Microsoft’s official X account, which counts more than 13 million followers, was used on October 2 to push a cryptocurrency called $Clippy. The posts did not come from Microsoft, the company confirmed afterward, and it said the token has nothing to do with it.
The mechanics were thin but effective. An impersonator styled as the retired Office assistant, operating as @clippymsftcto, promoted the coin, and the hijacked corporate account followed and reposted that material, lending a stranger’s pitch the credibility of one of the best-known names in software.
The Clippy impersonator and the borrowed audience
According to BleepingComputer’s report by Sergiu Gatlan, the scammers claimed $Clippy “has a liquidity pool paired directly with $MSFT.” That phrasing borrows the ticker symbol of Microsoft’s stock to suggest an official tie-in. No such relationship exists, and the report notes the impersonation account has since been suspended.
The choice of mascot is deliberate. Clippy, the animated paperclip that offered writing help in Microsoft Office from the late 1990s, is a nostalgic meme with built-in recognition, so a token carrying its name needs little explanation to attract speculative buyers. Pairing that familiarity with an account followed by more than 13 million people is what makes an account takeover more valuable to a scammer than a fresh account would ever be.
BleepingComputer’s account does not give a price chart or a figure for how much money changed hands, and no source reviewed for this article supplies one, so the scale of any losses remains unreported. That absence matters, because the usual way to judge whether a scam like this worked is the size of the pool of buyers it drew in before the promotion stopped, and neither Microsoft nor the reporting offers a number to measure it by.
Microsoft’s statement and what it confirms
The company’s response was brief and came in two parts. In the first, Microsoft confirmed unauthorized access to its X account, acknowledged posts that “did not come from Microsoft,” and said the account had been secured with the unauthorized posts removed. The statement closes by saying the investigation is continuing, and that leaves the cause of the breach an open matter rather than a closed one.
A second sentence from Microsoft addressed the token directly: the company “does not endorse or have any affiliation with this token, its creators, or any related cryptocurrency project.” The statement does not say how attackers gained entry, whether a password, a session or a connected third-party application was involved, or how long they held control. Those details were still under investigation when BleepingComputer published on October 2, and the article credits The Verge with first reporting the incident, so the earliest public account of the takeover came from a technology outlet rather than from Microsoft itself.
A pattern of hijacked Microsoft-branded accounts
This is not the first time a Microsoft property on X has been turned toward crypto fraud. BleepingComputer recalls a June 2024 incident in which Microsoft India’s account was hijacked to promote a cryptocurrency wallet drainer, a different scam type that tries to empty a victim’s wallet once they connect it to a malicious site. The Benzinga India coverage of that episode carried the same basic shape: a trusted brand name, a short window of control, and a link to a crypto lure.
Other corporate accounts have been used the same way. TweakTown reported that official Xbox social media accounts were hacked to post a crypto scam, and The Block reported that on-chain investigator ZachXBT traced at least $440,000 in thefts after MicroStrategy’s account appeared to be hacked and pushed phishing messages. The October incident differs in its pitch, since it sold a speculative token rather than a drainer link, but it follows the same logic.
Pump-and-dump tokens and the liquidity-pool claim
BleepingComputer’s headline calls the episode a pump-and-dump scheme. In that model, the people who created a token hold most of the supply, a burst of promotion draws in buyers, and the creators sell into the demand before interest collapses. A claim that a token sits in a liquidity pool paired with a well-known asset is a standard way to make a new coin look tradable and legitimate, since the pool is what lets strangers swap into it.
A related BleepingComputer investigation into a wider X hacking spree described hijacked accounts feeding similar token promotions, which suggests the Microsoft takeover fits a broader market for stolen verified accounts rather than a one-off stunt. That reading comes from the earlier reporting and has not been confirmed for this specific incident, which Microsoft has still to explain in full.
What remains open is the entry point. Microsoft’s statement says an investigation continues, and until the company publishes how the account was compromised, the public record rests on a single confirmation of unauthorized posts and one disclaimer of any link to $Clippy.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell
- Doctors warn a silent liver disease now affects one in three American adults
- Hackers are hijacking outdated home routers, and the FBI named the models to check
- Older Teslas are wearing out in ways early owners never saw coming