Hackers hijacked Microsoft's official X account to promote an unauthorized Clippy-themed cryptocurrency, changing the profile picture and reposting token promotions before Microsoft removed the activity roughly 30 minutes later. Microsoft confirmed the breach and said it would pursue legal action over the unauthorized use of its branding.
Attackers took over Microsoft's X account and used it to push an unofficial token tied to Clippy, the paperclip assistant from earlier versions of Microsoft Office, according to The Verge. The account followed a profile promoting the token and reposted one of its messages, while the attackers also swapped Microsoft's profile picture for an image of Clippy.
Roughly 30 minutes after the promotional activity began, the posts disappeared and an apology briefly appeared on the account before it, too, was deleted. Users captured screenshots of the apology before it vanished. Microsoft later confirmed to The Verge that the posts had not originated from the company. According to The Verge: Microsoft said it was "continuing to investigate the circumstances".
Microsoft denies any link between the token and its shares
Before the apology was deleted, a separate statement on the account said Microsoft had not authorized anyone to promote a cryptocurrency using its intellectual property, including Clippy, and that it would pursue legal action to remove the token and its marketing. The statement also rejected any connection between the token and Microsoft's MSFT stock ticker, saying ownership of the token carried no ownership rights in Microsoft Corporation.
The token behind the promotion was identified as CLIPPY, with an account called Clippy MSFT named as one of the promoters. That account claimed its associated liquidity pools held more than $200,000, and some promoters alleged that actual Microsoft shares backed the pools. The share-backing claim remained unverified, and Microsoft's deleted statement explicitly denied authorizing any such use of its name.
Pattern of celebrity and corporate account hijacks continues
The Microsoft breach follows a string of similar incidents. On July 23, hackers used Robinhood CEO Vlad Tenev's X account to promote a fake Vladhood meme coin, which briefly reached a market capitalization of about $10 million before falling below $5 million once Robinhood confirmed the breach. Earlier that month, compromised SpaceX and Starlink accounts reposted promotions for a token called SCATMAN. A July 17 hack of Airbnb CEO Brian Chesky's account separately published a thread about blockchain-based asset tokenization.
A June 2024 attack on Microsoft India's X account, which had more than 211,000 followers, was used to impersonate trader Keith Gill and promote a fake GameStop token presale linked to a wallet-draining scheme, Bitcoin.com reported.
Regulators warn against trusting social media investment posts
The U.S. Securities and Exchange Commission has separately warned investors against making decisions based solely on social media posts. In a Feb. 6 investor alert, the agency said fraudsters may impersonate investment professionals or claim ties to registered brokers before directing users into investment group chats. In related guidance, the SEC said social media posts can create a false impression of legitimacy or suggest false popularity for an investment, and it cautioned against relying on celebrity endorsements when deciding whether to invest.
Source: crypto.news
Trading involves risk.