BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

Hackers use Microsoft’s X account to push unofficial Clippy token

Hackers have used Microsoft’s official X account to promote an unauthorized Clippy-themed token, with the promotional activity removed roughly 30 minutes later, according to The Verge. Summar

AnonymousCryptoCompass newsroom
October 3, 2026
6 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

Hackers have used Microsoft’s official X account to promote an unauthorized Clippy-themed token, with the promotional activity removed roughly 30 minutes later, according to The Verge.

Summary
  • Microsoft confirmed unauthorized access and said it had secured its account and removed the posts.
  • A deleted statement rejected any connection between the Clippy token and ownership of Microsoft shares.
  • Token promoters claimed liquidity exceeded $200,000 and alleged share backing, without verified evidence.
  • Previous account breaches targeted Robinhood CEO Vlad Tenev and accounts associated with SpaceX and Starlink.

The Verge reported that Microsoft confirmed the breach after its account promoted an unofficial cryptocurrency associated with Clippy, the paperclip assistant from earlier versions of Microsoft Office.

In its response to the publication, Microsoft said the account had been secured and the unauthorized posts removed. The company also said it was investigating how the access occurred.

“We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft.”

According to the report, a separate statement briefly appeared on Microsoft’s account after the promotional activity ended. The message rejected the token’s use of Microsoft branding and said the company would pursue legal action to remove the token and related marketing.

You might also like: Bitget hacker moves $6.3 million into Bitcoin after THORChain rejects freeze request

In the subsequently deleted statement, Microsoft said it had not authorized anyone to promote a cryptocurrency using its intellectual property, including Clippy. The message also rejected attempts to connect the token with the company’s stock ticker.

According to the report, the statement said Microsoft’s MSFT shares had no connection with a cryptocurrency carrying a similar name. It added that ownership of such a token did not give holders ownership rights in Microsoft Corporation.

For investors encountering the promotion through Microsoft’s account, the company’s statement addressed both the unauthorized branding and the claim of a connection to its shares. Microsoft rejected a corporate relationship with the token and said token holders received no ownership interest in the business.

The supplied report identified the cryptocurrency as CLIPPY and named Clippy MSFT as one of the accounts promoting it. That account claimed that associated liquidity pools held more than $200,000.

Some promoters also alleged that actual Microsoft shares backed the pools, according to the report. The share-backing assertion remained unverified, while Microsoft’s deleted statement explicitly denied authorizing the token’s use of its name and intellectual property.

The report described the legal action as a plan set out in the deleted message. Microsoft’s separate confirmation to The Verge focused on securing the account, removing unauthorized posts and investigating the breach.

The hijack used follows, reposts and a Clippy profile image

During the incident on Thursday, Microsoft’s account followed a profile promoting the unofficial token and reposted one of its messages, according to The Verge. The attackers also changed Microsoft’s profile picture to an image of Clippy.

Rather than relying only on a promotional message, the unauthorized activity placed the character on Microsoft’s own profile and used the account’s repost function to circulate the token-related content, the report said.

Roughly 30 minutes later, the promotional posts disappeared, and an apology appeared, according to the supplied account of events. Users captured screenshots before that message was also deleted shortly afterward.

Microsoft subsequently confirmed directly to The Verge that the posts had not originated from the company. In the same response, it said it was “continuing to investigate the circumstances.”

The supplied report also recalled a June 2024 attack on Microsoft India’s X account. Bitcoin.com reported that attackers used the profile, which had more than 211,000 followers, to impersonate Keith Gill, the trader known as Roaring Kitty, and promote a fake GameStop token presale linked to a wallet-draining scheme.

SEC guidance warns U.S. investors about social media impersonation

For U.S. investors, the SEC’s investor education office and enforcement division have issued guidance addressing investment promotions distributed through social platforms.

In a Feb. 6 investor alert, the agencies warned against making investment decisions based solely on social media posts or apps. The alert said fraudsters may impersonate investment professionals or claim to work for registered brokers and investment advisers.

According to the alert, advertisements can also claim an association with a well-known person in finance before directing users into investment group chats. The SEC advised investors to verify the background of anyone offering an investment.

In separate guidance on social media investment fraud, the SEC said online information can be inaccurate, incomplete or misleading. The agency warned that posts may create a false impression of legitimacy or suggest that large numbers of people are buying an investment.

The same guidance identifies impersonation, crypto investment scams and market manipulation among schemes distributed through social media. It also cautions investors against relying on celebrity endorsements or testimonials when deciding whether to invest.

July breaches promoted fake company tokens and tokenization posts

On July 23, crypto.news reported that hackers had used Robinhood CEO Vlad Tenev’s X account to promote a fake Vladhood meme coin. The unauthorized post described VLAD as Robinhood Chain’s official mascot and claimed the brokerage would list it on its trading app.

According to that report, Vladhood briefly reached a market capitalization of about $10 million before falling below $5 million after Robinhood confirmed the breach. The company said it was working with X to restore access and had removed the unauthorized post.

The July 23 coverage also said Robinhood Chain’s explorer attached a potential-scam warning to the token after recording more than 1,800 transactions. Robinhood had announced neither a listing nor recognition of Vladhood as its mascot.

Earlier in July, reporting on the SpaceX and Starlink breach described compromised accounts reposting promotions for SCATMAN. Published July 15, the report cited Lookonchain’s analysis of two wallets that sold tokens for approximately 73.7 ETH, worth about $135,000.

According to the cited analysis, one wallet sold 10 trillion tokens for 59 ETH, while another sold 59.28 million tokens for 14.7 ETH. The report said the promotional posts were removed and the accounts restored that evening.

A July 17 report documented a separate Brian Chesky account hack after the Airbnb chief’s profile published a thread about blockchain-based asset tokenization. According to that coverage, the deleted posts discussed ownership and financial markets without promoting a specific meme coin, fake presale, or cryptocurrency giveaway.

Chesky later confirmed the compromise in a post addressing the attacker and the crypto followers attracted by the unauthorized thread. Fortune’s reporting, cited in the July 17 article, said Airbnb worked with X to secure the account.

Read more: NEAR co-founder pitches AI pets, private trading and cross-chain payments