Discuss Scratch
- Discussion Forums
- » Questions about Scratch
- » NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
- Matikiscool
-
Scratcher
100+ posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
Oh no! That must be terrible.i saw this happening on different by design too and i got curious and eventually hacked on my mainNot even that. I think they spammed Grifftopia once for five minutes and that was it.dec 7th did end up happening, albiet on a smaller, smaller scale
Let me guess they spammed grifftopia, other popular Chatrooms and a st member profile. They nearly do that every month
some might say…my compass is curiosity /j /ref
KING OF THE PAGE!
Last edited by Matikiscool (May 6, 2026 11:41:29)
- ReallySopa
-
Scratcher
100+ posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
You're on my side, Scratcher.Oh finally… The so-called “Canvas Virus” is getting fixed, Thank the Scratch Team.You heard that, the ST is not THAT bad after all. I just wonder why this happened in the first place.
Honestly, the people that spammed a lot of “Canvas Virus” comments everywhere on Scratch don't know what they're doing, I know they want to “help” other people, but just send the message to their relatives, not to random or unrelated projects…
And also, I'm glad that this is sticked, because they were a lot of people who was panicking about the issue, they even didn't know the Scratch Team was fixing it and yet… they complained about the Scratch Team. So hey Scratchers, the Scratch Team is not actually THAT bad, they were actually aware of this and fixing it. Respect them please.
Anyway, I hope the Scratch Team can keep going on Scratch. Also, if you can, then try tell your relatives that the issue is getting fixed by the Scratch Team (just don't spam it).

- FriskVRYT
-
Scratcher
11 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
CSS exploit isnt fixed, as all of my custom styles projects still have the styles.
- nembence
-
Scratcher
500+ posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
CSS exploit isnt fixed, as all of my custom styles projects still have the styles.The CSS exploit is not what the virus used. The virus used a bug in the costume editor, which has been fixed since then (in the online editor)
The CSS exploit doesn't need that you see inside the project, and it can't run JavaScript so it can't take over your account
- WeTheSkyBlues_42
-
New Scratcher
7 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
well hopefully my account is recovered 

- IceCreamTub
-
Scratcher
1000+ posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
A Youtube video sumarising most of the information regarding this attack will be posted tomorrow morning (where i live, GMT+8), hopefully……
What i'm mainly concerned about are scratch “influencers” hitching a ride off of this incident & sensationalizing it to oblivion with MrBeast style editing & everything, i made sure my video has minimal editing
I included some “advice” for dealing with this incident while it's ongoing but aaaagh thag part is mostly outdated by now
Excluding the “not opening random sb3 files” part, as far as i know the fixes are only limited to the website at the moment
What i'm mainly concerned about are scratch “influencers” hitching a ride off of this incident & sensationalizing it to oblivion with MrBeast style editing & everything, i made sure my video has minimal editing
I included some “advice” for dealing with this incident while it's ongoing but aaaagh thag part is mostly outdated by now
Excluding the “not opening random sb3 files” part, as far as i know the fixes are only limited to the website at the moment
Last edited by IceCreamTub (May 6, 2026 13:16:11)
- dKng_4725
-
Scratcher
1 post
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
can anybody explain what this is
- Stormagedon1556
-
Scratcher
36 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
can anybody explain what this isThis is a forum post by @SushiCat_75 discussing the problem with the Canvas Virus, which is deleting people's projects, changing their descriptions, etc.
- Tsarjosh
-
Scratcher
67 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
Canvas isnt real most of the time, just trolls, although it is occasionally real. Theres not much of a point to hack a moneyless website for kids though. It's kind of like stealing candy from the baby when all the baby has is a twig.Oh no! That must be terrible.i saw this happening on different by design too and i got curious and eventually hacked on my mainNot even that. I think they spammed Grifftopia once for five minutes and that was it.dec 7th did end up happening, albiet on a smaller, smaller scale
Let me guess they spammed grifftopia, other popular Chatrooms and a st member profile. They nearly do that every month
some might say…my compass is curiosity /j /ref
KING OF THE PAGE!
Also, grifftopia already gets massed spammed.
- sup3r_r0ck
-
Scratcher
500+ posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
Please tell me it’s finally fully resolved
- Stormagedon1556
-
Scratcher
36 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
Please tell me it’s finally fully resolvedThe Canvas Virus did, in fact, get resolved, and the Scratch Team is working on getting people's accounts back.
- AtEnds
-
New Scratcher
6 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
I know there's at least one more major vulnerability that allows bad actors to cause significant harm to the platform; I suggest ST review the code for the website. The offline editor is less of a concern, but it should still be reviewed.
- umbreon_is_a_pokemon
-
Scratcher
14 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
Canvas isnt real most of the time, just trolls, although it is occasionally real. Theres not much of a point to hack a moneyless website for kids though. It's kind of like stealing candy from the baby when all the baby has is a twig.Oh no! That must be terrible.i saw this happening on different by design too and i got curious and eventually hacked on my mainNot even that. I think they spammed Grifftopia once for five minutes and that was it.dec 7th did end up happening, albiet on a smaller, smaller scale
Let me guess they spammed grifftopia, other popular Chatrooms and a st member profile. They nearly do that every month
some might say…my compass is curiosity /j /ref
KING OF THE PAGE!
Also, grifftopia already gets massed spammed.
Some people report that the email associated with their account would get uploaded to the hacker when their account became compromised, supposedly. An email doesn't seem like much, but it's still technically valuable.
Also, it invites you to an outside server? I wonder if that's where the real scam is.
Take this with a grain of salt, this is only a theory. Don't go testing it for your safety please. I am only guessing. Do not take me super seriously. I am reasoning the theoretical in this case.
Last edited by umbreon_is_a_pokemon (May 6, 2026 15:07:26)
- PrettyCoolStuffs
-
Scratcher
34 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
the css exploit is not fixed, since my chatroom still has stylingso you're telling me that that project is affected
edit: I've heard words off the virus also was spread through popular chatrooms. I remember seeing reports of not clicking links on griffpatch's comments. Is this related at all?
Last edited by PrettyCoolStuffs (May 6, 2026 15:30:10)
- gem1001
-
Scratcher
1000+ posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
The CSS glitch is unrelatedthe css exploit is not fixed, since my chatroom still has stylingso you're telling me that that project is affected
edit: I've heard words off the virus also was spread through popular chatrooms. I remember seeing reports of not clicking links on griffpatch's comments. Is this related at all?
- gouki2805
-
Scratcher
49 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
MIT will surely fix it 

