Hackers hijack Microsoft’s X account to promote Clippy crypto scam
Even a Microsoft "apology" post turned out to be fake.

Image by Photo by Gary Hershorn via Getty Images
- Hackers compromised Microsoft’s official X account and used it to promote an unauthorized Clippy-themed cryptocurrency.
- The account has 13 million followers, and its profile picture briefly changed to Clippy.
- Microsoft said it secured the account, removed the posts, and continues to investigate.
- X shut down one fake Clippy account, but another still promoted the token.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Have you been missing Clippy? Microsoft’s iconic paperclip has just made a surprising comeback as part of a crypto scam. The company’s official X account got hijacked to promote an unauthorized Clippy-themed cryptocurrency.
The tech giant’s X account, which has 13 million followers, started following a Clippy crypto account and reposted one of its tweets on Thursday.
Clippy is Microsoft’s old animated paperclip assistant, which was introduced with Office 97 and later removed because of its intrusive pop-ups. Microsoft’s profile picture was also replaced with one of Clippy.
About 30 minutes after the original posts were taken down, the account published a bizarre apology, which was also soon deleted. Microsoft confirmed that it didn’t publish any of those tweets.
"We are aware of a cryptocurrency token being promoted in connection with $MSFT stock, including the unauthorized use of the Clippy brand and Microsoft-related intellectual property. Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT," the deleted and apparently fake tweet read.
X has since shut down the @clippymsftcto account posing as Clippy, but a second account (@ClippyMSFT) is still promoting a $Clippy token, claiming that it "has a liquidity pool paired directly with $MSFT."
Microsoft later confirmed that its account had been compromised and said the unauthorized posts had been removed.
“We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft,” said Microsoft spokesperson Brent Colburn, according to The Verge. “The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.”
It’s not the first time scammers have hijacked an official Microsoft account. In June 2024, attackers used Microsoft's India X account to impersonate meme-stock trader Roaring Kitty (Keith Gill) and promote a fake GameStop crypto presale to drain victims’ wallets.