Microsoft’s X Account Was Used to Boost a Clippy-Branded Crypto Token
Microsoft confirmed its X account was hijacked to promote $Clippy crypto token. It removed posts, secured account, disavowed endorsement.
Illustrative image generated with AI
Microsoft confirmed that someone accessed its official X account without authorization and used it to amplify a cryptocurrency promotion. The account, @Microsoft, has more than 13 million followers.
The activity promoted $Clippy, a token presented as connected to Microsoft’s Clippy assistant. Its promoters claimed the token had a liquidity pool paired with $MSFT. Microsoft said it had not approved or endorsed the token or any relationship with the company.
The promotion involved two Clippy-themed accounts
Both reports place the activity on Thursday, but neither gives the incident’s calendar date. BleepingComputer published its report on October 2, 2026, at 05:29 AM.
According to BleepingComputer, @Microsoft followed and reposted material from @clippymsftcto, an account posing as Clippy. That account has since been suspended.
BleepingComputer also named @ClippyMSFT as another account promoting $Clippy and reposting Microsoft’s post. It reported that the account was still pushing the token when its article appeared. SecurityWeek’s report likewise describes a second account continuing to promote the token, but does not give its handle.
The claimed liquidity pool was described as paired with $MSFT. BleepingComputer specified that the pairing was “directly” with $MSFT; SecurityWeek did not include that qualifier.
SecurityWeek reported another change to the official profile: Microsoft’s picture was replaced with an image of Clippy, the animated paperclip assistant shipped with older versions of Office. That detail appears in SecurityWeek’s account, not BleepingComputer’s.
Microsoft removed the posts and disavowed the token
Microsoft said posts made during the incident did not come from the company. It removed the unauthorized content, secured the account, and said it was continuing to investigate the circumstances of the access.
An apology was also posted and later deleted. SecurityWeek, citing The Verge, placed the apology roughly 30 minutes after the promotional activity and said it disappeared shortly afterward. BleepingComputer also reported a deleted apology; SecurityWeek said no reason for its removal was given.
Microsoft stated that it had not authorized, sponsored, endorsed, or permitted a cryptocurrency token associated with Clippy, Microsoft, or $MSFT. It also disclaimed affiliation with the token’s creators and related projects. BleepingComputer reported that Microsoft said it would pursue appropriate legal action to remove the unauthorized token and related material.
The confirmed impact in the reports is the unauthorized use of a high-reach corporate account and Microsoft branding to amplify a token promotion. Neither report attributes financial losses to this incident or establishes whether the promotion generated trading activity. The reports also do not say whether account credentials, internal systems, or other Microsoft services were affected.
The route used to access the account remains undisclosed
Microsoft has not publicly identified how the attackers obtained access, and the reports do not identify them. SecurityWeek outlines several possible account-takeover routes as general scenarios, not as findings about this incident.
These include phishing a social-media manager for credentials, taking control of the associated phone number through SIM swapping, or accessing the email account used for password resets. SecurityWeek also describes infostealer malware capturing browser session cookies from an employee’s device; a stolen active session could permit access without a password or an MFA prompt.
A further possibility raised by SecurityWeek is misuse of an authorized third-party marketing or social-media management service. None of these methods has been confirmed as the entry path in Microsoft’s case.
Microsoft has said the account was secured and the posts removed. The reports do not describe specific technical containment steps, such as credential or MFA changes.
Earlier account compromises show how social platforms can be abused
BleepingComputer reports that @MicrosoftIndia was hijacked in June 2024. The account had more than 211,000 followers, and the attackers used it to impersonate meme-stock trader Keith Gill, known as Roaring Kitty.
The attackers directed users to presaIe-roaringkitty[.]com, presented as a presale site for GameStop (GME) cryptocurrency. According to BleepingComputer, users who connected wallets and authorized transactions had crypto assets taken through a wallet-drainer service. The report does not establish a connection between that incident and the $Clippy promotion.
BleepingComputer also cited blockchain threat analysts at ScamSniffer, who said in December 2023 that a Twitter-ad campaign using MS Drainer was associated with roughly $59 million stolen from 63,000 people. The campaign period was reported as March through November, without a year specified for that interval. Those figures describe the cited campaign, not the Microsoft account incident.
The U.S. Securities and Exchange Commission’s @SECGov account was reportedly taken over through SIM swapping. The compromised profile published a false announcement about approval of Bitcoin exchange-traded funds, after which Bitcoin prices rose temporarily and significantly. BleepingComputer refers to the incident as occurring “last year”; SecurityWeek dates it to 2024.
In a separate account of the aftermath, BleepingComputer identifies Eric Council Jr. as the hacker in the @SECGov compromise and reports that he pleaded guilty in February 2025. He received a 14-month prison sentence for participating in a conspiracy to manipulate Bitcoin’s value through the compromised account.
For the current incident, Microsoft’s stated response is that it secured @Microsoft, removed the unauthorized posts, and is continuing its investigation. The company has not disclosed the access method in the reports.
Sources
This article is an original reworking based on the sources below.




