Microsoft's headquarters in Redmond, Washington, photographed in daylight
Photo: Hardware.info
Tech

Microsoft's X Account Was Hijacked to Push a Fake Clippy Crypto Token

On Thursday, attackers took over Microsoft's official X account — more than 13 million followers — followed a Clippy impersonator, reposted its pitch, and swapped the profile picture for the old paperclip assistant. The posts were gone within about 30 minutes. Microsoft has confirmed the breach and says it is still investigating how the attackers got in.

The Short Version

Share

On Thursday afternoon, Microsoft's official X account stopped being Microsoft's. The @Microsoft handle — one of the most-followed corporate accounts on the platform, with more than 13 million followers — began following a Clippy impersonator account called @clippymsftcto, reposted one of its pitches, and swapped its own profile picture for Clippy, the animated paperclip assistant Microsoft retired years ago. For roughly half an hour, the face of one of the world's most valuable companies was pumping a fake cryptocurrency.

The Verge's Tom Warren was among the first to flag the compromise as it was happening. Within about 30 minutes, the unauthorized posts were taken down — and a strange "apology" post briefly appeared on the account before being deleted as well, according to reporting from The Verge, SecurityWeek, and BleepingComputer. Microsoft has since confirmed the account was hijacked, secured it, removed the posts, and said it is still investigating what happened.

What the hijackers actually did

The takeover became visible in stages. First the @Microsoft account followed @clippymsftcto, an account posing as Clippy's comeback. Then it reposted one of that account's messages — a viral-style pitch asking how many likes it would take to "bring Clippy back." Then the profile picture changed to a Clippy image, completing the impersonation look, according to BleepingComputer's reporting.

That sequence matters. The attackers didn't need to write a convincing sales pitch from scratch. By following and reposting an account that already existed, they borrowed Microsoft's own credibility — the verified checkmark, the 13 million followers, the blue-chip brand — and pointed it at a token pitch that was already dressed up in Clippy nostalgia. Anyone who glanced at the repost in their feed would have seen Microsoft's name and face on it.

A smartphone displaying the X logo on a wooden table
The hijack ran entirely inside the official @Microsoft account on X, one of the platform's most-followed corporate handles. Photo: Pexels

The $Clippy bait

The token at the center of the scheme trades as $Clippy. After X suspended @clippymsftcto, a related account, @ClippyMSFT, kept promoting the token and reposted Microsoft's hijacked message. The pitch, according to BleepingComputer, claimed the token had a "liquidity pool paired directly with $MSFT" — Microsoft's actual stock ticker — an obvious attempt to make a meme coin look like it had some kind of corporate backing.

Promoters of the token claimed its liquidity pools held more than $200,000, with some posts suggesting the token was effectively backed by Microsoft stock, according to reporting from Bitcoin.com News and CoinDesk. Those claims have not been verified — and Microsoft's denial couldn't be plainer. The deleted post that briefly appeared on its account, via reporting from The Verge and BleepingComputer, said Microsoft was "aware of a cryptocurrency token being promoted in connection with $MSFT stock, including the unauthorized use of the Clippy brand and Microsoft-related intellectual property," and stated it had not "authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT."

The post went further: holding the token gives holders no ownership rights in Microsoft Corporation, and Microsoft said it will pursue legal action to have the unauthorized token and related materials removed. A liquidity pool on a decentralized exchange has nothing to do with a company's equity — and nothing about $MSFT shares was ever connected to the token.

A physical Bitcoin coin photographed on a warm orange background
The $Clippy token was pitched with claims about a liquidity pool "paired directly with $MSFT." The claim was never verified, and Microsoft says holding the token gives holders no ownership rights in the company. Photo: Pexels

The apology that wasn't Microsoft's

Here's the strangest part of the timeline. Roughly 30 minutes after the unauthorized posts went up, a long apology-style post appeared on the Microsoft account — disavowing the token, warning that Microsoft had never authorized anyone to promote a token using its intellectual property including Clippy, and threatening legal action. It read like corporate crisis management.

