Ethereum developers have locked in Oct. 6 for the public Sepolia test of the network’s upcoming Glamsterdam upgrade, while warning that attackers using fake builder identities could disrupt the exercise by winning block auctions and withholding transaction payloads.
Developers said the attack would not threaten funds on Ethereum mainnet. The risk is limited to Sepolia, where test ether has no meaningful cost. Even so, blocks could be left without transaction payloads, disrupting the infrastructure testing needed before Glamsterdam can move toward Ethereum itself.
The Oct. 6 event is the public dress rehearsal for Glamsterdam. The final upgrade will only move ahead once developers are satisfied that the changes work safely.
Developers say disposable builders could keep winning and then disappear
During Thursday’s core developer call, Ethereum consensus developer Potuz described how easy the attack could be on a free test network.
Potuz said, “I can just spin up a thousand builders, rotate them, offer very high bids, and not produce payloads. Any teenager can do this.”
The concern is that someone with free test ether and a set of fake or disposable builder accounts could repeatedly win Ethereum’s auctions for the next block. After that, the operator could simply stop short of revealing the underlying transaction data, effectively freezing traffic on the chain.
That matters because stalled traffic would make it much harder for developers to test how the upgrade behaves under real-world conditions.
What Glamsterdam is meant to change
Glamsterdam is Ethereum’s next major upgrade. It is designed to fit more activity into each block without overwhelming the computers that verify those blocks.
Alongside changes to gas pricing, the upgrade is intended to support a block gas limit of about 200 million, creating more room for payments and trades before users start bidding fees higher.
The upgrade also moves the relationship between validators and specialized block builders into Ethereum’s protocol. Builders assemble transaction blocks and compete to supply them. Once a validator accepts the winning bid, the builder is expected to reveal the transactions underneath.
On a free test network, developers said, that process becomes easier to abuse. A malicious operator can bid far above legitimate builders, win again and again, and then withhold the promised payload.
Current safeguards react only after several payloads go missing
Developers said existing protections usually fall back to locally built blocks only after several payloads fail to arrive.
Potuz added that clients also need a way to identify and reject individual builders. Without that, an attacker could return under a new identity and continue winning auctions.
The warning came one day after a large private rehearsal completed the Glamsterdam transition and pushed the block gas limit toward 200 million without losing finality.
Client teams have only seven days before the Sepolia fork
Client teams now have until Sept. 29 to release software that is ready for Sepolia.
That leaves seven days before the Oct. 6 fork. Ethereum’s normal upgrade process usually reserves 14 days for security reviews and bug-bounty testing, so this window is half the usual length.
Developers accepted the tighter schedule because Sepolia is relatively centralized and easier to recover if something breaks.
Hoodi is tentatively set for Oct. 27, while mainnet remains unscheduled
Production builder software run by the Titan and Ultrasound teams has not yet completed a Glamsterdam fork transition. That leaves another gap before the upgrade can be treated as ready for mainnet.
The next public test on Hoodi is tentatively planned for Oct. 27. Developers will decide whether to keep that date after seeing how Sepolia performs. A mainnet activation date has not been scheduled.

