Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 452673988
- Off-chain at
- 2026-10-02T17:11:53.667Z
- Anchored at
- 2026-10-02T17:12:23.761Z
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 8gPhqcmv9HU5yCpj4WrY3jyUoQSAYGNRf5Y5YuoUE4nU
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (10544 chars)
{"actor":"system:backfill","investigation_id":"9484ddf8-f6c0-42fa-9b10-cfd63759507e","kind":"publish","page_slug":"clippy-token-clippy-microsoft-x-account-hijack-pump-and-dump","published_at":"2026-10-02T17:11:53.518Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Clippy Token ($CLIPPY) — Microsoft X Account Hijack Pump-and-Dump","sections":[{"content":"For approximately 30 minutes on October 2, 2026, Microsoft's verified X account, which has more than 13 million followers, was taken over by unknown attackers. The attackers changed the account's profile picture to Clippy, the animated paperclip assistant formerly bundled with Microsoft Office, and made the account follow and repost content from an account impersonating a Clippy revival, @clippymsftcto, which asked how many likes it would take to \"bring Clippy back.\" The hijacked @Microsoft account quoted this post with language including \"500,000 likes and we bring Clippy back. The ball is in your court.\" The @clippymsftcto account was subsequently suspended by X. Microsoft has not disclosed the technical method used to gain access; security reporting noted possible vectors such as SIM swapping, email-based password resets, infostealer malware, or compromise of a third-party social media management tool, none of which have been confirmed by Microsoft.","heading":"The Account Hijack","severity":"high","sources":[{"credibility":2,"name":"Crypto Briefing: \"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token\"","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"credibility":2,"name":"BleepingComputer: \"Microsoft's X account hacked in crypto token pump-and-dump scheme\"","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"credibility":2,"name":"SecurityWeek: \"Crypto Scammers Hijack Microsoft's Official X Account\"","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"}]},{"content":"During and after the hijack, accounts including @ClippyMSFT promoted a cryptocurrency token under the ticker $Clippy, with one promotional claim stating the token \"has a liquidity pool paired directly with $MSFT.\" This claim originated from the token's promoters, not from Microsoft, and Microsoft's publicly traded stock ($MSFT) has no connection to any cryptocurrency liquidity pool. Reporting describes the episode as resembling a pump-and-dump pattern, in which a token's visibility and price are inflated using borrowed credibility — here, the hijacked reach of a major corporate account — before early holders can sell into the resulting attention. No outlet reviewed had verified trading-volume or price-change figures tying a specific token contract to this incident at the time of writing, and no regulator (SEC, CFTC, or otherwise) has announced an enforcement action connected to this specific event. A separate, pre-existing Solana meme token also trading under the ticker CLIPPY (associated with a \"Clippy PFP Cult\" branding, contract address 7eMJmn1bYWSQEwxAX7CyngBzGNGu1cT582asKxxRpump) exists on decentralized exchanges; it is not established by available sourcing whether this is the same token promoted during the Microsoft hijack or a distinct, opportunistically similarly-named project. This ambiguity itself is a hallmark of ticker-hijacking scams, where attackers or opportunists attach an unrelated token to a trending name.","heading":"The $Clippy Token Promotion","severity":"critical","sources":[{"credibility":2,"name":"Crypto Briefing: \"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token\"","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"credibility":2,"name":"Windows Latest: \"Hacker hijacked Microsoft's X: '500,000 likes and we bring Clippy back,' all to pump a crypto token\"","type":"news_article","url":"https://www.windowslatest.com/2026/10/02/hacker-hijacked-microsofts-x-500000-likes-and-we-bring-clippy-back-all-to-pump-a-crypto-token/"},{"credibility":2,"name":"GeckoTerminal: CLIPPY/SOL pool on PumpSwap","type":"on_chain","url":"https://www.geckoterminal.com/solana/pools/JCuQ71cULQv1nsb2MWAmYaoyuX6XxzcA4PnEDmqnm7N3"}]},{"content":"Microsoft confirmed the unauthorized access in an official statement: \"We have confirmed unauthorized access to our account on X including posts that did not come from Microsoft. The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.\" Microsoft further stated: \"We are aware of a cryptocurrency token being promoted in connection with $MSFT stock, including the unauthorized use of the Clippy brand and Microsoft-related intellectual property. Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT.\" Microsoft indicated it intends to pursue action over the unauthorized use of its intellectual property, though no lawsuit or named defendant had been reported at the time of writing.","heading":"Microsoft's Response and Denial","severity":"medium","sources":[{"credibility":2,"name":"BleepingComputer: \"Microsoft's X account hacked in crypto token pump-and-dump scheme\"","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"credibility":2,"name":"Crypto Times: \"Microsoft's X Account Was Hijacked to Push a Clippy Token. 13 Million Followers Saw It.\"","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/microsofts-x-account-was-hijacked-to-push-a-clippy-token/"}]},{"content":"Coverage of the incident noted it follows a broader pattern of attackers hijacking high-follower corporate or government social media accounts to promote cryptocurrency tokens, including a prior compromise of a Microsoft India account in 2024 and the well-documented 2024 hijack of the U.S. SEC's X account, which was used to falsely announce approval of spot bitcoin ETFs. These precedents are cited by reporters as context for assessing credibility of sudden crypto-related posts from official accounts, rather than as direct evidence connecting the same perpetrators to the $Clippy incident.","heading":"Pattern of Corporate Account Hijacks for Crypto Promotion","severity":"medium","sources":[{"credibility":2,"name":"SecurityWeek: \"Crypto Scammers Hijack Microsoft's Official X Account\"","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"credibility":2,"name":"Crypto Briefing: \"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token\"","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"}]}],"sources_used":[{"credibility":2,"name":"Crypto Briefing: \"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token\"","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"credibility":2,"name":"BleepingComputer: \"Microsoft's X account hacked in crypto token pump-and-dump scheme\"","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"credibility":2,"name":"SecurityWeek: \"Crypto Scammers Hijack Microsoft's Official X Account\"","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"credibility":2,"name":"Crypto Times: \"Microsoft's X Account Was Hijacked to Push a Clippy Token. 13 Million Followers Saw It.\"","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/microsofts-x-account-was-hijacked-to-push-a-clippy-token/"},{"credibility":2,"name":"Windows Latest: \"Hacker hijacked Microsoft's X: '500,000 likes and we bring Clippy back,' all to pump a crypto token\"","type":"news_article","url":"https://www.windowslatest.com/2026/10/02/hacker-hijacked-microsofts-x-500000-likes-and-we-bring-clippy-back-all-to-pump-a-crypto-token/"},{"credibility":2,"name":"GeckoTerminal: CLIPPY/SOL pool on PumpSwap","type":"on_chain","url":"https://www.geckoterminal.com/solana/pools/JCuQ71cULQv1nsb2MWAmYaoyuX6XxzcA4PnEDmqnm7N3"}],"summary":"On October 2, 2026, Microsoft's official X account (@Microsoft, 13+ million followers) was hijacked for approximately 30 minutes and used to promote a cryptocurrency token called $Clippy, alongside a changed profile picture and reposts from impersonator accounts claiming Clippy's return. Microsoft confirmed the unauthorized access, said it never authorized any token tied to Clippy, Microsoft, or $MSFT, removed the posts, and said it is investigating and may pursue legal action. News outlets characterized the episode as an alleged pump-and-dump scheme exploiting the hijacked account's reach; no party has been identified or charged as of this writing.","timeline":[{"date":"2026-10-02","date_evidence":"For approximately 30 minutes on Thursday, October 2, 2026, Microsoft's official X account was not really Microsoft's. Unknown attackers took over @Microsoft, which has over 13 million followers, and used it to promote a fraudulent crypto token called $Clippy.","event":"Microsoft's @Microsoft X account is hijacked for approximately 30 minutes, with its profile picture changed to Clippy and posts promoting the $Clippy token.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"date":"2026-10","date_original":"2026-10-02","event":"Microsoft regains control of the account, removes the unauthorized posts, issues a statement confirming unauthorized access, and says it never authorized any crypto token tied to Clippy, Microsoft, or $MSFT.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"date":"2026-10","date_original":"2026-10-02","event":"The impersonator account @clippymsftcto, which the hijacked Microsoft account had followed and reposted, is suspended by X.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"}]},"v":1}