Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
452675287
Off-chain at
2026-10-02T17:18:08.163Z
Anchored at
2026-10-02T17:18:11.561Z
Block time
—

Independent verification

1. Database (off-chain)
6JnSrFL8FVA6DoxTNuF3iYMoxUTq1GnZfWL4E2mRVhex
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (18778 chars)
{"actor":"system:backfill","investigation_id":"9dca8a37-94ec-492b-abc7-90a7b38b6393","kind":"publish","page_slug":"clippy-token-clippy-microsoft-x-account-hijack","published_at":"2026-10-02T17:18:08.079Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Clippy Token ($CLIPPY) — Microsoft X Account Hijack","sections":[{"content":"On October 2, 2026, Microsoft's verified X account (@Microsoft, 13+ million followers) was subjected to unauthorized access by an unknown party or parties. During the approximately 30-minute window of compromise, the attackers changed the account's profile picture to an image of Clippy — Microsoft's retired animated Office assistant — and caused the account to follow and repost content from a separate impersonator account operating as @clippymsftcto. The hijacked account also allegedly posted the message '500,000 likes and we bring Clippy back. The ball is in your court,' framing the takeover as an official Microsoft rebrand announcement. The @clippymsftcto account has since been suspended by X. Microsoft regained control within approximately 30 minutes and removed all unauthorized posts. A Microsoft spokesperson, identified as Brent Colburn, confirmed the breach: 'We have confirmed unauthorized access to our account on X, including posts that did not come from Microsoft. The account has been secured and the unauthorized posts have been removed, and we are continuing to investigate the circumstances.' How the account was compromised has not been publicly disclosed by Microsoft or X. Security researchers note that possible vectors include SIM swapping, email compromise enabling a password reset, or infostealer malware harvesting an employee's active browser session cookies.","heading":"The X Account Hijack","severity":"high","sources":[{"credibility":1,"name":"Microsoft's X account hacked in crypto pump-and-dump scheme — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"credibility":1,"name":"Crypto Scammers Hijack Microsoft's Official X Account — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"credibility":2,"name":"Microsoft's X Account Was Hijacked to Push a Clippy Token. 13 Million Followers Saw It. — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/microsofts-x-account-was-hijacked-to-push-a-clippy-token/"},{"credibility":2,"name":"Hacker hijacked Microsoft's X: '500,000 likes and we bring Clippy back,' all to pump a crypto token — Windows Latest","type":"news_article","url":"https://www.windowslatest.com/2026/10/02/hacker-hijacked-microsofts-x-500000-likes-and-we-bring-clippy-back-all-to-pump-a-crypto-token/"}]},{"content":"The hijack was alleged by multiple news outlets to be a pump-and-dump scheme. A second X account, @ClippyMSFT, was used to promote a $CLIPPY cryptocurrency token on the Solana blockchain, falsely claiming the token had a 'liquidity pool paired directly with $MSFT' — a reference to Microsoft's stock ticker. This claim was false; the real Microsoft Corporation has no association with any cryptocurrency token. One Solana token identified as 'Microsoft Mascot' with the symbol 'Clippy' carries the contract address GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump (creation date: October 29, 2024). As of early October 2026, this token had a market cap of approximately $1,500 USD, a liquidity of approximately $2,700 USD, and 75 holders, with the top 10 holders controlling 99.39% of the total supply of 995.53 million tokens. The extreme top-holder concentration is consistent with the structure commonly seen in pre-pump token deployments. A separate and older Solana token using the same Clippy name and imagery — contract address 7eMJmn1bYWSQEwxAX7CyngBzGNGu1cT582asKxxRpump — reached an all-time high market cap of approximately $36.6 million on August 11, 2025, before declining sharply. The specific token most directly promoted during the October 2, 2026 hijack has not been conclusively identified by contract address in public reporting as of this writing; the on-chain addresses above are provided for reference and researchers should verify which token was actively promoted during the 30-minute window. Reported liquidity tied to $MSFT-paired pools was alleged