Microsoft’s official X account was hijacked on Thursday, October 2, 2026, and used for roughly 30 minutes to promote an unauthorized cryptocurrency built around Clippy, the paperclip assistant from earlier editions of Microsoft Office, according to Crypto.news.
The attackers did not simply post a link. They changed the account’s profile picture to an image of Clippy, followed a profile promoting the token, and reposted one of that account’s messages, Crypto.news reported. The posts vanished about 30 minutes later, and an apology message appeared, then was also deleted. Users grabbed screenshots before it disappeared.
Also readSEC Proposes Crypto Custody Rules for Advisers and Funds
Key facts
- Microsoft confirmed unauthorized access to its X account and said the account had been secured and the unauthorized posts removed, with an investigation into how the breach occurred.
- The token promoted was CLIPPY, and an account named Clippy MSFT was among its promoters, claiming associated liquidity pools held more than $200,000, according to Crypto.news.
- Cryptobriefing reported the hijacked @Microsoft account has over 13 million followers and that the attack lasted approximately 30 minutes before Microsoft regained control.
- A Microsoft spokesperson told Cryptobriefing the company “has not authorized, sponsored, endorsed, or granted permission” for any cryptocurrency token tied to Clippy, Microsoft, or $MSFT.
- In 2024, attackers hijacked Microsoft India’s X account, which had more than 211,000 followers, to impersonate Keith Gill and push a fake GameStop token presale, News.bitcoin noted.
A deleted statement and a blunt denial
After the promotional activity ended, a separate statement briefly appeared on Microsoft’s account. It said the company had not authorized anyone to promote a cryptocurrency using its intellectual property, including Clippy, and that it would pursue legal action to have the token and related marketing removed. The message also rejected any link between the token and Microsoft’s MSFT ticker, adding that holding such a token gave no ownership rights in Microsoft Corporation. That statement was subsequently deleted.
Cryptobriefing carried a shorter, sharper version of the company’s position from a Microsoft spokesperson, who said permission had not been granted for the creation, promotion, or use of any token associated with Clippy, Microsoft, or $MSFT. Cryptobriefing also reported the impersonator account that claimed a Clippy connection has since been suspended, and that there was no immediate impact on Microsoft shares or on digital assets. Promoters’ claims that real Microsoft shares backed the liquidity pools remained unverified, and Microsoft’s deleted statement denied any official link.
Also readCalacanis Calls Meme Coins a 'Giant Scam,' Denies Any Involvement
Why it matters
The episode fits a pattern of attackers renting the credibility of large corporate accounts for short windows. Crypto.news noted earlier breaches of Robinhood CEO Vlad Tenev’s account, which promoted a fake Vladhood meme coin in July, and accounts tied to SpaceX and Starlink. Cryptobriefing judged that the repeat use of Microsoft accounts, from the India profile in 2024 to the main one now, suggests attackers view large corporate profiles as worth repeated attempts. News.bitcoin reported that the SpaceX-related promotion reached a $2 million market cap before collapsing to zero, illustrating how quickly these schemes can end.
For ordinary users, the recurring warning signs are sudden token announcements from companies with no crypto history, unexpected profile changes alongside a promotion, and staged interactions with lookalike accounts. The U.S. Securities and Exchange Commission’s investor education office and enforcement division warned in a February 6 alert against making investment decisions based solely on social media posts, noting fraudsters may impersonate professionals or claim ties to well-known finance figures.
What to watch
Microsoft said it is continuing to investigate the circumstances of the breach. Whether the company follows through on the legal action outlined in its deleted statement, and what X does about the accounts involved, are the concrete threads to track. The comparison with the 2024 Microsoft India hijack also matters: that earlier case ended with the account restored, but the playbook has since been reused.
Sources: crypto.news, Cryptobriefing, News.bitcoin




