Microsoft X account hijacked to push Clippy crypto token

Microsoft X account hijacked to push Clippy crypto token

Attackers took over Microsoft's official account on X on Thursday and used it to promote a cryptocurrency token in what looks like a pump-and-dump scheme. The @Microsoft account has more than 13 million followers.

In a pump-and-dump scheme, promoters inflate interest in an asset, often a little-known token, so they can sell their own holdings at a higher price before the value collapses. Access to a widely followed corporate account gives that kind of hype a large and trusting audience.

How the hijack unfolded

According to The Verge, which first reported the incident, the compromise became visible when @Microsoft followed and reposted a tweet from @clippymsftcto. That account impersonated Clippy, the animated paperclip assistant Microsoft shipped with older versions of Office. X has since suspended it.

A second account, @ClippyMSFT, reposted the Microsoft tweet and was still promoting a $Clippy token after the takeover. It claimed the token "has a liquidity pool paired directly with $MSFT," a reference to Microsoft's stock ticker.

Microsoft removed the posts and confirmed the breach.

"We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft," a company spokesperson told The Verge. "The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances."

Microsoft disowns the token

In a tweet it later deleted, Microsoft apologized for the posts. It said it does not support any cryptocurrency or crypto-related token and that it would take legal action.

"We are aware of a cryptocurrency token being promoted in connection with $MSFT stock, including the unauthorized use of the Clippy brand and Microsoft-related intellectual property. Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT," the company said.

"We are taking this matter seriously and will pursue appropriate legal action to have the unauthorized token and related materials removed. For the avoidance of doubt, Microsoft does not endorse or have any affiliation with this token, its creators, or any related cryptocurrency project."

Microsoft has not said how the attackers got into the account. BleepingComputer asked the company for more details, but a spokesperson was not immediately available.

Not the first Microsoft account to fall

Microsoft has been here before. In June 2024, crypto scammers took over the Microsoft India account on X (@MicrosoftIndia), which had more than 211,000 followers at the time. They used it to pose as Roaring Kitty, the online handle of meme stock trader Keith Gill.

The attackers replied to tweets from the hijacked account and pointed users to a malicious site, presaIe-roaringkitty[.]com. The page claimed to offer a "presale" of GameStop (GME) crypto. Anyone who connected a wallet and approved transactions handed their assets to a wallet drainer, a type of malware that empties cryptocurrency wallets once the victim grants it permission.

A wider pattern on X

These incidents sit inside a larger wave of account takeovers and malicious ads on X. Verified organizations have repeatedly been hijacked to push crypto scams and drainers.

The scale can be significant. In December 2023, blockchain threat analysts at ScamSniffer reported that criminals stole roughly $59 million in cryptocurrency from 63,000 people between March and November. They did it through a single ad push on the platform, then still called Twitter, using a drainer called "MS Drainer."

Government accounts have not been spared. The U.S. Securities and Exchange Commission's @SECGov account was compromised through SIM swapping, an attack in which criminals take control of a victim's phone number. The account then posted a fake announcement that Bitcoin exchange-traded funds (ETFs) had been approved, which briefly pushed Bitcoin prices sharply higher. Eric Council Jr., the hacker behind that hijack, pleaded guilty in February 2025. He was sentenced to 14 months in prison for his part in a conspiracy to manipulate Bitcoin's value through the account.

Our Take

The Microsoft takeover shows that a large follower count makes an account a target in its own right. Attackers don't need to breach corporate networks to profit from a brand. They only need one social media login, and a few minutes of posting is enough to lend credibility to a token. The Clippy theme was well chosen for this, because it plays on nostalgia and on the meme culture that drives a lot of speculative crypto trading.

For readers, the practical lesson hasn't changed. A post from a verified corporate account is not proof that the company endorses anything, especially when the post involves tokens, presales or wallet connections. This fits a broader picture of crypto fraud that ranges from pig butchering scams to incidents affecting wallet providers such as MetaMask.

It is worth watching whether Microsoft explains how the account was accessed, for example through stolen credentials, a third-party tool or SIM swapping. Its threatened legal action against the token's creators could also show how far brand owners can go after scammers. The SEC case suggests that prosecutions are possible, but they took time.