Newsroom
4 October, 2026 / News / AI / Tags: clippy, microsoft, apology, account, nostalgia

Attackers gained control of Microsoft’s official X account and used a nostalgic Clippy revival promise plus a fake apology to drive traffic toward an unbacked cryptocurrency token
Hackers seized Microsoft’s official X account and repurposed it to advertise a cryptocurrency token tied to the company’s famous paperclip assistant. The posts promoted what attackers called the $Clippy token and claimed the Microsoft paperclip would return once the campaign reached 500,000 likes on the platform. They also linked the token to Microsoft stock using the symbol MSTF, an association with zero basis in reality. Reposts from a linked account pushed the scheme forward while the fraudulent campaign remained active on the compromised profile.
The operation leaned heavily on the assistant’s iconic image to spark engagement. Users were encouraged to participate in the engagement challenge as a way to “revive” Clippy. No connection existed between the token and the actual company, and X later suspended the related account that had been used to amplify the posts.
Shortly after the account takeover, a statement appeared claiming Microsoft had distanced itself from the events and threatened legal action against those responsible. The message was not issued by the company itself. Its timing and content were likely intended to sow doubt among followers and make it harder to determine whether control of the account had been recovered.
This fabricated corporate response circulated alongside the promotional activity and contributed to the overall deception surrounding the hijacking.
Microsoft has encountered similar compromises in the past. In June 2024, the company’s India-based X account was targeted to promote a GameStop cryptocurrency presale. The posts referenced Keith Gill, known online as Roaring Kitty, and directed users to a website that security experts warned could drain cryptocurrency wallets. That campaign proved more immediately risky than the recent nostalgia-driven token push.
Public information on the exact method of access to Microsoft’s account and the financial gains from the operation remains unavailable. The creative execution of the Clippy campaign, including the engagement metric and the fabricated apology, shows attackers continuing to exploit the tech giant’s brand authority to advance cryptocurrency schemes. Security observers have noted how quickly social platforms can respond once the fraud is reported, but the tactics remain effective in the short term.




