REDMOND — Microsoft's official X account was compromised today, posting promotional content for a fraudulent meme coin named ClippyCoin ($CLIPPY) for approximately 25 minutes before the posts were deleted.
The attacker shared multiple messages directing users to a fake decentralized exchange, urging them to "ape in" before a supposed major exchange listing. On-chain data from Etherscan tracked a newly deployed token contract matching the $CLIPPY ticker. Over $3 million in liquidity was added to a Uniswap v2 pool, then drained by the deployer wallet within minutes of the posts going live. The stolen funds were rapidly transferred to an unknown cold wallet address—a standard rug pull pattern designed to obscure asset movement.
Microsoft has not issued an official statement. The incident reflects persistent vulnerabilities in X's security architecture for high-value verified accounts. Similar compromises have targeted other major corporate and government profiles in recent months, raising questions about the platform's two-factor authentication protocols.
The attack underscores a critical risk for retail investors: even verified accounts can be weaponized to execute scams. Wallet flows show the attacker moved stolen capital quickly, a hallmark of coordinated rug pulls. Investors should verify token contracts and official announcements directly from project websites, not social media posts, regardless of account verification status.
