Ethereum core developers picked Oct. 6 for the first public Sepolia test of the Glamsterdam upgrade, with Hoodi penciled in for Oct. 27. But the schedule came with a pretty stark warning: on a free testnet, an attacker using loads of fake identities and free Sepolia ETH could win block auctions by bidding aggressively, then just not reveal the transaction data. That could jam testing across the chain.
On Thursday’s core developer call, Ethereum consensus-layer developer Potuz put it bluntly: "I can spin up a thousand builders in an instant, rotate through them, post extremely high bids, and still produce no payload at all. Any teenager could do it." He said an attacker could launch thousands of builders almost immediately, cycle between them, bid absurdly high, and return no payload. His point was simple: this is easy.
Sepolia goes first, Hoodi remains tentative
Right now, the plan is for Sepolia to host the first public test on Oct. 6. Hoodi is tentatively next on Oct. 27, though developers said that date depends on what turns up on Sepolia. There is still no mainnet activation date.
What Glamsterdam is designed to change
Glamsterdam is Ethereum’s next major upgrade. The main target is to raise the amount of transaction activity each block can handle without adding to validator load. With changes to gas accounting, the block gas limit after the upgrade is expected to land at roughly 200 million. Put plainly, that should let the chain handle more payments and transactions before users start pushing fees higher.
The upgrade also puts the relationship between validators and block builders straight into the protocol layer. Builders put transaction blocks together and send bids to validators in an auction. Once a validator accepts the top bid, the winning builder has to reveal the full transaction data inside the block within the protocol’s time limit.
Why the builder model creates a Sepolia-specific weakness
On mainnet, this mechanism holds together because builders bid and post collateral with real ETH, and money keeps behavior in check. Sepolia is another story. Testnet ETH is free. Identities are cheap to create. So those economic checks vanish.
That creates an obvious attack path. A bad actor can keep submitting bids far above what legitimate builders offer, keep winning the right to supply blocks, and then withhold the payload. Existing protections usually fall back to a mode where validators build blocks themselves only after several payloads in a row fail to appear. That gap alone, developers said, may be enough to throw testing off course.
No threat to mainnet funds, but testing can still be disrupted
Developers kept stressing the same point: the risk is limited to the Sepolia testnet and does not touch Ethereum mainnet funds or transactions. Sepolia ETH has no real economic value, and there is no direct financial upside for an attacker who disrupts the testnet. Still, the attack is technically possible and cheap. That's the problem.
If missing payloads and block interruptions start showing up often during testing, developers may have a hard time figuring out whether they are seeing a real flaw in the upgrade or just sabotage from malicious builders. And that would slow Glamsterdam testing directly, while making it tougher for teams to finish the infrastructure checks they need in the time they have.
Potuz also said client software needs some way to identify and reject a specific malicious builder. Without that, an attacker can just return with a fresh identity and keep breaking the auction in exactly the same way.
A seven-day review window before the fork
To hit the Oct. 6 Sepolia test date, client teams have to ship Sepolia-ready versions with Glamsterdam support by Sept. 29. That leaves just seven days between the software release and fork activation. Ethereum upgrades usually leave 14 days for security review and bug bounty testing.
Developers accepted the shorter window partly because Sepolia is fairly centralized and easier to recover if something goes wrong. Even so, production-grade builder software run by the Titan and Ultrasound teams still has not finished Glamsterdam fork migration testing. So yes, there is still a real gap before anyone can call this mainnet-ready.
Hoodi and mainnet timing still depend on Sepolia results
The next test stage is still flexible. Hoodi is tentatively set for Oct. 27, but developers said they will decide whether that date holds based on what happens on Sepolia.
The report said that if fake builders do cause large-scale disruption during Sepolia testing, developers may first add builder identification and blocking measures. They may also lengthen the client security review window. If that happens, Glamsterdam’s mainnet launch could slip past the original mid-2026 expectation mentioned in the article.
For Ethereum, this test is not just about whether the upgrade works. It is also a stress test of putting the MEV-Boost model into the protocol in a low-cost attack setting. Short version: how well developers close this gap on testnet will shape confidence in Ethereum’s ability to handle upgrade risk.