at over $200,000, though this figure could not be independently confirmed from primary sources. No quantified losses to retail purchasers have been published.","heading":"The $CLIPPY Token and Alleged Pump-and-Dump Scheme","severity":"critical","sources":[{"credibility":2,"name":"Microsoft disavows Clippy-themed token tied to its MSFT ticker — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/microsoft-disavows-clippy-msft-token/"},{"credibility":2,"name":"Microsoft Mascot (Clippy) Token on Phantom — contract GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump","type":"on_chain","url":"https://phantom.com/tokens/solana/GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump"},{"credibility":2,"name":"Clippy PFP Cult ($CLIPPY) — LoreScreener (contract 7eMJmn1bYWSQEwxAX7CyngBzGNGu1cT582asKxxRpump)","type":"on_chain","url":"https://lorescreener.com/entry/clippy"},{"credibility":2,"name":"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"credibility":2,"name":"Meme token CLIPPY surges over 34% in the past hour, market cap rises to $22.4 million — Bitget","type":"news_article","url":"https://www.bitget.com/news/detail/12560604910475"}]},{"content":"Microsoft issued an explicit public denial of any affiliation with the $CLIPPY token. Its full statement reads: 'Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT.' The company added that it 'does not support or endorse the token' and stated it would 'pursue appropriate legal action to have the unauthorized token and related materials removed,' citing unauthorized use of its brands and intellectual property. Microsoft also posted — and subsequently deleted — an apology related to the incident. The company confirmed it was continuing to investigate the circumstances of the breach. X has not issued a public incident note as of the time of this writing.","heading":"Microsoft's Official Response and Legal Position","severity":"low","sources":[{"credibility":1,"name":"Crypto Scammers Hijack Microsoft's Official X Account — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"credibility":1,"name":"Microsoft's X account hacked in crypto pump-and-dump scheme — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"}]},{"content":"As of October 2, 2026, no attacker or group has claimed responsibility for the hijack, and no suspect has been publicly named by Microsoft, X, or law enforcement. The method of account compromise has not been officially confirmed. Security Week noted that possible attack vectors include SIM swapping (as used in the 2024 SEC X account hack), email-based account recovery compromise, or infostealer malware harvesting session cookies from an employee device. The @clippymsftcto impersonator account has been suspended. The @ClippyMSFT account, which continued promoting the token after the hijack, was still active as of initial reporting but its current status is unconfirmed. Microsoft has stated it is investigating and will pursue legal action, but no charges, filings, or regulatory actions had been publicly announced at the time of this writing. This investigation page will be updated as attribution evidence or legal filings emerge.","heading":"Attribution and Investigation Status","severity":"medium","sources":[{"credibility":1,"name":"Crypto Scammers Hijack Microsoft's Official X Account — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"credibility":2,"name":"Microsoft's X Account Was Hijacked to Push a Clippy Token — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/microsofts-x-account-was-hijacked-to-push-a-clippy-token/"}]},{"content":"This was not the first time a Microsoft-affiliated social media account was hijacked for a cryptocurrency promotion. In June 2024, Microsoft India's verified X account was compromised in what security researchers attributed to a SIM-swapping attack. In that incident, the attackers impersonated investor Keith Gill ('Roaring Kitty') and directed Microsoft India's approximately 211,000 followers to a malicious website (presaIe-roaringkitty[.]com) promising a fraudulent GameStop (GME) crypto presale, with the goal of draining connected wallets. The 2024 Microsoft India hack involved a drain-style phishing site rather than a token promotion, but both incidents followed the pattern of exploiting a high-follower corporate account to confer false legitimacy on a cryptocurrency scheme.","heading":"Prior Incidents Involving Microsoft Social Accounts","severity":"medium","sources":[{"credibility":2,"name":"Microsoft India