Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Ethereum locks in Glamsterdam dates but warns teenagers could stall the test network

Ethereum confirms Glamsterdam dates but warns teen attackers could freeze Sepolia tests using free test ether and fake builder accounts.

By mitch·4 min read
A digital illustration of a blockchain network with glitch effects representing a security warning.

The dates for Ethereum’s Glamsterdam upgrade have been confirmed, yet the announcement comes with a warning. A teenager with access to free test ether and a collection of fake accounts holds the power to stall the entire dress rehearsal.

Security researchers warn that bad actors might abuse free test ether and temporary builder accounts to win Sepolia block auctions while withholding transaction payloads during Glamsterdam testing. Such an assault would not endanger mainnet funds, yet it could disrupt infrastructure testing and demonstrate the need for clients to recognize and reject malicious builders.

The attack vector

Here is how the attack would work:

Advertisement
  • Anyone, even a teenager, can spin up a thousand builders with free test ether.
  • They rotate those fake accounts and offer very high bids to win the next block auction.
  • Once they win, they withhold the data they promised to include in the block.
  • That freezes the blockchain’s traffic.

“I can just spin up a thousand builders, rotate them, offer very high bids, and not produce payloads,” Ethereum consensus developer Potuz said during Thursday’s core developer call. “Any teenager can do this.”

The assault is aimed at Sepolia, a place where test ether holds little to no value. By refusing to include payloads, attackers leave blocks empty of transaction data, which throws off the testing required before Glamsterdam can move forward onto Ethereum proper.

What Glamsterdam actually does

Ethereum’s upcoming update, Glamsterdam, aims to pack more activity into each block while keeping verification work within safe limits. Combined with adjustments to how fees are charged, the upgrade targets a block gas limit of roughly 200 million. That expanded capacity should let more payments and trades fit inside a single block before users start paying higher fees again.

Ethereum’s protocol now holds the arrangement between validators and specialized block builders inside itself. These builders put together transaction blocks and vie to deliver them. A validator picks the winning bid, and at that point the builder is supposed to show what transactions sit underneath the block.

A free test network makes it simple for someone acting with ill intent to misuse the system. That person could place bids far beyond what any honest builder would offer, win again and again, and then refuse to deliver the promised content.

The shortened release window

Sept. 29 is the deadline for client teams to release Sepolia-ready software, giving them seven days before the fork. That window amounts to half the 14 days Ethereum’s standard upgrade schedule sets aside for security reviews and bug-bounty testing.

The tighter timeline was accepted due to Sepolia’s more centralized nature and the ease of recovery should something go wrong there. The production builder software run by teams Titan and Ultrasound has yet to finish its Glamsterdam fork transition, creating an additional delay before the upgrade can be considered ready for mainnet use.

Hoodi’s upcoming public test has a tentative target of Oct. 27, with developers waiting to see how Sepolia performs before confirming the date. A mainnet launch still has no set schedule.

Why this matters

The threat is real. It costs almost nothing and can be repeated again and again. One young person with access to free test ether can create a thousand fake accounts, win the auctions, and hold back the payloads. The design depends on clients recognizing and refusing individual builders so an attacker cannot come back under a new name and keep winning.

Local backup blocks aren’t usually relied on until after a few payloads have gone missing. So the system tends to wait for signs of trouble before it switches to them.

The assault does not threaten mainnet assets. It focuses on Sepolia, where test ether carries no worth. Yet it might leave blocks without transaction contents and upset the testing groundwork required before Glamsterdam arrives at Ethereum proper.

The timeline

  • Oct. 6: Sepolia public test debut
  • Sept. 29: Sepolia-ready software deadline for clients
  • Oct. 27: Hoodi public test tentatively planned
  • Mainnet activation: unscheduled

Security reviews and bug-bounty testing lose half their time under the new schedule, since clients now sit through just seven days rather than 14. That reduction has already passed a major private rehearsal, one that raised its block gas limit toward 200 million without giving up finality.

A teenager’s attack using fake accounts could paralyze the test network, and the warning makes no effort to soften the point. Client teams are given only seven days to ready themselves, instead of the fourteen they normally receive.

Source material: “Ethereum confirms Glamsterdam dates, but warns 'fake' builders could stall the chain,” CoinDesk.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.