA says those businesses should not provide services for affected stablecoins to EU clients. Its list extends beyond buying and selling to custody, transfers, advice and portfolio management. The concern is that missing safeguards at the token's issuer cannot be repaired by the service provider. Warnings and client acknowledgements would not be enough.
For existing holdings, ESMA wants supervisors to require providers to resolve their non-compliant exposure as soon as possible, within three months of publication. That points to early January 2027. National authorities may permit strictly limited services to let clients sell, convert, transfer or withdraw existing holdings during the wind-down. They should not permit new purchases or promotion.
The opinion targets access through regulated providers. It does not freeze tokens on-chain.
This is a supervisory opinion, not new legislation. National authorities must decide how it applies to particular providers and tokens, including which exit services they permit.

CrowdStrike: What the Attacker Left in the Open
CrowdStrike Intelligence published an analysis on 7 October of a campaign against South Korean financial organisations. It says the campaign ran from late September to early October and resulted in stolen data.
The evidence came from publicly accessible folders on attacker-controlled servers. They contained Claude Code session histories and memory files, and configuration files for ARTEX, an open-source tool developed in China that uses AI to plan and carry out security testing.
CrowdStrike describes two servers: the attacker's main infrastructure in Hong Kong and a second server running ARTEX, which it considers likely responsible for the Korean attacks. The records show several language models being used, including DeepSeek, GLM and Grok. They also contain requests for help finding markets for stolen Korean data.
CrowdStrike describes an attacker directing AI tools, not a model acting alone. Its assessment is that the tools helped a financially motivated actor conduct several intrusions in a short time.
CrowdStrike has not named a group. Based on the tools and Chinese-language prompts, it assesses with moderate confidence that the actor is likely a Chinese speaker and financially motivated. Details about affected organisations come from press reports it cites, including a bank's loan-inquiry service and another bank's employee mobile work-support system. The number of affected organisations remains unconfirmed.
NEAR Intents: The Reported Return
On 2 October, NEAR Intents general manager Alex Shevchenko said the roughly $3.8 million taken the previous day had been returned in full. He said the team was stopping its investigation.
Decrypt reports that the exploit involved a bug in the connection between the service's deposit and withdrawal layer, Omni, and its main smart contract. NEAR Intents halted service, pledged to compensate users and reported the incident to law enforcement. Shevchenko told the attacker that the team had identified them and set a 48-hour deadline to return the funds.
Reporting on 1 October said the team had fixed the vulnerability and restored the service, and cited NEAR co-founder Illia Polosukhin as saying a few affected chains remained unavailable.
The Defiant reported that a published Bitcoin recovery wallet received about 34.59 BTC. That is one part of the reported recovery, rather than a complete account of all returned assets.
A reported return of funds does not establish that every affected user has been repaid. The recovery announcement did not itemise the full return or provide a completed compensation account.
CryptoTimes reported that Polosukhin credited SHIELD, the service's AI security layer, and investigative work with identifying the party responsible. He did not publish technical details of that process. The reporting reviewed does not establish that law enforcement identified the attacker or recovered the funds, and contains no technical post-mortem.
FinCEN: Two Proposals Withdrawn
On 5 October, the US Financial Crimes Enforcement Network, FinCEN, announced that it was withdrawing two crypto-related proposals. The formal withdrawals took effect on 6 October.
The first proposal would have required banks and money services businesses to collect, verify and report information about certain transactions involving unhosted wallets, meaning wallets people control themselves.
The second would have introduced additional recordkeeping and reporting for transactions involving international crypto mixing. FinCEN withdrew both that proposal and the finding that had designated this class of transactions a primary money-laundering concern.
These were proposed requirements being withdrawn, not existing rules being repealed. FinCEN cited public comments, the administration's deregulatory agenda and its aim to make digital-asset regulation fit for purpose.

Weekly Freeze Ledger
47 freezes • $21.08M frozen
The ledger covers Saturday 3 October through Friday 9 October 2026, counting issuer-enforced freezes of $200K or more across Ethereum, Tron and XRPL. Each row covers the 24 hours ending at 21:00 UTC on that date.
| Date | Freezes | Frozen |
|---|---|---|
| Sat 3 Oct | 0 | $0 |
| Sun 4 Oct | 1 | $406.2K |
| Mon 5 Oct | 5 | $2.52M |
| Tue 6 Oct | 1 | $223.9K |
| Wed 7 Oct | 3 | $1.03M |
| Thu 8 Oct | 13 | $5.40M |
| Fri 9 Oct | 24 | $11.50M |
| Weekly total | 47 | $21.08M |
Most of the week's recorded value fell on Thursday and Friday. Together they account for $16.90M, about 80 per cent of the total. Friday alone accounts for more than half, with 24 freezes worth $11.50M. The Friday digest lists twenty freezes at $500.0K and 22 of the 24 at the same 12:09 UTC timestamp. The Thursday and Friday digests identify all their entries as Tether USDT on Tron, without attributing them to a specific case.
Daily amounts are rounded as published in the digests; the weekly total sums those rounded figures.
These figures record freeze actions, rather than a reconciliation of funds still frozen or ultimately recovered.
Source: The Cipher Index Stablecoin Freeze Tracker
What to Watch
For Arbitrum, the next developments are a process and timeline for resuming Stylus activations, and any use of the settlement guard.
For ESMA, watch how national authorities apply the three-month period and which tokens and providers they consider affected.
Corrections and Continuing Investigations
NEAR Intents. The full return remains a statement by the service's leadership. The sources reviewed do not provide a complete reconciliation of recovered assets, a technical post-mortem or confirmation that all user compensation has been paid.
CrowdStrike. The number of affected organisations is unconfirmed. Victim details come from press reports cited by CrowdStrike.
Arbitrum. The Council's report does not link the guard-contract audit or the Stylus bug reports.
Further Reading
- The Recovery Economy, the previous Nexus Report, follows recovery after Bitget, Zano and Limit Break, and covers Base's Cobalt changes to transaction conditions and issuer powers.
- Arbitrum Security Council emergency action report, the Council's account of both changes.
- ESMA opinion on non-MiCA-compliant stablecoins, the full text.
- CrowdStrike's ARTEX analysis, including indicators security teams can use to investigate.
- FinCEN's withdrawal announcement, with links to the formal notices.
Published by the Zero Trust Network. Research supported by CipherBot and CipherIndex.


Discussion