It wasn't. SecurityWeek reports that Microsoft clarified to the outlet that the apology post was part of the unauthorized activity and did not originate from the company. The post was then deleted, just as quickly, with no explanation. The sequence — malicious posts, then an unauthorized "clean-up" message, then another deletion — suggests the attackers held control of the account for a window even as Microsoft worked to lock it down, though that is an inference from the timeline, not something Microsoft has confirmed.

Microsoft's actual, on-the-record statement came from spokesperson Brent Colburn, who told The Verge, SecurityWeek, and BleepingComputer: "We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft. The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances."

How they got in: the question nobody is answering

For all the detail about what the hijackers did, one fact is missing from every report: how they got in. Microsoft has not said how the attackers gained access to the account, and SecurityWeek notes the possibilities run well beyond the classic image of someone tricking a social media manager into entering credentials on a phishing page — hijacked sessions, stolen tokens, and third-party publishing tools are all on the table for high-profile account takeovers. But none of that is confirmed here. This is the highest-risk part of the story to get wrong, so let's be precise: no outlet has reported a confirmed access method, and until Microsoft says otherwise, the mechanism is unknown.

That matters because the scale of the account makes the access method the real story. A lone scammer phishing one employee is a different incident from a stolen session token in a vendor tool used by a global marketing team. How Microsoft answers this question — and how quickly — will determine whether this was an isolated slip or a warning sign about how corporate accounts are managed on X.

A professional holding a laptop in a bright modern office with large windows
Microsoft has not said how the attackers gained access to its account, and no outlet has confirmed a mechanism. The investigation is ongoing. Photo: SAP Concur

A familiar playbook

This is not the first time a Microsoft account has been turned into a crypto-scam billboard. In June 2024, crypto scammers hijacked the Microsoft India X account (@MicrosoftIndia), which had more than 211,000 followers, to impersonate Roaring Kitty — the handle of meme-stock trader Keith Gill — and push wallet-drainer malware, as BleepingComputer reported.

And 2026 has already seen this playbook used at the highest levels. In July, Robinhood CEO Vlad Tenev's X account was hijacked to promote a fake meme coin — the same basic sequence: borrow a trusted, verified identity and point its audience at a token, according to Bitcoin.com News. The Clippy scheme's twist was branding: instead of impersonating a person, it weaponized a beloved, nostalgic mascot — a paperclip millions of people remember fondly from the 1990s and early 2000s. International Cyber Digest documented the full sequence with screenshots, including the swapped profile picture and the deleted apology.

The pattern is consistent enough to name: high-profile verified accounts are now a standard launch vehicle for token pump-and-dump schemes. The attackers don't build an audience. They rent one for 30 minutes.

What users should know

A few things worth holding onto from this incident. First: a blue checkmark and a corporate profile picture are not evidence. The hijack worked precisely because it stacked trust signals — Microsoft's name, a verified badge, 13 million followers — on top of a fraud. If a brand's account suddenly starts promoting a cryptocurrency, especially one tied to the company's own ticker or branding, assume something is wrong until the company confirms it through other channels.

Second: Microsoft does not have, endorse, or support any cryptocurrency token. The deleted post — according to The Verge — put it in blunt terms: "Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token." If you bought $Clippy on the strength of those 30 minutes of hijacked posts, understand that the token's connection to Microsoft was fabricated — and the company says it will pursue legal action against the token and its promoters.

Third: real digital money moves the other way — through official channels, announced on company websites, with real documentation. (See our Apple Pay India launch coverage for how legitimate payment products actually arrive.) If a token announcement exists only on a social feed, with claims like a liquidity pool "paired" with a stock ticker, that is a red flag, not a feature.

The news desk will update this story as Microsoft's investigation progresses — particularly if the company explains how its account was compromised, which is the one fact still missing from the public record.

DateThursday, October 1, 2026 — roughly a 30-minute window
AccountOfficial @Microsoft on X, 13+ million followers
Token$Clippy — unauthorized, no Microsoft affiliation
StatusAccount secured, posts removed, investigation ongoing

Sources

Share this story
Keep reading

More from the newsroom

All stories →