Ethereum's Glamsterdam Upgrade Explained: What It Changes and Why Developers Are Worried
Ethereum's next major upgrade, Glamsterdam, reached its first public testnet on October 6, 2026. Here's what it actually changes — enshrined proposer-builder separation and parallel execution — and why developers warned days earlier that the test itself could be disrupted by anyone with free testnet ether.
▶ View as web storyEthereum’s next major protocol upgrade, called Glamsterdam, reached its first public test network on October 6, 2026. It bundles two significant changes to how the network builds and processes blocks: proposer-builder separation written directly into Ethereum’s rules, and a new mechanism that lets validators handle multiple transactions at once instead of one by one. Days before the test began, though, a core Ethereum developer warned that the new design had an exploitable weak spot — one that would be expensive to pull off on the real network, but free to try on the test version.
Here’s what Glamsterdam actually changes, why it matters even if you’ve never heard the term before, and what the warning was actually about.
What is the Glamsterdam upgrade?
Glamsterdam is the name for Ethereum’s next scheduled network upgrade. Like Ethereum’s last few upgrades, it’s a combination of two code names — an execution-layer change (Amsterdam) and a consensus-layer change (Gloas) — stitched together the same way “Dencun” combined Cancun and Deneb in March 2024, and “Pectra” combined Prague and Electra in May 2025 (ethereum.org).
Glamsterdam’s two headline proposals are:
- EIP-7732, which enshrines proposer-builder separation (often shortened to ePBS) directly into Ethereum’s protocol rules.
- EIP-7928, which introduces Block-Level Access Lists (BALs), a data structure that lets validators verify independent transactions in parallel.
Both are aimed at the same underlying goal: let Ethereum process more transactions, more cheaply, without concentrating power over block production in a small number of outside companies.
Why Ethereum is “enshrining” proposer-builder separation
To understand why ePBS matters, it helps to know how Ethereum blocks get built today. Most Ethereum validators don’t construct their own blocks. Instead, they outsource that job to specialized “builders” through an off-chain auction system called MEV-Boost, which has handled roughly 90% of Ethereum blocks in recent years. A peer-reviewed study by researchers from the Technical University of Munich, Flashbots, and the Ethereum Foundation found that just three builders — beaverbuild, rsync, and Titan — produced about 80% of all MEV-Boost blocks between October 2023 and March 2024 (rig.ethereum.org).
That concentration is the problem ePBS is meant to address. Today’s system relies on trusted off-chain relays to keep builders and validators honest. EIP-7732 replaces that trust requirement with on-chain rules: builders cryptographically commit to a bid and a sealed block, validators pick the winning bid without seeing its contents, and the block’s actual transactions are only revealed once the commitment is locked in. The goal is to keep the efficiency benefits of specialized block builders while removing the need to trust a relay operator in the middle.
What Block-Level Access Lists actually do
The second major piece, EIP-7928, tackles a different bottleneck: Ethereum validators today process transactions in a block one after another, even when most of those transactions don’t actually touch the same data. Block-Level Access Lists require a block to declare upfront exactly which accounts and storage slots each transaction will touch. With that map in hand, a validator’s software can identify which transactions are independent of each other and verify them simultaneously instead of in sequence.
That parallel-processing capability is also what’s expected to let Ethereum eventually raise its per-block gas limit well beyond today’s levels without making the chain slower to verify — reporting from The Defiant has pointed to a roadmap target of raising the gas limit from 60 million toward 200 million once BALs and related changes are in place (The Defiant). That’s a target tied to further upgrades and testing, not something that arrives the moment Glamsterdam ships — treat it as direction, not a locked-in promise.
The warning: how a free-money exploit could stall the test
Glamsterdam’s path to its October 6 testnet wasn’t smooth. Client teams spent the prior weeks patching bugs surfaced on Ethereum’s internal “devnet-9” test environment, including one tied to EIP-8037 — a related proposal that changes how Ethereum prices the creation of new permanent on-chain data — which Ethereum Foundation researcher Maria Silva identified during testing and which required execution-layer clients to be updated before the test could proceed (Cointribune; KuCoin).
On top of that bug-fixing scramble, Ethereum consensus developer Potuz raised a more pointed concern on a developer call on September 17, 2026, as reported by CoinDesk: the new proposer-builder auction system could be gamed on the Sepolia test network specifically because test ether (Sepolia ETH) is free (CoinDesk; crypto.news). Potuz warned that an attacker — in his words, something “any teenager” could attempt — could spin up large numbers of fake builder identities, submit high bids to win block-building auctions over and over, and then simply refuse to hand over the actual transaction data once they’d won. Because losing bids costs nothing on a test network, that kind of abuse could repeat indefinitely and potentially stall block production. On Ethereum’s real mainnet, the same trick would require spending real ETH on every losing bid, which is the deterrent that doesn’t exist on a free test network.
That left client teams with a tighter-than-usual runway: software had to be ready for Sepolia by September 29, 2026, giving roughly seven days of final review before the October 6 activation — about half of the 14-day window Ethereum’s process normally reserves for security review and bug-bounty testing before a fork. Developers reportedly accepted the shorter window partly because Sepolia is a relatively small, centralized test network that’s easier to recover if something does go wrong, compared to risking the same compressed timeline on mainnet.
Ethereum’s major upgrades at a glance
| Upgrade | Activated | Headline change |
|---|---|---|
| Dencun (Cancun/Deneb) | March 2024 | Proto-danksharding (EIP-4844) — cheap “blob” storage for rollups |
| Pectra (Prague/Electra) | May 2025 | Smart-account-like features for standard wallets |
| Fusaka (Osaka/Fulu) | 2025 | Scaling and data-availability groundwork |
| Glamsterdam (Amsterdam/Gloas) | Testnet: Oct. 6, 2026; mainnet date not yet set | Enshrined proposer-builder separation + Block-Level Access Lists |
Does this affect your ETH or any dApp you use?
Not right now, and when Glamsterdam does eventually reach mainnet, it still won’t require anything from you. This is a protocol-level change to how validators build and verify blocks — it doesn’t touch user wallets, balances, or how you sign transactions, the same way Dencun and Pectra didn’t require any action from regular ETH holders. If you run your own validator or operate infrastructure that depends on block-building (an MEV searcher, a builder, a relay operator), the ePBS changes are directly relevant to you; everyone else can treat this as background engineering that may eventually show up as lower fees and faster blocks, not as something to act on today.
It’s also worth being honest about timelines: crypto upgrade schedules slip often, and a security warning surfacing less than three weeks before a testnet date is itself a sign that the mainnet date could move further depending on what this testnet turns up. None of this is a signal about ETH’s price one way or the other — this is not financial advice, and any price reaction to protocol news should be treated as speculation, not a predictable outcome.
If you’re also tracking Ethereum’s validator and staking side, see our explainer on MetaMask’s security incident and its Lido validator exits for a recent example of how validator operations can go wrong in practice. And if the idea of a tighter-than-normal security review window makes you want more context on 2026’s track record for crypto security incidents, our roundup of September 2026’s $768 million in crypto hacks is a useful comparison point for why developers are being especially careful here.