Newsroom

Microsoft X Account Hijacked to Promote Fake Clippy Token and Scam

4 October, 2026   /   News   /  AI   /   Tags:  clippy, microsoft, apology, account, nostalgia

Microsoft X Account Hijacked to Promote Fake Clippy Token and Scam

Attackers gained control of Microsoft’s official X account and used a nostalgic Clippy revival promise plus a fake apology to drive traffic toward an unbacked cryptocurrency token

Attack Uses Nostalgia to Promote Cryptocurrency

Hackers seized Microsoft’s official X account and repurposed it to advertise a cryptocurrency token tied to the company’s famous paperclip assistant. The posts promoted what attackers called the $Clippy token and claimed the Microsoft paperclip would return once the campaign reached 500,000 likes on the platform. They also linked the token to Microsoft stock using the symbol MSTF, an association with zero basis in reality. Reposts from a linked account pushed the scheme forward while the fraudulent campaign remained active on the compromised profile.

The operation leaned heavily on the assistant’s iconic image to spark engagement. Users were encouraged to participate in the engagement challenge as a way to “revive” Clippy. No connection existed between the token and the actual company, and X later suspended the related account that had been used to amplify the posts.

Fake Apology Added Layer of Confusion

Shortly after the account takeover, a statement appeared claiming Microsoft had distanced itself from the events and threatened legal action against those responsible. The message was not issued by the company itself. Its timing and content were likely intended to sow doubt among followers and make it harder to determine whether control of the account had been recovered.

We're back on X.
Our previous account (36crypto2) is currently unavailable while we continue working through the appeal process. In the meantime, this is our new official account. While you are on this page, please support us by sharing and following.
36Crypto (@36crypto1)

This fabricated corporate response circulated alongside the promotional activity and contributed to the overall deception surrounding the hijacking.

Earlier Incident Offers Pattern

Microsoft has encountered similar compromises in the past. In June 2024, the company’s India-based X account was targeted to promote a GameStop cryptocurrency presale. The posts referenced Keith Gill, known online as Roaring Kitty, and directed users to a website that security experts warned could drain cryptocurrency wallets. That campaign proved more immediately risky than the recent nostalgia-driven token push.

Details on Compromise and Impact Limited

Public information on the exact method of access to Microsoft’s account and the financial gains from the operation remains unavailable. The creative execution of the Clippy campaign, including the engagement metric and the fabricated apology, shows attackers continuing to exploit the tech giant’s brand authority to advance cryptocurrency schemes. Security observers have noted how quickly social platforms can respond once the fraud is reported, but the tactics remain effective in the short term.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.