Microsoft's X Account Was Hacked to Push a Fake Cryptocurrency, Renewing Warnings About Verified Badges
Microsoft's X Account Was Hacked to Push a Fake Cryptocurrency, Renewing Warnings About Verified Badges

Technology

Microsoft’s X Account Was Hacked to Push a Fake Cryptocurrency, Renewing Warnings About Verified Badges

Microsoft’s official X account, which has more than 13 million followers, was briefly hijacked and used to promote a cryptocurrency scheme, renewing concerns that verified badges don’t guarantee a post can be trusted.

Microsoft’s official account on X, which has more than 13 million followers, was taken over by unauthorized users and used to promote a cryptocurrency scheme, the company has confirmed. The incident is renewing concerns that a blue verification checkmark no longer guarantees a post is trustworthy.

According to BleepingComputer, the @Microsoft account followed and reposted content from a separate, Clippy-themed account that was promoting a cryptocurrency called $Clippy, a reference to Microsoft Office’s old animated paperclip assistant. Microsoft told CyberGuy that two unauthorized posts appeared while the account was compromised: one was a quote repost referencing the Clippy character, and the second appeared to be an apology for the earlier activity. The company says neither post came from Microsoft itself.

A Microsoft spokesperson gave this statement: “We have confirmed unauthorized access to our account on X, including posts that did not originate from Microsoft. The account has been secured, the unauthorized posts have been removed, and we are continuing to investigate the circumstances.”

A Pattern of Hijacked Trust

Security researchers say the episode illustrates a broader problem: attackers who compromise a well-known account inherit the trust and audience that account has already built. A similar dynamic played out after hackers hijacked HBO Max’s verified Reddit account, which researchers say was used to push 108 malicious ads over roughly 48 hours.

This isn’t the first time a Microsoft-linked X account has been used in a crypto scheme. In June 2024, attackers hijacked Microsoft India’s X account and used it to impersonate Keith Gill, known online as “Roaring Kitty,” to promote a fake GameStop cryptocurrency presale. Users who connected their crypto wallets through that scheme risked having their assets stolen by wallet-draining malware.

Perhaps the most consequential example came in January 2024, when attackers took over the U.S. Securities and Exchange Commission’s official X account and falsely announced approval of spot Bitcoin exchange-traded funds. The Justice Department says Bitcoin rose by more than $1,000 after the false post and then fell by more than $2,000 once the SEC corrected the record. Investigators traced the breach to a SIM swap targeting the phone number linked to the SEC’s account. Eric Council Jr. pleaded guilty in February 2025 to conspiracy charges related to the attack and was sentenced in May 2025 to 14 months in prison.

Why the Checkmark Isn’t Enough

A verification badge can confirm an account belongs to the organization it claims to represent, but it cannot confirm who controls that account at any given moment. Hackers have used phishing, credential theft and SIM swapping — which can intercept password reset codes and bypass some two-factor authentication — to seize control of verified accounts and redirect them toward crypto scams.

Security experts recommend several precautions before acting on a surprising social media post, especially one involving money or cryptocurrency:

  • Verify any major announcement, such as a new cryptocurrency or investment opportunity, through the company’s official website or newsroom rather than relying on a single social media post.
  • Treat a sudden shift in an account’s subject matter — such as a software company abruptly promoting an obscure token — as a warning sign.
  • Avoid connecting a cryptocurrency wallet to a site or service linked from a social media post, and never enter a recovery phrase or private key based on such a prompt.
  • Be wary of urgency or deadlines in a post, which are often designed to pressure quick action before verification is possible.
  • Check web addresses carefully, since small changes to a domain name can redirect users to a fraudulent site.
  • Use unique passwords, enable two-factor authentication through an app or passkey rather than text messages, and periodically review active account sessions for unrecognized devices.

The incident involving Microsoft’s account underscores that even organizations with substantial security resources can have their official channels briefly seized by attackers. Experts say the safest approach is to treat a verification badge as one data point rather than proof that a post is legitimate, particularly when it involves financial transactions or requests to connect a cryptocurrency wallet.

Click to comment

You must be logged in to post a comment Login

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

You May Also Like

Government Corruption

Updated 5/17/19 9:52am Jack Crane | Opinion  James Baker, Former-FBI General Counsel has joined Russian hoax media collaborator Michael Isikoff on his podcast, yesterday....

US Politics

I do not even know where to begin with this one.  Just when you think you have seen the worst that humanity has to...

US News

Education is considered to be one of the pillars of a successful life. Without a college degree, many believe these students will earn lower...

US News

ICYMI| If it were not for Tom Fitton and Judicial Watch, it is more than likely that the world would never know the extent...