Ethereum developers warned that attackers could exploit free test ether and disposable builder identities to win block auctions on Sepolia and withhold transaction payloads during Glamsterdam testing.
The attack would target Sepolia, the public test network where test ether carries no real cost. A malicious operator could submit repeatedly high bids using multiple builder identities, win auctions consistently, and then refuse to deliver the promised transactions. "I can just spin up a thousand builders, rotate them, offer very high bids, and not produce payloads," said Ethereum consensus developer Potuz during Thursday's core developer call.
While the attack would not endanger mainnet funds, it could disrupt infrastructure testing needed before the upgrade reaches Ethereum's main network. Glamsterdam moves the relationship between validators and block builders into Ethereum's protocol, with builders assembling transaction blocks and competing to supply them.
Developers said existing safeguards typically revert to locally built blocks after several payloads go missing. However, Potuz argued that clients also need to identify and reject individual builders so attackers cannot simply return under new identities.
Sepolia's public test is scheduled for Oct. 6, giving client teams until Sept. 29 to release compatible software. This represents a shortened seven-day window compared to Ethereum's normal 14-day security review period for upgrades. Developers accepted the narrower timeline because Sepolia is relatively centralized and easier to recover if issues emerge.
The next public test on Hoodi is tentatively planned for Oct. 27. Developers will decide whether to keep that date after monitoring Sepolia, while mainnet activation remains unscheduled. Production builder software from teams Titan and Ultrasound has not yet completed a Glamsterdam fork transition, adding another gap before the upgrade can be considered mainnet-ready.


