Ethereum's Glamsterdam Upgrade Hits Snag as Vulnerability Exploits Emerge
The Ethereum team has confirmed that the Glamsterdam upgrade will proceed as scheduled on October 6, but developers are warning about potential vulnerabilities in the system. The upgrade introduces a new relationship between validators and specialized block builders, where builders assemble transaction blocks and compete to supply them.
However, this process can be easily abused on a free test network, allowing a malicious operator to submit bids far above legitimate builders and win repeatedly without delivering the promised payload.
Ethereum consensus developer Potuz warned that 'any teenager' could exploit this vulnerability, simply by spinning up multiple builder identities and offering high bids without producing payloads.
Developers are urging client teams to release Sepolia-ready software by September 29, as they will be relying on existing safeguards to prevent such attacks. These safeguards typically fall back to locally built blocks after several missing payloads.