---
title: "Microsoft X Hackers Push Unauthorized Clippy Crypto Token"
date: 2026-10-02
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/10/microsoft-x-account-hacked-clippy-crypto.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Microsoft X Hackers Push Unauthorized Clippy Crypto Token

Attackers hijacked Microsoft’s official X account on Thursday, October 1, and used it to boost a Clippy impersonator pushing a $Clippy crypto token. Microsoft confirmed the unauthorized access and removed the posts.

## What Happened?

- Microsoft confirmed that attackers gained unauthorized access to its X account and published posts the company did not write.
- The hijacked @Microsoft account, which has over 13 million followers, reposted a now-suspended Clippy impersonator called @clippymsftcto.
- Microsoft said it never authorized any crypto token linked to Clippy, Microsoft, or $MSFT, and it plans legal action.
- A second account, @ClippyMSFT, kept promoting the token after the takeover and claimed a link to Microsoft stock.

## A Clippy repost carried a crypto pitch

The takeover began when **@Microsoft followed @clippymsftcto** and reposted its message asking how many likes it would take to bring Clippy back. The Verge first reported the posts, and the pattern looked like a pump-and-dump scheme built around a $Clippy token.

The Clippy angle probably helped the scam blend in. Microsoft has played along with Clippy nostalgia over the years. A “**bring back Clippy**” repost from the real account could pass as one more brand joke.

Another account, @ClippyMSFT, reposted Microsoft’s tweet and stayed live after the original impersonator was suspended. It claimed the token has a liquidity pool “**paired directly with $MSFT.**” That pitch borrows the ticker of a company that says it has no tie to the project.

Microsoft confirmed “**unauthorized access to our account on X including posts that did not come from Microsoft.**” The company said it has secured the account, removed the posts, and is still investigating.

> ‼️ BREAKING: Microsoft's official X account with over 13 million followers was hijacked to boost a fake Clippy account tied to a crypto scam.  
>   
> Microsoft wrote an apology threatening legal action, then deleted that post too.  
>   
> The account followed and reposted the impersonator and… [pic.twitter.com/0pcOBlN2n4](https://t.co/0pcOBlN2n4)
> 
> — International Cyber Digest (@IntCyberDigest) [October 2, 2026](https://x.com/IntCyberDigest/status/2105962585623232774?ref_src=twsrc%5Etfw)

 In a since-deleted post, Microsoft apologized and said it “**has not authorized, sponsored, endorsed, or granted permission**” for any token tied to Clippy, [Microsoft](https://sqmagazine.co.uk/microsoft-statistics/), or $MSFT. That post also told readers to rely only on Microsoft’s official channels. The advice landed awkwardly, since an official channel had just carried the pitch.

Microsoft’s statements confirm the account takeover and the unauthorized posts. They don’t explain the rest:

- **How did the attackers get into @Microsoft, and did the account use two-factor authentication?**
- **How long did they hold the account before Microsoft noticed?**
- **How many people bought $Clippy, and how much did they lose?**
- **Who created the token and runs @ClippyMSFT?**

## Microsoft’s X accounts have been hit before

This isn’t the first time [crypto scammers](https://sqmagazine.co.uk/cybersecurity-in-cryptocurrency-statistics/) have used a Microsoft handle. In June 2024, attackers hijacked @MicrosoftIndia, with over 211,000 followers, to impersonate Roaring Kitty, the handle of meme stock trader Keith Gill. They sent followers to **presaIe-roaringkitty\[.\]com**, a domain spelled with a capital I in place of an L. The site pitched a fake GameStop (GME) crypto presale and drained wallets that connected and approved transactions.

The wider X problem is much bigger than one brand. In December 2023, blockchain threat analysts at ScamSniffer tied the MS Drainer kit to roughly **$59 million** in stolen crypto. The losses hit 63,000 people through a single Twitter ad push between March and November. Broader [wallet drainer incident data](https://sqmagazine.co.uk/phishing-and-wallet-drainer-incidents-statistics/) shows how often these kits follow social media lures, and the [BNB Chain X account hijack](https://sqmagazine.co.uk/bnb-chain-x-account-hack-phishing-warning/) fit the same pattern.

## Why It Mattes?

Government accounts aren’t immune either. Attackers seized the **SEC’s @SECGov account** through SIM swapping and posted a fake Bitcoin ETF approval. The post caused a temporary but sharp spike in Bitcoin prices. Eric Council Jr. pleaded guilty in February 2025, and the Justice Department said he was [sentenced to 14 months in prison](https://www.justice.gov/usao-dc/pr/alabama-man-sentenced-hack-sec-x-account-spiked-value-bitcoin) for his role.

Microsoft’s next stated step is legal action to get the unauthorized token and related materials taken down. Anyone who connected a wallet to a site the Clippy accounts promoted should revoke token approvals. Moving remaining funds to a new wallet helps reduce risk. Microsoft’s own advice to trust official channels only works while those channels stay in the right hands.