Microsoft has confirmed that its official X account was compromised after attackers used the profile to promote an unauthorized cryptocurrency tied to Clippy, the company’s old Office assistant.
The account, which has more than 13 million followers, briefly followed and reposted content from an account impersonating Clippy. Microsoft’s profile picture was also replaced with the paperclip character during the incident.
One of the accounts involved promoted a $CLIPPY token and even claimed that its liquidity pool was paired with Microsoft stock, or $MSFT. Microsoft did not endorse the token and later secured its X account.
A Microsoft spokesperson said the company had confirmed “unauthorized access” and removed posts that did not originate from Microsoft. The company said it was continuing to investigate how the compromise happened.
Hackers Used Microsoft’s Brand to Give the Token Credibility
The attack appears to have followed a familiar meme-coin playbook: compromise a trusted account, use its audience to give a newly created token an appearance of legitimacy, and direct attention toward the asset before the account owner regains control.
The incident lasted roughly 30 minutes, according to reports, but the attackers had access to one of the most recognizable corporate accounts on X during that window.
Microsoft also made clear that it had not authorized, sponsored or endorsed any cryptocurrency connected to Clippy, Microsoft or the MSFT ticker.
The setup resembles previous X account hijacking scams in which attackers used compromised high-profile profiles to promote meme coins. One earlier campaign involving 15 hacked accounts generated nearly $500,000, according to blockchain investigator ZachXBT.
Fake Tokens Keep Targeting Trusted Brands
The Microsoft breach is part of a broader pattern in which scammers borrow familiar brands, celebrities or official accounts to create artificial credibility around new tokens.
Coinpaper recently covered fake branded tokens after CoinMarketCap warned that scammers were promoting unofficial “CMC Tokens” despite the company never launching one.
Similar account compromises have previously targeted crypto projects and public figures, including a Drake meme coin scam that generated millions of dollars in trading volume before being exposed.