Ethereum developers warn ‘any teenager’ could disrupt upcoming Glamsterdam test
Free test ether lets fake builders outbid rivals and withhold transaction payloads, while client teams get half the usual review time before Sepolia.
By Shaurya Malwa|Edited by Omkar Godbole
Updated Published
Share this article

Summary
Ethereum developers have locked in Oct. 6 as the test date for their highly anticipated “Glamsterdam” upgrade. However, the announcement comes with a serious warning that bad actors using “fake” identities could stall the dress rehearsal of the upgrade.
Developers warned that anyone, even a teenager with free test ether, and a handful of fake accounts could repeatedly win the Ethereum network’s auctions to process the next block of transactions. Then, the bad actor could simply ghost the network by withholding the data, effectively freezing the blockchain’s traffic.
This matters because potential freezing of the traffic would make it challenging for developers to properly test how the upgrade handles real-world traffic. The Oct. 6 debut is a dress rehearsal, or public test run for the final Glamsterdam upgrade, which will happen once developers are sure everything works safely.
“I can just spin up a thousand builders, rotate them, offer very high bids, and not produce payloads,” Ethereum consensus developer Potuz said during Thursday’s core developer call. “Any teenager can do this.”
Such an attack would not endanger mainnet funds. Any potential attack would only target “Sepolia,” where test ether has no meaningful cost, but could leave blocks without transaction payloads and derail the infrastructure testing needed before Glamsterdam reaches Ethereum itself.
Glamsterdam is Ethereum’s next major upgrade, designed to fit more activity into each block without overwhelming the computers that verify it. Together with changes to gas pricing, the upgrade is intended to support a block gas limit of about 200 million, creating room for more payments and trades before users begin bidding fees higher.
The upgrade moves the relationship between validators and specialized block builders into Ethereum’s protocol. Builders assemble transaction blocks and compete to supply them. Once a validator accepts the winning bid, the builder is expected to reveal the underlying transactions.
And that process becomes easy to abuse on a free test network. A malicious operator can submit bids far above every legitimate builder, win repeatedly and then withhold the promised payload.
Developers said existing safeguards typically fall back to locally built blocks only after several payloads go missing.
Potuz added that clients also need to identify and reject individual builders so an attacker cannot return under a new identity and continue winning.
The warning came one day after a large private rehearsal completed the Glamsterdam transition and raised its block gas limit toward 200 million without losing finality.
Read More: Ethereum’s upcoming Glamsterdam upgrade clears rehearsal for a big jump in capacity
Client teams now have until Sept. 29 to release Sepolia-ready software. That leaves seven days before the fork, half the 14 days Ethereum’s normal upgrade process reserves for security reviews and bug-bounty testing.
Developers accepted the narrower window because Sepolia is relatively centralized and easier to recover if something breaks. Production builder software operated by teams Titan and Ultrasound has also not completed a Glamsterdam fork transition, adding another gap before the upgrade can be treated as mainnet-ready.
The next public test on Hoodi is tentatively planned for Oct. 27. Developers will decide whether to keep that date after observing Sepolia, while a mainnet activation remains unscheduled.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
Sep 15, 2026
Why it matters:
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.




