Microsoft has acknowledged that intruders briefly controlled its official X account, then used it to promote a crypto project dressed up as a software-era mascot.
Its audience runs past 13 million people. The Verge reports that the account began following a crypto handle and boosted a post from it. The avatar was changed to Clippy, the paperclip helper that shipped years ago with Office.
The post originated from @clippymsftcto, a handle that pretended to be Clippy. That account has since been suspended. A companion account spent the episode touting a $Clippy token and claimed the coin’s liquidity pool traded alongside $MSFT.
The posts eventually came down. Roughly half an hour later a note appeared on the Microsoft account and was pulled shortly afterward without comment. In it, the company said it knew of a token being pitched against its stock and using the Clippy name without permission. The note also read: “Microsoft does not support, endorse, sponsor, or authorize any cryptocurrency or crypto-related token.”
A Microsoft spokesperson told The Verge the company had confirmed unauthorized access, that the offending posts were not Microsoft’s, and that the account was secured while investigators work.
Microsoft has not explained the intrusion. Possible routes include SIM swapping the phone number on the account, as happened with the SEC’s X profile in 2024; hijacking the password-reset inbox; lifting browser session cookies with infostealer malware; or abusing a third-party social tool trusted to post on the company’s behalf.
