Updated Oct 11, 2026
/Kelce's NFL Network broadcast draws mixed reviews after Eagles-Jaguars game/Microsoft X account compromised in Clippy crypto scheme/Former DOGE engineer Coristine leads new AI government portal/AI firms embed third-party evaluators amid safety scrutiny/Cook Political Report tilts 18 House races toward Democrats/Supreme Court leaves Maine lobster GPS tracking mandate in place/Kelce's NFL Network broadcast draws mixed reviews after Eagles-Jaguars game/Microsoft X account compromised in Clippy crypto scheme/Former DOGE engineer Coristine leads new AI government portal/AI firms embed third-party evaluators amid safety scrutiny/Cook Political Report tilts 18 House races toward Democrats/Supreme Court leaves Maine lobster GPS tracking mandate in place

Microsoft X account compromised in Clippy crypto scheme

BleepingComputer reported that attackers gained unauthorized access to Microsoft's official X account and used it to promote a cryptocurrency called $Clippy. The account, which has more than 13 million followers, was used to follow and repost content from a Clippy-themed account. Microsoft stated that two unauthorized posts appeared during the compromise period. The first was a quote repost referencing the return of the animated paperclip character, while the second appeared to be an apology. A Microsoft spokesperson confirmed the unauthorized access, noting that the account has been secured and the posts removed. The company is continuing to investigate the circumstances. This incident highlights how compromised verified accounts can mislead users by inheriting established trust. Attackers used the credibility of the Microsoft name to make the promotion of an obscure token appear legitimate. A similar tactic was used in June 2024 when scammers hijacked Microsoft India's X account to impersonate Keith Gill, also known as Roaring Kitty. In that case, attackers promoted a fake GameStop cryptocurrency presale that risked draining users' wallets through malware. The use of compromised accounts for financial scams is not new. In January 2024, attackers took over the U.S. Securities and Exchange Commission's official X account and falsely announced the approval of spot Bitcoin exchange-traded funds. According to the Justice Department, Bitcoin prices jumped by more than $1,000 following the false post before falling by more than $2,000 after the SEC corrected the announcement. Investigators determined that a SIM swap allowed attackers to intercept password reset codes. Eric Council Jr. pleaded guilty to conspiracy charges related to that attack in February 2025 and was sentenced to 14 months in prison in May 2025. These cases demonstrate that a verification badge confirms ownership but does not guarantee current control of an account. Hackers can steal credentials through phishing or SIM swapping to bypass security measures. Users are advised to verify any financial announcements or cryptocurrency offers directly on official company websites rather than relying solely on social media posts. If an account suddenly promotes a token or investment opportunity out of character, it should be treated as a warning sign. Connecting a cryptocurrency wallet to a suspicious link can expose users to malicious approvals that allow asset theft. Security experts recommend using unique passwords, enabling two-factor authentication, and checking active sessions regularly to protect accounts from takeover.

By Rafael Okonkwo2 min read$CLIPPY
Share

BleepingComputer reported that attackers gained unauthorized access to Microsoft's official X account and used it to promote a cryptocurrency called $Clippy. The account, which has more than 13 million followers, was used to follow and repost content from a Clippy-themed account. Microsoft stated that two unauthorized posts appeared during the compromise period. The first was a quote repost referencing the return of the animated paperclip character, while the second appeared to be an apology. A Microsoft spokesperson confirmed the unauthorized access, noting that the account has been secured and the posts removed. The company is continuing to investigate the circumstances. This incident highlights how compromised verified accounts can mislead users by inheriting established trust. Attackers used the credibility of the Microsoft name to make the promotion of an obscure token appear legitimate. A similar tactic was used in June 2024 when scammers hijacked Microsoft India's X account to impersonate Keith Gill, also known as Roaring Kitty. In that case, attackers promoted a fake GameStop cryptocurrency presale that risked draining users' wallets through malware. The use of compromised accounts for financial scams is not new. In January 2024, attackers took over the U.S. Securities and Exchange Commission's official X account and falsely announced the approval of spot Bitcoin exchange-traded funds. According to the Justice Department, Bitcoin prices jumped by more than $1,000 following the false post before falling by more than $2,000 after the SEC corrected the announcement. Investigators determined that a SIM swap allowed attackers to intercept password reset codes. Eric Council Jr. pleaded guilty to conspiracy charges related to that attack in February 2025 and was sentenced to 14 months in prison in May 2025. These cases demonstrate that a verification badge confirms ownership but does not guarantee current control of an account. Hackers can steal credentials through phishing or SIM swapping to bypass security measures. Users are advised to verify any financial announcements or cryptocurrency offers directly on official company websites rather than relying solely on social media posts. If an account suddenly promotes a token or investment opportunity out of character, it should be treated as a warning sign. Connecting a cryptocurrency wallet to a suspicious link can expose users to malicious approvals that allow asset theft. Security experts recommend using unique passwords, enabling two-factor authentication, and checking active sessions regularly to protect accounts from takeover.