Recently, the Layer2 sector has seen consecutive operational and security incidents: Blast has ceased operations, with TVL falling from $2 billion to $32 million; Arbitrum has urgently suspended the activation of new Stylus contracts to guard against AI-assisted attacks and potential DoS risks. L2 elimination and security governance have become focal points.
Blast Ceases Operations as TVL Falls from $2 Billion to $32 Million
Blast announced it would cease operations, marking a landmark event for the Layer2 sector. The material shows that its TVL fell from $2 billion to $32 million, a significant contraction. The event involves user asset withdrawals, the failure of the airdrop model, and a sharp drop in TVL, with a major impact on the Layer2 ecosystem and investor expectations. After Blast ceased operations, the progress of user asset withdrawals has become the primary concern, and changes in TVL have also become an important indicator for observing its ecosystem exit. Because the material does not disclose the specific reasons for ceasing operations or the timetable for asset withdrawals, the market still needs to wait for more follow-up information.
Airdrop Model Fails as L2 Elimination Accelerates
In the Blast incident, the failure of the airdrop model is listed as one of the key impacts. In the past, L2 projects often used airdrops and incentive programs to drive up TVL, but Blast's data, falling from $2 billion to $32 million, indicates that incentive-dependent growth is difficult to sustain over the long term. The material defines Blast's cessation of operations as a landmark event for the L2 sector and points out that L2 elimination is accelerating. For the Layer2 ecosystem, this means competition may shift from short-term data expansion to sustained operational capability, capital retention, and protection of user rights. Investor expectations will also adjust accordingly: TVL size can no longer alone represent a project's health, and whether a project can continue operating and properly handle user assets has become a more realistic standard for judgment.
Arbitrum Urgently Suspends Activation of New Stylus Contracts
Unlike Blast's cessation of operations, the leading L2 project Arbitrum is experiencing a security governance event. Arbitrum's Security Council urgently suspended the activation of new Stylus contracts to guard against AI-assisted attack risks. The material notes that this involves AI-assisted attacks and potential DoS risks and is a security governance event for a leading L2. The suspension of new Stylus contract activation means that related risk handling and restrictive measures have been initiated, and users need to pay attention to the scope of impact. As a leading L2, Arbitrum's Security Council action is drawing attention from ecosystem participants, and the duration of the subsequent restrictions and conditions for resumption will affect the market's assessment of L2 security governance capabilities.
AI-Assisted Attacks and DoS Risks Enter L2 Security Spotlight
Arbitrum's restriction on the activation of new Stylus contracts directly points to AI-assisted attacks and potential DoS risks. The material does not disclose further attack details, but the Security Council's emergency action itself indicates that the related risks need to be prioritized. For the L2 ecosystem, AI-assisted attacks mean security threats may become more automated, while DoS risks may put pressure on service availability. Such security governance events not only affect user confidence but also influence the market's judgment of L2 security models. Going forward, attention needs to be paid to how long the restrictive measures last, when activation of new Stylus contracts will resume, and whether the Security Council discloses more information on the scope of impact. This information will determine whether the event is a localized security restriction or evolves into a broader L2 security issue.
L2 Sector Faces Dual Test of Operations and Security
Observing the Blast and Arbitrum events together, the Layer2 sector currently faces two types of pressure: first, pressure on projects' continued operations and TVL retention; second, pressure on contract security and risk response. Blast's cessation of operations, with TVL falling from $2 billion to $32 million, shows that L2 elimination is accelerating; Arbitrum's urgent restriction on new Stylus contract activation shows that leading L2s also need to address AI-assisted attacks and potential DoS risks. Both events point to one change: L2 competition is no longer just about attracting liquidity and users, but also about proving asset security, operational sustainability, and governance response capabilities. For investors and users, focusing on project fundamentals, asset withdrawal channels, and security governance progress is more important than simply chasing airdrops and TVL data. It should be noted that the Blast and Arbitrum events are different in nature—the former is a project ceasing operations, while the latter is a security restriction measure—and the two should not simply be seen as caused by the same reason; however, both reflect that risks in the Layer2 sector are being repriced.
What to Watch Next: Asset Withdrawals, Security Restrictions, and Scope of User Impact
Future market focus areas include: progress on user asset withdrawals after Blast's cessation of operations, whether TVL continues to change, and the impact of the failed airdrop model on incentive design for L2 projects; the duration of Arbitrum's restriction on new Stylus contract activation, the outcome of handling AI-assisted attacks and DoS risks, and the scope of impact on users and ecosystem participants. In addition, whether L2 elimination continues to accelerate and whether security governance events increase will also become important observation points for judging the direction of the Layer2 sector. What can currently be confirmed is that the Blast and Arbitrum events have brought both L2 operational risks and security risks into public view at the same time, and the market's evaluation of Layer2 projects will place greater emphasis on continued operations, asset security, and governance capabilities.


