Microsoft X account hijacked to promote unofficial Clippy token
Attackers used Microsoft's X account to push a Clippy-themed token, and the posts came down about 30 minutes later.
Key takeaways
- Gone in 30 minutes. The promotional posts and an apology tweet were removed roughly 30 minutes after they appeared.
- Liquidity claim unverified. Promoters said liquidity pools held more than $200,000, but the share-backing claim was not verified.
- Prior Microsoft breach. In 2024, attackers hijacked Microsoft India's X account, which had more than 211,000 followers.
What happened
Microsoft's official X account was hijacked on Thursday and used to promote an unauthorized crypto token tied to Clippy, the paperclip assistant from earlier versions of Microsoft Office.
The account followed a profile that was promoting the token, reposted one of its messages and swapped its profile picture for an image of Clippy.
The promotional posts came down and an apology tweet appeared roughly 30 minutes later, and that tweet was deleted almost as quickly.
Microsoft confirmed the unauthorized access, said the account had been secured and the posts removed, and said it was still investigating how the access happened.
A statement that briefly appeared and was then deleted said Microsoft had not authorized anyone to promote a cryptocurrency using its intellectual property, including Clippy. It rejected any connection between the token and ownership of Microsoft shares, and said holding the token gave no ownership rights in Microsoft Corporation.
Why it matters
The token trades as CLIPPY. An X account called Clippy MSFT promoted it and said its liquidity pools held more than $200,000.
Some promoters also said the pools were backed by actual Microsoft shares. That claim has not been verified, and Microsoft's deleted statement denied any link to its stock.
The hijack follows a pattern of crypto scams on X. In July, attackers took over Robinhood CEO Vlad Tenev's account to promote a fake token called Vladhood, and ten days earlier an account linked to SpaceX pushed a meme coin that Starlink's compromised account then shared.
What the data shows
- Promoters said the token's liquidity pools held more than $200,000.
- The SpaceX-linked token reached a $2 million market cap before crashing to zero.
- Microsoft India's X account had more than 211,000 followers when it was hijacked in 2024.
Background
- In July, attackers took over Robinhood CEO Vlad Tenev's X account to promote a fake token called Vladhood.
- Ten days before that, an apparently hacked account linked to SpaceX promoted a meme coin that was then shared by Starlink's compromised X account.
What is still unclear
- It is unclear why Microsoft deleted its lengthy apology tweet.
- Microsoft said it was investigating how the access occurred, and no cause has been given.
- The claim that Microsoft shares backed the liquidity pools has not been verified.
Questions readers ask
Did Microsoft launch a Clippy meme coin?
No. Microsoft said it had not authorized anyone to promote a cryptocurrency using its intellectual property, including Clippy.
Does the CLIPPY token give holders Microsoft shares?
No. The deleted statement said Microsoft's MSFT shares had no connection with a cryptocurrency carrying a similar name, and that token ownership gave no ownership rights in Microsoft Corporation.
How long were the posts on Microsoft's X account?
The promotional posts were removed roughly 30 minutes later, and an apology tweet that appeared around then was deleted almost as quickly.
Have other X accounts been hijacked for crypto scams?
Yes. Previous breaches targeted Robinhood CEO Vlad Tenev and accounts associated with SpaceX and Starlink, and Microsoft India's account was hijacked in 2024.