Crypto scammers hijack Microsoft’s official X account to push a fake Clippy token
Attackers controlled the @Microsoft account for approximately 30 minutes and used it to promote a fraudulent $Clippy token
For approximately 30 minutes on Thursday, October 2, 2026, Microsoft’s official X account was not really Microsoft’s. Unknown attackers took over @Microsoft, which has over 13 million followers, and used it to promote a fraudulent crypto token called $Clippy.
How the $Clippy hijack played out
The attackers did more than post a link. They changed the account’s profile picture, a small cosmetic edit that helps a scam look like an official rebrand.
They also had the hijacked account interact with an impersonator account. That account claimed a connection to Clippy, the nostalgic virtual assistant character tied to Microsoft, and has since been suspended.
Microsoft regained control within approximately 30 minutes. The company confirmed the access was unauthorized, removed the misleading posts, secured the account, and said it was investigating the incident.
A Microsoft spokesperson also issued a blunt denial covering the token, the character, and even the company’s stock ticker:
“Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT.”
There was no immediate impact on Microsoft shares or on digital assets.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
A familiar playbook, and a familiar target
This is not the first time a Microsoft account has been turned into a billboard for a token. In 2024, the Microsoft India account was hijacked in a similar incident.
What this means for crypto investors and corporate brands
A few warning signs show up again and again in these incidents:
Sudden token announcements from companies with no history of launching crypto products deserve immediate suspicion.
Unexpected profile changes, like a new avatar appearing alongside a promotion, can signal that someone other than the owner is at the controls.
Interactions with lookalike accounts are often staged to create the appearance of an official partnership.
Microsoft’s response time of approximately 30 minutes limited the damage. The repeat appearance of Microsoft accounts in these schemes, from the India account in 2024 to the main account now, suggests attackers see large corporate profiles as worth repeated attempts.
The $Clippy episode ended with the impersonator account suspended, the posts deleted, and a clear denial on the record.