Ethereum confirms Glamsterdam dates, but warns 'fake' builders could stall the chainFree test ether lets fake builders outbid rivals and withhold transaction payloads, while client teams get half the usual review time before Sepolia.Updated 4 min agoPublished 22 min agoEthereum confirms Glamsterdam dates, but warns 'fake' builders could stall the chain. (Kevin Horvat on Unsplash)Ethereum developers warned that attackers could exploit free test ether and disposable builder identities to win Sepolia block auctions and withhold transaction payloads during Glamsterdam testing.The attack would not threaten mainnet funds, but it could disrupt infrastructure testing and highlights the need for clients to identify and reject malicious builders.Sepolia’s public test is scheduled for Oct. 6, giving client teams a shortened release window, while Hoodi testing is tentatively set for Oct. 27 and mainnet activation remains unscheduled.A teenager with free test ether and a collection of disposable builder identities could repeatedly win Ethereum’s new block auctions and refuse to deliver the transactions, developers warned as they confirmed an Oct. 6 public test of the Glamsterdam upgrade.The attack would not endanger mainnet funds. It targets Sepolia, where test ether has no meaningful cost, but could leave blocks without transaction payloads and derail the infrastructure testing needed before Glamsterdam reaches Ethereum itself.Glamsterdam is Ethereum’s next major upgrade, designed to fit more activity into each block without overwhelming the computers that verify it. Together with changes to gas pricing, the upgrade is intended to support a block gas limit of about 200 million, creating room for more payments and trades before users begin bidding fees higher.The upgrade moves the relationship between validators and specialized block builders into Ethereum’s protocol. Builders assemble transaction blocks and compete to supply them. Once a validator accepts the winning bid, the builder is expected to reveal the underlying transactions.And that process becomes easy to abuse on a free test network. A malicious operator can submit bids far above every legitimate builder, win repeatedly and then withhold the promised payload.“I can just spin up a thousand builders, rotate them, offer very high bids, and not produce payloads,” Ethereum consensus developer Potuz said during Thursday’s core developer call. “Any teenager can do this.”Developers said existing safeguards typically fall back to locally built blocks only after several payloads go missing. Potuz added that clients also need to identify and reject individual builders so an attacker cannot return under a new identity and continue winning.The warning came one day after a large private rehearsal completed the Glamsterdam transition and raised its block gas limit toward 200 million without losing finality.Read More: Ethereum’s upcoming Glamsterdam upgrade clears rehearsal for a big jump in capacityClient teams now have until Sept. 29 to release Sepolia-ready software. That leaves seven days before the fork, half the 14 days Ethereum’s normal upgrade process reserves for security reviews and bug-bounty testing.Developers accepted the narrower window because Sepolia is relatively centralized and easier to recover if something breaks. Production builder software operated by teams Titan and Ultrasound has also not completed a Glamsterdam fork transition, adding another gap before the upgrade can be treated as mainnet-ready.The next public test on Hoodi is tentatively planned for Oct. 27. Developers will decide whether to keep that date after observing Sepolia, while a mainnet activation remains unscheduled.12345678910
Ethereum confirms Glamsterdam dates, but warns 'fake' builders could stall the chain
Full Article
Original Source
Read the full article at Coindesk →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.