Malicious code is able to show UI over the purchase prompt, and trick users into purchasing items

I was able to get my Robux back that I lost from this, but Roblox Support took away my one-time courtesy option as if my account was hacked or compromised – it was neither the two as you know.

Any options to get around this? I’m trying my best to work with the support agent but I can only do so much.

1 Like

No. There’s no way for the Roblox employee to distinguish between you being legitimately scammed and you prompting yourself with any gamepass and playing it off as if your purchase was hijacked.

I didn’t click on a purchase prompt, I never did. The whole Bug Report is about malicious code being able to show over a UI purchase prompt. I had no clue that there was a purchase prompt under, and this shouldn’t be my responsibility at all.

I really hope for more clarification or instructions on what to do about this. Not just for me, but for the many other users that have also been impacted by this as well.

EDIT: I’d also like to point out that this can happen to literally anyone. This shouldn’t even be considered something along the lines as, “you fell for it” or “you accidently bought it” as no visible purchase popup was shown anywhere on the screen.

5 Likes

KonekoKitten just made a video on this, so a lot of the Roblox community is aware of this now, probably should be better in the coming days.

1 Like

Roblox needs to patch this ASAP!

More and more people are being scammed by this

4 Likes

Most backdoors hide the PurchasePrompt and align the “continue” button right on the position of the Confirm purchase button. I messed randomly with the PurchasePrompt CoreGUI and managed to get it to purchase instantly without confirmation with it being invisible, sure works better than their scams, but I want to get this patched. Unfortunately I lost the code, but Roblox was very vulnerable to these things from the beginnings. I hope they fix this before this could lead to more important problems.

1 Like

The coregui didn’t really “crash,” more like the renderer doing it’s job… too well.
When there are too many UIs, it starts to hide some. This even happens with too many UIs in the workspace, hiding other player UIs (which includes coregui) with it.

1 Like

I’m actually curious on how someone found out how to do this.

Never have I seen something like this. This is a serious issue, and I’m glad it’s getting fixed.

1 Like

I’m honestly just curious on how Roblox will handle this issue. Hopefully they can find a solution in this disaster.

2 Likes

Still, I intentionally added “visible or not” because I’m really skeptical that he managed to make it activate with no further interaction from the player (such as moving over the button, clicking on it, etc). And again, you just believe you didn’t click on a purchase prompt because you didn’t see it.

Are you sure you didn’t modify anything/mess with mouse behavior?

If the purchase prompt wasn’t visible on my screen (which it wasn’t), not my problem. There is no way to somehow justify this any further.

roblox should do a rollback after that because tons of people got scammed

3 Likes

Not gonna tell how I did it, but it was extremely easy to replicate without any help and it needs to be patched ASAP.

As you can see by the mouse darkening, the purchase screen remains functional yet invisible.

6 Likes

You can send repro details to the @Exploit_Reports group in private.

2 Likes

Nevermind this. It seems like it only works when run by command bar in studio and not in actual scripts. Not sure how they did it.

2 Likes

its a rendering bug, I can reproduce this myself with my own code.

3 Likes

I’m able to replicate this on my own and surprisingly, this does not take effort to do.

1 Like

Mad scary, good thing I’m broke :joy:

11 Likes

yeah this is like 5 lines and dangerous whew