when green flag clicked
say [Virus fixed !]
- Tsarjosh
-
Scratcher
67 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
I know there's at least one more major vulnerability that allows bad actors to cause significant harm to the platform; I suggest ST review the code for the website. The offline editor is less of a concern, but it should still be reviewed.whut
- Stormagedon1556
-
Scratcher
36 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
They have already fixed the bug, they are now just getting people's accounts back.
- Tsarjosh
-
Scratcher
67 posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
It is very difficult to prevent exploitation of the website via an image file code, or anything else, and the scratch team at MIT is doing a good job (which is to be expected, because most of them are coding nerds at MIT who live to solve these problems). Mass hysteria has been caused by the copy/paste messages people continue to use. The bad news is there will always be another way to hack into it… the good news, there's not much you can do with a hacked account, besides trolling, falsifying information, bot farming, and spreading information. The only major thing a hacker can find is your email address, which, from experience, I can say they can hack into an email address pretty easily, considering they have done it to me outside of scratch. This CAN be dangerous, but is out of scratch's control, so you have to figure it out yourself.
Everyone who will heed warnings has been warned. The projects that are hacked can be found easily, although most of them aren't actually hacked, they are just published by trolls. I have made a test account and not been hacked by the so-called “Canva Virus”. A lot of people publishing messages are just; A. Misinformed but unwilling to change their views, B. Trying to become popular/accepted or C. Attempting to spread arson. There are legitimate viruses that have not been resolved, but I guarantee virtually none of them are heard of or known by the great public masses of scratch. It also doesn't help that both Gaehive and DBD, two popular megastudios known for misinformation and evading the Scratch Team, have at the top of their description's warnings that their obsessed followers eagerly spread. DBD literally has a whole page on the bans.
Tell me if I missed anything on situation, and remember not to discourage the Hysteria which has engulfed the website. Don't click on suspicious links (although the links above are safe), but please skim through the two studio pages' tops and read the messages causing this confusion. Have a nice day!
Everyone who will heed warnings has been warned. The projects that are hacked can be found easily, although most of them aren't actually hacked, they are just published by trolls. I have made a test account and not been hacked by the so-called “Canva Virus”. A lot of people publishing messages are just; A. Misinformed but unwilling to change their views, B. Trying to become popular/accepted or C. Attempting to spread arson. There are legitimate viruses that have not been resolved, but I guarantee virtually none of them are heard of or known by the great public masses of scratch. It also doesn't help that both Gaehive and DBD, two popular megastudios known for misinformation and evading the Scratch Team, have at the top of their description's warnings that their obsessed followers eagerly spread. DBD literally has a whole page on the bans.
Tell me if I missed anything on situation, and remember not to discourage the Hysteria which has engulfed the website. Don't click on suspicious links (although the links above are safe), but please skim through the two studio pages' tops and read the messages causing this confusion. Have a nice day!
- nembence
-
Scratcher
500+ posts
NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.
I have made a test account and not been hacked by the so-called “Canva Virus”.The Scratch Team has fixed the exploit that the virus was using yesterday: https://github.com/scratchfoundation/scratch-paint/pull/3536
It used to infect accounts before that
Also, the ST deleted the infected costume from their servers, so if you clear the cache then infected projects will just show a question mark instead of asking to see inside
Last edited by nembence (May 6, 2026 16:13:44)
- Discussion Forums
- » Questions about Scratch
-
» NOTICE: "Canvas" ACE VULNERABILITIES MOSTLY FIXED-PLEASE DO NOT SPREAD FEAR, MISINFORMATION, OR RUMORS.