Microsoft’s X (formerly Twitter) Account Hacked in Crypto Pump-and-Dump Scandal
Microsoft’s official X account was hacked in a cryptocurrency pump-and-dump scheme, with unauthorized posts promoting a fake token.
The Breach and Unauthorized Posts
On Thursday, an unauthorized entity gained control of the official Microsoft X account (@Microsoft), which has over 13 million followers, as part of a coordinated scheme to promote a cryptocurrency token. The breach involved the account following and sharing a post from a suspended X profile (@clippymsftcto) that mimicked Microsoft’s Clippy virtual assistant. This account has since been removed from the platform, but a related profile (@ClippyMSFT) continues to propagate a token labeled $Clippy, falsely asserting it is paired with $MSFT stock through a liquidity pool.
Microsoft’s Response
Microsoft confirmed the incident, stating that unauthorized posts were removed and the account was secured. A company representative disclosed to The Verge that the breach involved unauthorized access to the X account, with posts originating from external sources. The organization also issued a public statement retracting the compromised content and emphasizing its lack of involvement with cryptocurrency projects.
“Microsoft has not authorized any cryptocurrency token or related materials, and we are pursuing legal action to eliminate the unauthorized content,” the statement read. The company reiterated its position that it does not endorse or associate with the $Clippy token or its developers.
Previous Incidents Involving Microsoft Accounts
This incident marks the second known compromise of a Microsoft X account in recent years. In June 2024, the Microsoft India account (@MicrosoftIndia) was hijacked to impersonate Roaring Kitty, a well-known meme stock trader. Attackers used the compromised account to distribute malware designed to drain cryptocurrency wallets, directing users to a fraudulent website (presaIe-roaringkitty[.]com) that purported to offer a GameStop crypto presale. The site allegedly stole digital assets by exploiting user wallet connections.
Broader Context of Social Media Fraud
X users have increasingly faced account takeovers and malicious advertising campaigns, with verified entities targeted for cryptocurrency fraud and wallet-draining exploits. In December 2023, blockchain analysts at ScamSniffer reported that cybercriminals siphoned approximately $59 million from 63,000 individuals through a single ad campaign utilizing the “MS Drainer” wallet-draining tool. Similar tactics have been employed in other high-profile breaches, including the 2024 compromise of the U.S. Securities and Exchange Commission’s @SECGov account.
In that incident, attackers executed a SIM-swapping attack to post a false announcement regarding the approval of Bitcoin exchange-traded funds, triggering a temporary surge in Bitcoin’s value. The perpetrator, Eric Council Jr., pleaded guilty in February 2025 and received a 14-month prison sentence for orchestrating the scheme.
Implications and Recommendations
The recurrence of such attacks underscores the persistent threat of social media-based fraud and the need for heightened security measures to protect institutional accounts. Organizations must remain vigilant against impersonation tactics and ensure robust verification protocols to mitigate risks associated with cryptocurrency-related scams.