X Account Falls Victim to Roaring Kitty Scam — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2024/06/05/microsoft-india-x-account-falls-victim-to-roaring-kitty-scam/"},{"credibility":2,"name":"Sim-Swap Attack: Microsoft India's X Account Falls Victim to Roaring Kitty Crypto Scam — Blockonomi","type":"news_article","url":"https://blockonomi.com/sim-swap-attack-microsoft-indias-x-account-falls-victim-to-roaring-kitty-crypto-scam/"},{"credibility":2,"name":"Crypto Scammers Exploit Microsoft India's Verified Twitter Account — Winbuzzer","type":"news_article","url":"https://winbuzzer.com/2024/06/04/crypto-scammers-exploit-microsoft-indias-verified-twitter-account-xcxwbn/"}]},{"content":"Any $CLIPPY token promoted during or after this incident carries extreme risk for the following independently verifiable reasons. First, Microsoft has explicitly and publicly disavowed all cryptocurrency tokens using its Clippy brand, Microsoft name, or MSFT ticker, and has stated it will pursue legal action. Second, the token was promoted through a compromised third-party account rather than any official Microsoft channel. Third, on-chain data for the Solana token most plausibly connected to this event (GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump) shows the top 10 holders controlling 99.39% of total supply, a structure that creates extreme exit-liquidity risk for any retail buyer. Fourth, the false claim that the token's liquidity was 'paired directly with $MSFT' stock is not mechanically possible and constitutes a materially misleading representation. Fifth, no registered securities offering, legal entity, or development roadmap has been associated with this token. Purchasing any $CLIPPY token promoted in connection with this incident constitutes trading against a deceptive representation by unknown actors, not an investment in or endorsement by Microsoft Corporation.","heading":"Investor Risk Assessment","severity":"critical","sources":[{"credibility":2,"name":"Microsoft Mascot (Clippy) Token — Phantom wallet page","type":"on_chain","url":"https://phantom.com/tokens/solana/GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump"},{"credibility":2,"name":"Microsoft disavows Clippy-themed token tied to its MSFT ticker — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/microsoft-disavows-clippy-msft-token/"}]}],"sources_used":[{"credibility":1,"name":"Microsoft's X account hacked in crypto pump-and-dump scheme — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"credibility":1,"name":"Crypto Scammers Hijack Microsoft's Official X Account — SecurityWeek","type":"news_article","url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"credibility":2,"name":"Microsoft's X Account Was Hijacked to Push a Clippy Token. 13 Million Followers Saw It. — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/10/02/microsofts-x-account-was-hijacked-to-push-a-clippy-token/"},{"credibility":2,"name":"Hacker hijacked Microsoft's X: '500,000 likes and we bring Clippy back,' all to pump a crypto token — Windows Latest","type":"news_article","url":"https://www.windowslatest.com/2026/10/02/hacker-hijacked-microsofts-x-500000-likes-and-we-bring-clippy-back-all-to-pump-a-crypto-token/"},{"credibility":2,"name":"Crypto scammers hijack Microsoft's official X account to push a fake Clippy token — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/crypto-scammers-hijack-microsoft-x-account/"},{"credibility":2,"name":"Microsoft disavows Clippy-themed token tied to its MSFT ticker — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/microsoft-disavows-clippy-msft-token/"},{"credibility":2,"name":"Hackers hijacked Microsoft's X account to promote a Clippy cryptocurrency — Windows Central","type":"news_article","url":"https://www.windowscentral.com/microsoft/microsoft-office/hackers-hijacked-microsofts-x-account-to-promote-a-clippy-cryptocurrency"},{"credibility":3,"name":"Microsoft X Account Hijacked to Promote Fake $Clippy Token — mallory.ai","type":"news_article","url":"https://mallory.ai/stories/01a0fc1b-be39-7268-97c7-49754447e6de"},{"credibility":2,"name":"Microsoft Mascot (Clippy) Token — Phantom (contract: GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump)","type":"on_chain","url":"https://phantom.com/tokens/solana/GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump"},{"credibility":2,"name":"Clippy PFP Cult ($CLIPPY) — LoreScreener (contract: 7eMJmn1bYWSQEwxAX7CyngBzGNGu1cT582asKxxRpump)","type":"on_chain","url":"https://lorescreener.com/entry/clippy"},{"credibility":2,"name":"CLIPPY/SOL