LIVE · US TRENDS, UPDATED DAILY

Microsoft’s X Account Got Hacked, Then Spent 30 Minutes Shilling a Clippy Crypto Coin

Picture this. You open X on an ordinary Thursday and the official Microsoft account, 13 million followers strong, is suddenly begging for likes to bring back Clippy. The profile picture is the paperclip. The posts are hyping a crypto token. For a few surreal minutes, one of the biggest brands on earth looked like a memecoin promoter.

It was not a marketing stunt. It was not a rogue intern. Hackers had taken over @Microsoft and turned it into a billboard for a fake Clippy cryptocurrency, and by the time the company got the keys back, the damage, and the screenshots, were everywhere.

This is the kind of story that could only happen now: a nostalgia-soaked office mascot, a verified blue checkmark, and a crypto scam colliding in real time while millions watched.

Hand holding a smartphone with a glowing screen in a dark room, illustrating the half-hour takeover of Microsoft's X account

Thirty very strange minutes

According to reporting from ThreatBeat and WindowsForum, the takeover became visible on October 1 and stretched into October 2. For roughly half an hour, the attackers had full control of the voice of one of the most valuable companies in the world, and they used it exactly the way you would expect scammers to use it.

First, they swapped the profile picture to Clippy, the googly-eyed paperclip assistant that shipped with old versions of Microsoft Office. Then the account followed @clippymsftcto, an account impersonating Clippy, and reposted one of its messages. The repost asked how many likes it would take to bring Clippy back, setting the target at 500,000. It was a perfect engagement hook: part joke, part dare, engineered to travel.

X has since suspended the impersonator account. But during the window it was live, the scam had the most powerful distribution channel a crypto promoter could dream of: Microsoft’s own verified feed, piped straight to more than 13 million followers.

Why Clippy was the perfect disguise

Here is the clever part. A random crypto shill post from @Microsoft would have looked instantly suspicious. But a Clippy post? Microsoft has spent years leaning into Clippy nostalgia, joking about the paperclip, selling the merch, playing along every time the internet gets sentimental about the old Office days.

So when the hacked account started posting about bringing Clippy back, it did not trip everyone’s alarm bells right away. It read like one more brand joke. That is precisely why the attackers picked it. The scam did not need to build credibility from scratch. It borrowed Microsoft’s, wrapped in a mascot everybody already loves to laugh about.

Nostalgia is a powerful social engineering tool. Nobody fact-checks a paperclip.

Nostalgic 1990s office desk with an old CRT monitor and a paperclip, recalling the original Clippy assistant

The token, the ticker trick, and the oldest play in crypto

The token at the center of this was styled as $Clippy. Its promoters claimed it had a liquidity pool paired directly with $MSFT, which happens to be Microsoft’s actual stock ticker. One report put the claimed pool value at more than $200,000, with posts hinting the token was somehow backed by Microsoft stock.

None of that was true. A liquidity pool on a decentralized exchange has nothing to do with a company’s equity, and Microsoft says it has zero connection to the token or the people behind it. But the ticker trick is an old one: borrow the symbols of legitimacy, a famous brand, a real stock ticker, a beloved mascot, and let confused buyers fill in the rest.

This is the classic pump-and-dump shape. Hype a token, point a flood of attention at it, and let the buying frenzy do the work before anyone asks hard questions. The only new twist here was the delivery mechanism: instead of paying influencers, the scammers just stole the biggest microphone they could find.

A second account, @ClippyMSFT, kept promoting the token even after the original impersonator was suspended, which tells you something about how these operations are built. Take down one account and the backup is already posting.

Microsoft’s response, and the apology it deleted

Microsoft confirmed the breach through spokesperson Brent Colburn, who said the company had found unauthorized access to its account on X, including posts that did not come from Microsoft. The account was secured, the unauthorized posts were removed, and the company says its investigation is ongoing.

Then came the strange part. Microsoft posted a statement disavowing the token completely, saying it does not support, endorse, sponsor, or authorize any cryptocurrency or token, and warning that it would pursue legal action to get the token and related materials taken down. Then it deleted that post too.

Nobody outside the company knows exactly why the disavowal disappeared. Maybe it was a comms cleanup. Maybe legal wanted different wording. Either way, deleting your own denial in the middle of a public hack is a rough look, and screenshots of the apology were already circulating before it vanished. The internet keeps receipts.

As of now, the how remains unanswered. How did the attackers get in? Was two-factor authentication in place on one of the most followed corporate accounts on the platform? How long were they inside before anyone noticed? Microsoft has not said, and those are the questions that should make every brand manager lose sleep.

The uncomfortable lesson nobody wants to sit with

Strip away the Clippy jokes and this story is genuinely unsettling. The attackers did not need to hack a blockchain or break any encryption. They just needed thirty minutes inside a verified account, and suddenly a scam had the trust of 13 million followers.

We have trained ourselves to treat the blue checkmark as proof. Verified means real, real means safe. This hack is a reminder that verification only proves who an account belongs to, not who is typing. When the account itself is compromised, every signal we rely on, the checkmark, the follower count, the brand history, starts working for the attacker.

Security researchers have been saying this for years: high-follower brand accounts are cheap distribution for scams. What changed this week is the proof. It happened to Microsoft, a company that spends more on security than most countries, and it happened in broad daylight.

For the rest of us, the rule is simple and worth repeating. If an official account suddenly starts promoting a token, a wallet address, or limited liquidity, do not trust the checkmark. Wait for the company to confirm it somewhere else, on its website, in a press release, anywhere that is not the compromised feed. Treat the post as hostile until proven otherwise.

The bottom line

In the end, the Clippy coin episode will probably be remembered as one of the weirder footnotes of internet history: the day Microsoft’s X account got turned into a crypto hype page by strangers, with a paperclip as the mascot. It is funny until you realize how easily it worked, and how many people could have lost money in those thirty minutes.

Clippy spent the nineties popping up uninvited to offer help nobody asked for. This week, he popped up again, uninvited, offering something nobody should have accepted. Some things never change.

Enjoying Trendly?

We publish ten fresh US trend stories every day. Come back tomorrow for what’s next.

Keep reading