Skip to main content
AVOID.NET

Audit log

Every state-changing event for Clippy Token ($CLIPPY) — Microsoft X Account Hijack Pump-and-Dump: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-02 17:11:53Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 452,673,988
    sig
    2bjMc7oysjKL…4GKjcrGaexplorer ↗
    hash
    8gPhqcmv9HU5…YuoUE4nUsha256 → base58
    verifying row…full verify ↗
    canonical bytes (10544 B) ▸
    {"actor":"system:backfill","investigation_id":"9484ddf8-f6c0-42fa-9b10-cfd63759507e","kind":"publish","page_slug":"clippy-token-clippy-microsoft-x-account-hijack-pump-and-dump","published_at":"2026-10-02T17:11:53.518Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Clippy Token ($CLIPPY) — Microsoft X Account Hijack Pump-and-Dump","sections":[{"content":"For approximately 30 minutes on October 2, 2026, Microsoft's verified X account, which has more than 13 million followers, was taken over by unknown attackers. The attackers changed the account's profile picture to Clippy, the animated paperclip assistant formerly bundled with Microsoft Office, and made the account follow and repost content from an account impersonating a Clippy revival, @clippymsftcto, which asked how many likes it would take to \"bring Clippy back.\" The hijacked @Microsoft account quoted this post with language including \"500,000 likes and we bring Clippy back. The ball is in your court.\" The @clippymsftcto account was subsequently suspended by X. Microsoft has not disclosed the technical method used to gain access; security reporting noted possible vectors such as SIM swapping, email-based password resets, infostealer malware, or compromise of a third-party social media management tool, none of which have been confirmed by Microsoft.","heading":"The Account Hijack","severity":"high","sources":[{"credibility":2,"name":"Crypto Briefing: \"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token\"","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"credibility":2,"name":"BleepingComputer: \"Microsoft's X account hacked in crypto token pump-and-dump scheme\"","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"credibility":2,"name":"SecurityWeek: \"Crypto Scammers Hijack Microsoft's Official X Account\"","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"}]},{"content":"During and after the hijack, accounts including @ClippyMSFT promoted a cryptocurrency token under the ticker $Clippy, with one promotional claim stating the token \"has a liquidity pool paired directly with $MSFT.\" This claim originated from the token's promoters, not from Microsoft, and Microsoft's publicly traded stock ($MSFT) has no connection to any cryptocurrency liquidity pool. Reporting describes the episode as resembling a pump-and-dump pattern, in which a token's visibility and price are inflated using borrowed credibility — here, the hijacked reach of a major corporate account — before early holders can sell into the resulting attention. No outlet reviewed had verified trading-volume or price-change figures tying a specific token contract to this incident at the time of writing, and no regulator (SEC, CFTC, or otherwise) has announced an enforcement action connected to this specific event. A separate, pre-existing Solana meme token also trading under the ticker CLIPPY (associated with a \"Clippy PFP Cult\" branding, contract address 7eMJmn1bYWSQEwxAX7CyngBzGNGu1cT582asKxxRpump) exists on decentralized exchanges; it is not established by available sourcing whether this is the same token promoted during the Microsoft hijack or a distinct, opportunistically similarly-named project. This ambiguity itself is a hallmark of ticker-hijacking scams, where attackers or opportunists attach an unrelated token to a trending name.","heading":"The $Clippy Token Promotion","severity":"critical","sources":[{"credibility":2,"name":"Crypto Briefing: \"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token\"","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"credibility":2,"name":"Windows Latest: \"Hacker hijacked Microsoft's X: '500,000 likes and we bring Clippy back,' all to pump a crypto token\"","type":"news_article","url":"https://www.windowslatest.com/2026/10/02/hacker-hijacked-microsofts-x-500000-likes-and-we-bring-clippy-back-all-to-pump-a-crypto-token/"},{"credibility":2,"name":"GeckoTerminal: CLIPPY/SOL pool on PumpSwap","type":"on_chain","url":"https://www.geckoterminal.com/solana/pools/JCuQ71cULQv1nsb2MWAmYaoyuX6XxzcA4PnEDmqnm7N3"}]},{"content":"Microsoft confirmed the unauthorized access in an official statement: \"We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft. The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.\" Microsoft further stated: \"We are aware of a cryptocurrency token being promoted in connection with $MSFT stock, including the unauthorized use of the Clippy brand and Microsoft-related intellectual property. Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT.\" Microsoft indicated it intends to pursue action over the unauthorized use of its intellectual property, though no lawsuit or named defendant had been reported at the time of writing.","heading":"Microsoft's Response and Denial","severity":"medium","sources":[{"credibility":2,"name":"BleepingComputer: \"Microsoft's X account hacked in crypto token pump-and-dump scheme\"","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"credibility":2,"name":"Crypto Times: \"Microsoft's X Account Was Hijacked to Push a Clippy Token. 13 Million Followers Saw It.\"","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/microsofts-x-account-was-hijacked-to-push-a-clippy-token/"}]},{"content":"Coverage of the incident noted it follows a broader pattern of attackers hijacking high-follower corporate or government social media accounts to promote cryptocurrency tokens, including a prior compromise of a Microsoft India account in 2024 and the well-documented 2024 hijack of the U.S. SEC's X account, which was used to falsely announce approval of spot bitcoin ETFs. These precedents are cited by reporters as context for assessing credibility of sudden crypto-related posts from official accounts, rather than as direct evidence connecting the same perpetrators to the $Clippy incident.","heading":"Pattern of Corporate Account Hijacks for Crypto Promotion","severity":"medium","sources":[{"credibility":2,"name":"SecurityWeek: \"Crypto Scammers Hijack Microsoft's Official X Account\"","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"credibility":2,"name":"Crypto Briefing: \"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token\"","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"}]}],"sources_used":[{"credibility":2,"name":"Crypto Briefing: \"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token\"","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"credibility":2,"name":"BleepingComputer: \"Microsoft's X account hacked in crypto token pump-and-dump scheme\"","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"credibility":2,"name":"SecurityWeek: \"Crypto Scammers Hijack Microsoft's Official X Account\"","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"credibility":2,"name":"Crypto Times: \"Microsoft's X Account Was Hijacked to Push a Clippy Token. 13 Million Followers Saw It.\"","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/microsofts-x-account-was-hijacked-to-push-a-clippy-token/"},{"credibility":2,"name":"Windows Latest: \"Hacker hijacked Microsoft's X: '500,000 likes and we bring Clippy back,' all to pump a crypto token\"","type":"news_article","url":"https://www.windowslatest.com/2026/10/02/hacker-hijacked-microsofts-x-500000-likes-and-we-bring-clippy-back-all-to-pump-a-crypto-token/"},{"credibility":2,"name":"GeckoTerminal: CLIPPY/SOL pool on PumpSwap","type":"on_chain","url":"https://www.geckoterminal.com/solana/pools/JCuQ71cULQv1nsb2MWAmYaoyuX6XxzcA4PnEDmqnm7N3"}],"summary":"On October 2, 2026, Microsoft's official X account (@Microsoft, 13+ million followers) was hijacked for approximately 30 minutes and used to promote a cryptocurrency token called $Clippy, alongside a changed profile picture and reposts from impersonator accounts claiming Clippy's return. Microsoft confirmed the unauthorized access, said it never authorized any token tied to Clippy, Microsoft, or $MSFT, removed the posts, and said it is investigating and may pursue legal action. News outlets characterized the episode as an alleged pump-and-dump scheme exploiting the hijacked account's reach; no party has been identified or charged as of this writing.","timeline":[{"date":"2026-10-02","date_evidence":"For approximately 30 minutes on Thursday, October 2, 2026, Microsoft's official X account was not really Microsoft's. Unknown attackers took over @Microsoft, which has over 13 million followers, and used it to promote a fraudulent crypto token called $Clippy.","event":"Microsoft's @Microsoft X account is hijacked for approximately 30 minutes, with its profile picture changed to Clippy and posts promoting the $Clippy token.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"date":"2026-10","date_original":"2026-10-02","event":"Microsoft regains control of the account, removes the unauthorized posts, issues a statement confirming unauthorized access, and says it never authorized any crypto token tied to Clippy, Microsoft, or $MSFT.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"date":"2026-10","date_original":"2026-10-02","event":"The impersonator account @clippymsftcto, which the hijacked Microsoft account had followed and reposted, is suspended by X.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 6a4074c7-fddc-4527-86f7-6d7ffa0bd34a
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.