pool on Raydium — GeckoTerminal","type":"on_chain","url":"https://www.geckoterminal.com/solana/pools/GqaJcdnbEmrYg6iuNi15ymPWQZQFeaSY2xR1b1VbHh59"},{"credibility":2,"name":"Meme token CLIPPY surges over 34% in the past hour, market cap rises to $22.4 million — Bitget","type":"news_article","url":"https://www.bitget.com/news/detail/12560604910475"},{"credibility":2,"name":"Microsoft India X Account Falls Victim to Roaring Kitty Scam — CryptoTimes (June 2024)","type":"news_article","url":"https://www.cryptotimes.io/2024/06/05/microsoft-india-x-account-falls-victim-to-roaring-kitty-scam/"},{"credibility":2,"name":"Sim-Swap Attack: Microsoft India's X Account — Blockonomi (June 2024)","type":"news_article","url":"https://blockonomi.com/sim-swap-attack-microsoft-indias-x-account-falls-victim-to-roaring-kitty-crypto-scam/"},{"credibility":1,"name":"Crypto Scammers Exploit Microsoft India's Verified Twitter Account — Winbuzzer (June 2024)","type":"news_article","url":"https://winbuzzer.com/2024/06/04/crypto-scammers-exploit-microsoft-indias-verified-twitter-account-xcxwbn/"}],"summary":"On October 2, 2026, unknown attackers hijacked Microsoft's official X account — which has over 13 million followers — for approximately 30 minutes and used it to promote an unauthorized Clippy-themed cryptocurrency token ($CLIPPY) on the Solana blockchain. The incident is characterized by multiple reporters as a pump-and-dump scheme. Microsoft has confirmed the account compromise, denied any association with the token, and stated it will pursue legal action. No attacker has been publicly identified, and the compromise method has not been officially disclosed.","timeline":[{"date":"2024-06-04","event":"Microsoft India's verified X account is compromised in a SIM-swapping attack. Attackers impersonate investor Keith Gill to promote a fraudulent GameStop crypto presale and direct followers to a wallet-draining phishing site.","source":"Winbuzzer / Blockonomi / CryptoTimes","source_url":"https://winbuzzer.com/2024/06/04/crypto-scammers-exploit-microsoft-indias-verified-twitter-account-xcxwbn/"},{"date":"2024-10-29","event":"A Solana token named 'Microsoft Mascot' with symbol CLIPPY (contract: GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump) is created on the Solana blockchain via Pump.fun.","source":"Phantom token page","source_url":"https://phantom.com/tokens/solana/GyGYxT6XVwtAuEEVSn2V6YZ7bgkCxkjVzyWt8ogtpump"},{"date":"2025-08-11","event":"An older Clippy-themed Solana token (Clippy PFP Cult, contract: 7eMJmn1bYWSQEwxAX7CyngBzGNGu1cT582asKxxRpump) reaches an all-time high market cap of approximately $36.6 million.","source":"LoreScreener / Bitget","source_url":"https://lorescreener.com/entry/clippy"},{"date":"2026-10-02","event":"Microsoft's official X account (@Microsoft, 13+ million followers) is compromised by unknown actors. The account follows and reposts content from impersonator account @clippymsftcto, changes its profile picture to Clippy, and posts '500,000 likes and we bring Clippy back.' A second account (@ClippyMSFT) simultaneously promotes a $CLIPPY token on Solana, falsely claiming it has liquidity paired with Microsoft's $MSFT stock ticker.","source":"BleepingComputer / SecurityWeek / CryptoTimes","source_url":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/"},{"date":"2026-10-02","event":"Microsoft regains control of its X account within approximately 30 minutes. All unauthorized posts are removed. Microsoft spokesperson Brent Colburn confirms the breach and states the company is investigating.","source":"SecurityWeek","source_url":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/"},{"date":"2026-10-02","event":"Microsoft issues a public denial: 'Microsoft has not authorized, sponsored, endorsed, or granted permission for the creation, promotion, or use of any cryptocurrency token associated with Clippy, Microsoft, or $MSFT.' Microsoft announces it will pursue legal action. Microsoft later deletes its own apology/disclaimer post.","source":"CryptoBriefing / BleepingComputer","source_url":"https://cryptobriefing.com/microsoft-disavows-clippy-msft-token/"},{"date":"2026-10-02","event":"X suspends the @clippymsftcto impersonator account. The @ClippyMSFT account continues promoting the $CLIPPY token.","source":"CryptoTimes / Windows Latest","source_url":"https://www.cryptotimes.io/2026/10/02/microsofts-x-account-was-hijacked-to-push-a-clippy-token/"}]},"v":1}