Hi everyone,
We are closing out the Stylus Manager - Caching, Activating, and Tracking Stylus Contracts grant, funded through the Developer Tooling domain. All five milestones are delivered, and the platform is live on Arbitrum One, so this post consolidates the grant in one place: what we built, how we validated and audited it, where everything is deployed, and every link a reviewer or developer might need.
Thanks to the domain allocators and to everyone in the Stylus community who gave us feedback along the way.
1. Overview
Stylus programs stop being callable if you don’t reactivate them periodically. The failure is silent: the contract stays on chain, but every call reverts until someone calls activateProgram and pays for it again. Before this grant, there was no status indicator, no alert, and no way to automate it.
This grant extended the Stylus Cache Manager, which we built under the Stylus Sprint, into the Stylus Manager: one open-source platform to keep Stylus contracts cached, active, and monitored. Activation lives where caching already lived, inside each contract, so wherever you can cache a contract, you can now activate it.
The Stylus Manager is live on Arbitrum One at stylus.cobuilders.xyz, the same URL as the original Cache Manager. Cyfrin audited the automation contract, and the remediated CacheManagerAutomation v2.0.0 is the version running on mainnet.
2. Milestones delivered
| Milestone | Scope | Amount | Submitted | Report |
|---|---|---|---|---|
| M1 | Planning & Design | 6,000 USD | Jun 3, 2026 | Report |
| M2 | Backend Development | 9,500 USD | Jun 12, 2026 | Report |
| M3 | Frontend Development | 9,500 USD | Jul 30, 2026 | Report |
| M4 | Enhancements, QA, User Testing & Bug Fixing | 6,000 USD | Aug 21, 2026 | Report |
| M5 | Final Deployment | 4,000 USD | Sep 14, 2026 | Report |
| Total | 35,000 USD |
- M1, Planning & Design. Development plan, architecture across contracts, backend and frontend, user stories, and an interactive V0 prototype.
- M2, Backend Development. Activation event capture, lifecycle alerts,
placeActivationsbatch automation in CacheManagerAutomation, CI on devnode with integration tests, OpenAPI docs, and a v1.1.0 staging deployment on Arbitrum Sepolia. - M3, Frontend Development. Rebrand to Stylus Manager, activation status in the contract tables, a full Activation tab in the contract view, activation at Add Contract, alerts UI, and a public staging URL.
- M4, QA, and hardening. Full-system testing, the Cyfrin audit with remediation delivered as v2.0.0, four frontend pull requests (design system, workflow rebalance, wallet network consistency, keyboard navigation and accessibility), and testing-driven fixes.
- M5, Final Deployment. Mainnet deployment of contracts, backend and frontend, refreshed documentation, and the educational content committed in the proposal.
Across the five milestones, the reports list 33 merged pull requests (plus one NGINX commit) in the frontend, backend, contracts, and deploy repositories.
3. What shipped
- Activation status everywhere. My Contracts and Explore Contracts show each contract’s activation status next to its cache status, with time remaining computed from the on-chain activation date and the network’s expiry parameter.
- Four lifecycle alerts. Approaching expiration (configurable threshold, 1 to 365 days), expired, reactivation succeeded, and reactivation failed, delivered through Telegram, Slack, and Webhooks, the same channels used for caching alerts.
- Manual activation. A direct wallet-signed call to
arbWasm.activateProgram, with the activation fee discovered by simulation. No backend in the loop. - Opt-in auto-activation. Per contract,
autoActivateplus amaxActivationCostcap. The automation contract draws only what is needed from the existing escrow, callsactivateProgramand refunds the excess. Off by default, with a global cap of 5 activations per iteration. - Activation at Add Contract. Adding an expired or never-activated program offers to activate it right there instead of failing later.
- Rebuilt UI. Responsive dark design system, consolidated alert management, wallet network consistency checks, and keyboard-first navigation with a global command palette.
- Caching untouched. Regression testing covered the existing caching functionality throughout.
4. Security
Cyfrin performed an external audit of CacheManagerAutomation. The audit surfaced no critical findings and no issues putting user funds at risk. Cyfrin addressed each finding individually, and the remediation shipped as v2.0.0: hardened two-step ownership transfers, escrow and automation-withdrawal separation, funding-limit enforcement, per-batch authorization deduplication, owner-parameter bounds, gas optimizations, and build hardening.
Cyfrin completed the remediation review; the remediation was merged (PR #22), and the final report is public in the repository:
- Cyfrin audit report, CacheManagerAutomation v2.0 (PDF)
- Result: 0 critical, 0 high, 0 medium, 8 low, 12 informational, 10 gas optimizations (README audits table)
5. Deployments
| Artifact | Network | Link |
|---|---|---|
| Stylus Manager (production) | Arbitrum One | stylus.cobuilders.xyz |
| CacheManagerAutomation v2.0.0 | Arbitrum One | 0x42affF7D0e6649fc006B5Dd9131373f869e622AF |
| CacheManagerAutomation v2.0.0 | Arbitrum Sepolia | 0x4f64b21496B319dCaef26EDd165cab3039f5aD86 |
| API docs (Swagger) | Production | stylus-nginx-production.up.railway.app/api |
The backend runs on the v2.0 ABI with the Activation module enabled and database migrations applied in production. The rebranded frontend is served at the same URL as the original Cache Manager.
6. Validation and testing
- Backend unit tests and backend to contracts integration tests on fresh Nitro devnodes.
- Contract tests: 73/73 deterministic, 28/28 CacheManager, and 29/29 CacheManagerAutomation on a fresh local Nitro environment.
- Playwright UI validation at desktop and mobile widths: overflow checks, modal lifecycle, keyboard navigation, and focus restoration.
- Structured user-testing sessions on the public staging deployment, triaged in Linear. The two highest-impact improvements were the Cache/Activation workflow rebalance (PR #87) and wallet network consistency enforcement (PR #88).
7. Documentation and educational content
The documentation site was refreshed for v2: rebrand, a What’s New in v2 page, UI tutorials for activation and auto-activation, and an Activation Lifecycle page in the Deep Dive section.
Educational content, each piece covering the concept, Cargo, a direct Hardhat call (with runnable example scripts), the platform, automation, and alerts:
8. Resources
- Live: stylus.cobuilders.xyz
- Docs: cobuilders-xyz.github.io/stylus-cm-deploy
- Repositories: stylus-cm-frontend, stylus-cm-backend, stylus-cm-contracts, stylus-cm-deploy
- Audit: Cyfrin report (PDF)
- Grant proposal: Questbook
- Community write-up: CoBuilders, Building on Arbitrum
The Stylus Manager is open source, and we keep maintaining it as infrastructure for Stylus developers. Thanks to the Arbitrum DAO Grants Program for supporting this work. Feedback and contributions are welcome on the repositories.