Hackers took over Microsoft’s official X account to promote an unauthorized Clippy-themed cryptocurrency, using one of the world’s most recognizable corporate handles to push a token that promoters claimed — without any verified evidence — was backed by real Microsoft shares.
The Verge first reported the breach, and Microsoft has since confirmed it. “We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft,” the company said in a statement, adding that the account had been secured, the unauthorized posts removed, and the circumstances were under investigation.
## Thirty minutes of chaos
The incident unfolded on Thursday when Microsoft’s account began following a profile promoting the token and reposted one of its messages. The attackers also swapped Microsoft’s profile picture for an image of Clippy, the famously persistent paperclip assistant from earlier versions of Microsoft Office — a character with genuine nostalgic pull among millennials, which is precisely what makes it effective bait for a memecoin.
Roughly 30 minutes later the promotional posts disappeared, and an apology appeared — before that message too was deleted. Users had already captured screenshots.
The token was identified as CLIPPY, with an account named Clippy MSFT among its promoters. That account claimed the associated liquidity pools held more than 200,000 USD and alleged that actual Microsoft shares backed those pools. The share-backing assertion remained unverified, and Microsoft’s own response demolished any pretense of legitimacy.
## Microsoft’s deleted statement drew the line
A separate statement briefly appeared on Microsoft’s account after the promotion ended. In it, the company rejected any use of its intellectual property — including Clippy — for unauthorized cryptocurrency promotion and said it would pursue legal action to remove the token and its marketing.
Most significantly for investors who might have been tempted, the statement explicitly rejected attempts to connect the token with Microsoft’s stock ticker. Microsoft’s MSFT shares, it said, have no connection with a cryptocurrency carrying a similar name, and ownership of such a token confers no ownership rights in Microsoft Corporation. It is a remarkably direct repudiation: not merely “this isn’t ours,” but “this cannot ever be an equity claim on us.”
## Part of a worsening pattern
The Microsoft hijack is the latest in a string of high-profile X account breaches used to launch or pump tokens. On July 23, hackers used Robinhood CEO Vlad Tenev’s account to promote a fake meme coin called VLAD, falsely described as Robinhood Chain’s official mascot with a promised app listing. That token briefly reached a market capitalization of about 10 million USD before collapsing below 5 million USD once Robinhood confirmed the breach, and the chain’s explorer attached a potential-scam warning after recording more than 1,800 transactions.
Earlier in July, accounts associated with SpaceX and Starlink were compromised to repost promotions for another token. And in June 2024, attackers seized Microsoft India’s X account — over 211,000 followers — to impersonate Roaring Kitty trader Keith Gill and push a fake GameStop token presale linked to a wallet-draining scheme. Microsoft, in other words, has been here before with a regional account; this week’s incident hit the corporate flagship.
The mechanics keep repeating because they work: a verified account with an enormous audience, a nostalgic or meme-friendly brand, a liquidity claim that sounds substantial, and a tight window before the breach is caught. Thirty minutes of exposure across millions of followers is enough to move a token’s price and trap buyers who assume a blue check means endorsement.
## What regulators want investors to remember
The SEC’s investor education office and enforcement division have repeatedly warned about exactly this attack surface. In a February 6 investor alert, the agencies cautioned against making investment decisions based solely on social media posts or apps, noting that fraudsters may impersonate investment professionals or claim affiliation with well-known figures and registered firms before steering victims into group chats.
Separate SEC guidance on social media investment fraud stresses that online posts can create a false impression of legitimacy or suggest broad buying interest that does not exist. Impersonation, crypto investment scams and market manipulation rank among the schemes the agency says spread most effectively through social platforms — and it advises investors to verify the background of anyone offering an investment rather than trusting a testimonial or an endorsement, celebrity or otherwise.
The CLIPPY episode adds a corporate twist: when the brand itself is hijacked, even healthy skepticism toward unofficial accounts offers no protection, because the promotion came from the official one. The takeaway for crypto users is straightforward — a token is not equity, an account post is not a prospectus, and a claim of share backing without verifiable proof is worth exactly what the hackers’ screenshot was worth the moment Microsoft deleted it.
A 200k liquidity pool supposedly backed by Microsoft shares, a company worth trillions. The scale mismatch alone should have stopped anyone, yet the 30 minute window was enough.
it looks like youre trying to rug. would you like help? yes / yes
clippy offering to help you lose money is the most on-brand rug ever. 200k liquidity backed by microsoft shares lmao sure buddy
wildest part is people aped in within 30 minutes of the account flip. screenshots everywhere before the apology even got deleted
30 minutes was plenty. The liquidity pool claim of 200k with Microsoft share backing is such an obvious lie, yet the nostalgia bait absolutely caught people.
the apology getting deleted too is my favorite detail. whoever held the keys was still in there scrubbing posts while comms tried to clean up
deleting the apology too lmao. whoever had the session token just cleaned up and dipped. how does MSFT of all orgs not have hardware 2FA on the main account
for real, a stolen session cookie bypasses every hardware key. someone clicked a phish and the whole X account went Clippy mode in minutes
Exactly. And the deeper problem is X itself: no forced re-auth when a verified corporate account posts from a new device. 30 minutes of live rug promotion on an account that big is on the platform too, not just whoever clicked the phish
right, 2FA on login does nothing when an attacker rides an already authenticated session. the cookie was the whole ballgame
millennial nostalgia is genuinely elite bait. whoever ran this knew exactly which demo would buy a clippy coin