Someone took over Microsoftâs official X account and used it to promise you Clippyâs return in exchange for 500,000 likes. The bait was nostalgia. The goal was a fake cryptocurrency.
The token was called $Clippy, after the paperclip-shaped virtual assistant that many longtime Office users still remember with mixed feelings. Whoever controlled the account promoted it by reposting a related account. Xâs team has since suspended that fraudulent account.
The fake apology was the smartest part
The most unusual part of this hijacking came after the scam posts. Shortly after the compromise, a post on Microsoftâs account appeared to distance the company from the hack and threatened bad actors with legal action.
But Microsoft didnât publish that post either. The apology was fake too.
Thatâs a nasty move. If you follow a brand and see it disown a hack, youâd reasonably assume the real owners are back in control. Here, that assumption was the trap. The post was likely meant to confuse followers and make it harder to tell whether legitimate users had regained the account.
A stock pairing that didnât exist
The campaign also claimed the $Clippy token was paired with Microsoftâs own stock, which it listed as MSTF. That claim was absurd. There was no legitimate connection between the two.
The 500,000-like promise worked the same way. Asking people to like a post to bring back a beloved mascot is the kind of engagement request that spreads fast, and every share pushed the token in front of more people.
What we still donât know
Microsoft hasnât explained how the attacker got into the account. Thereâs also no word on how much money the scammers made from the campaign.
Those gaps matter. Without knowing how the account was breached, thereâs no way to judge whether the same weakness has been closed or is still open.
Microsoft has been here before
This isnât the first time a Microsoft X account has been turned against its followers. In June 2024, Microsoftâs India X account was hacked to promote Keith Gill, better known online as âRoaring Kittyâ of âGameStopâ fame.
That account was used to advertise a GameStop cryptocurrency pre-sale. Users were redirected to a website that could potentially drain their wallets, which made that attack more dangerous than the Clippy campaign, at least based on whatâs been disclosed so far.
The takeaway for you is simple. A verified corporate account posting about a token is a red flag, and a follow-up post from that same account saying everythingâs fine isnât proof of anything. If Clippy ever does come back, it wonât need your likes or your wallet.
Free crypto, NFTs & new crypto games, before everyone else
Airdrops, free games and launches the day they drop. One email, no spam, unsubscribe anytime.
