Hackers breached Microsoft’s official X account to promote an unauthorized cryptocurrency token called CLIPPY. The token used the paperclip assistant visual from legacy versions of Microsoft Office as its main draw. The illicit promotion ran on the timeline for 30 minutes before being taken down by the company.
During the incident, the Microsoft account changed its primary profile picture to an image of Clippy. The corporate handle also followed the profile promoting the CLIPPY token and reposted its messages directly to millions of followers.
Microsoft immediately confirmed that its account had been secured and the breach was under investigation. “We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft,” the company stated.
Stock Claims Spark Legal Action Threats
The token promoters operated using an account named ‘Clippy MSFT’ and claimed to have a liquidity pool valued at over $200,000. Some promoters even circulated claims that actual Microsoft stock backed the liquidity pool.
Microsoft explicitly refuted the claims regarding stock backing. The company also stressed that CLIPPY token holders gain absolutely no ownership rights in Microsoft Corporation. In a statement that was later deleted, Microsoft stated it would take legal action to remove the token and all associated marketing materials.
Pattern of Verified Account Hijacks
The Microsoft incident adds to an ongoing string of social media breaches. In June 2024, hackers took over the Microsoft India X account, which had 211,000 followers. The regional account was used to impersonate Roaring Kitty and promote a fake GameStop token launch.
Crypto industry executive profiles have also been targeted. In July 2026, the X account belonging to Robinhood CEO Vlad Tenev was compromised to distribute promotions for a memecoin called VLAD. The trap token briefly pumped its market cap to $10 million before crashing sharply.
The recurring attack pattern highlights the dangers of following information from verified accounts without cross-verification. Once a corporate brand suddenly appears to claim backing for a new memecoin, that is where the scam begins.
Reported by crypto.news.
Also read: 1,500 ATMs in the US Hacked by Tren de Aragua Gang - Stolen Funds Flow to 7 TRON Addresses
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




