Microsoft’s official X account, which has more than 13 million followers, was hijacked on October 1 and briefly used to promote a fake Clippy-themed cryptocurrency, the company confirmed in a statement to The Verge . The takeover briefly turned one of the most-followed corporate accounts on the platform into a vehicle for cryptocurrency fraud. The account has since been secured and the unauthorized posts removed.
What happened to the account
On the afternoon of October 1, the @Microsoft account began following a Clippy crypto account called @clippymsftcto, reposted one of its messages, and had its profile picture replaced with Clippy, the animated paperclip assistant Microsoft retired years ago. The posts were then taken down, and a strange apology appeared on the account roughly 30 minutes later before being deleted without explanation. The account behind the reposted message posed as Clippy and has since been suspended. The brief takeover was still enough to expose millions of followers to the scheme before it was stopped.
A fake token paired with Microsoft’s ticker
A second account involved in the incident kept pushing a so-called $Clippy token, telling followers its liquidity pool was paired with $MSFT. The short apology that Microsoft later deleted said the company was aware of a token being marketed in connection with its stock that used the Clippy brand without permission. “To be clear, Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token,” the now-deleted post read. There is no evidence the fake token was ever connected to Microsoft, and the company moved quickly to distance itself.
Microsoft’s response and a familiar pattern
Microsoft spokesperson Brent Colburn confirmed the breach in a statement. “We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft,” Colburn said. “The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.” Microsoft has not said how the attackers gained access, and the incident echoes the January 2024 takeover of the Securities and Exchange Commission’s X account, which regulators later attributed to a SIM swap. Security researchers note that account takeovers increasingly rely on SIM swaps or compromised credentials rather than any exploit of the platform itself.
The compromise adds to a widening pattern of crypto theft and fraud this year, from the $387 million Bitget hack attributed to North Korea to social-engineering schemes such as the $16 million Coinbase phishing ring that ended in a Brooklyn man’s prison sentence. The company said it is continuing to investigate how the attackers obtained access.


