Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$85,196▲ 0.72%ETH$2,702▲ 0.66%SOL$121.23▲ 1.70%TOTAL CRYPTO$2.89T▼ 1.89%S&P 5007,722.72▲ 0.73%NASDAQ27,190.86▲ 1.19%DOW51,176.96▲ 0.49%GOLD4,162.30▼ 0.95%WTI91.11▼ 1.90%BRENT102.25▼ 0.06%EUR/USD1.1257▲ 0.06%USD/JPY157.83▼ 0.06%DXY101.92▼ 0.17%
Crypto

Hackers Use Microsoft’s X Account to Push $Clippy Token

Microsoft's 13-million-follower X account was hijacked to promote a Clippy meme coin, then recovered within about half an hour.

Pexels – https://kaboompics.com/

Hijackers took over Microsoft’s official X account on Thursday and used it to promote a Clippy-themed crypto token, in a piggyback attack aimed at the company’s 13 million followers.

The intrusion, first reported by The Verge’s Tom Warren, did not begin with a fake giveaway tweet. Instead, the @Microsoft account followed an impostor profile called @clippymsftcto, reposted one of its messages and swapped the profile picture for an image of Clippy, the cartoon paperclip assistant from older versions of Office. The repost put the scam in front of every person who follows the main corporate account, with the site’s own verification and follower count standing behind it.

The impostor account, which posed as Clippy present at Microsoft, was suspended shortly after. A second account, @ClippyMSFT, kept pushing a $Clippy token and claimed it had a liquidity pool paired directly with $MSFT, Microsoft’s stock ticker. That pairing claim has no basis in how either markets or tokens work, and the pools reportedly held a little over $200,000, small enough that the scheme was fishing for retail buyers rather than anyone who checks a chart.

Microsoft regained control and removed the promotional activity roughly thirty minutes after it appeared. A first statement posted during the cleanup said the company was aware of a token being marketed in connection with its stock and that it had not authorized any cryptocurrency tied to Clippy, Microsoft or $MSFT. The company then deleted that post too, and a spokesperson later confirmed the breach, saying unauthorized posts had been removed while the investigation into how access was gained continues.

The mechanics matter more than the specific token. Most corporate account hijacks of this type post one fake tweet and wait for it to spread. This one used structural trust instead: the follow, the repost and the avatar made the scam look like something Microsoft itself had surfaced, and that signal is harder for a casual scroller to discount than any single message. X’s own design amplified it, since a repost from @Microsoft reaches followers directly through their timelines, and the impersonator account appeared as a followed source rather than a random reply.

Why Clippy

Clippy is a nostalgic brand with no current product attached, which makes it an ideal vehicle for a meme coin. There is no live Microsoft product page to contradict claims about it, no community of users who would flag impostors, and a built-in joke that meme-coin buyers find amusing. The attackers leaned on the mismatch between how famous the character is and how little Microsoft uses it, though Clippy remains a registered Microsoft trademark, which exposed the token’s creators to the legal threats contained in the company’s deleted statement, which cited unauthorized use of Microsoft intellectual property.

The $MSFT pairing claim deserves separate scrutiny, because it was the part assembled for people half paying attention. A liquidity pool paired with a stock ticker suggests the token is somehow collateralized by or convertible into Microsoft shares. No such mechanism exists without a regulated tokenization platform, and nothing in the claims pointed to one. The phrase was meant to borrow the credibility of a trillion-dollar company’s stock for a coin whose pools were worth less than a quarter million dollars. It is the digital equivalent of printing business cards that say the bearer works for a company nobody contacted.

Corporate account hijacks of this kind are not new. The US Securities and Exchange Commission’s own X account was compromised in January 2024 to post a fake announcement about a bitcoin ETF approval, briefly moving markets before the lie was caught. The account of certik, a blockchain security firm, and multiple exchange accounts have been taken over for token promotions in separate incidents. The standard resolution always looks the same, with the account secured, the posts deleted and a promise of investigation, and the repeat success of the technique says something about how hard account security at scale actually is.

What differs here is the method. Impersonation by follow and repost rather than a single fabricated announcement is quieter and arguably more effective, because it exploits the way timelines work rather than the gullibility of a reader. A person scrolling past a repost from @Microsoft sees content the account chose to surface, and the barrier to suspicion sits higher than it does for an obviously worded fake. The design choice suggests the operators understood the platform’s psychology, not just its mechanics.

How the attackers got in remains a question. Microsoft has not said whether stolen credentials, an insider, a hijacked session or a third-party integration was responsible. Two-factor authentication on a corporate account of this size is assumed, which makes plain password theft less likely, but the company’s statement stops at confirming unauthorized access. The answer matters for every large brand on the platform, since whatever worked here will be attempted on the next target, and the pattern of repeated corporate hijacks across years suggests no single fix has closed the door.

For buyers, the episode repeats a lesson that keeps costing people money. A token promoted from a verified corporate account is not endorsed by that company, and Microsoft has now said so in writing, on the platform where the scam ran. Anyone who bought $Clippy during the window the hijack was live did so on infrastructure the attackers controlled, and @ClippyMSFT was still promoting the token after Microsoft’s account was recovered, which means exposure continued past the cleanup.

The reputational cost to the token market is incidental but real. Meme coins launch daily without incident, and most never touch anyone’s trademark. But the recurring pattern of account hijacks paired with token promotions feeds a public association between the token market and fraud, and that association is exactly what regulators in Europe and the United States cite when they tighten custody, disclosure and marketing rules for digital assets. A scam that ran for half an hour will outlive itself in that debate.

SourcesThe Verge; BleepingComputer; SecurityWeek; PCMag; crypto.news.
Share: X