On October 2 the official Microsoft account on X followed and reposted a Clippy impersonator promoting a crypto token tied to $MSFT. I got that from BleepingComputer. Microsoft told The Verge it confirmed unauthorized access, locked the account, and pulled the posts. A deleted apology said Microsoft does not endorse any token using Clippy, Microsoft, or $MSFT branding.
Same pattern as the 2024 Microsoft India hijack that pushed wallet-drainer malware. A verified check is still a pump button. Followers treat that account as a wire. One stolen session turns 13 million people into distribution.
The token is bait. What I actually clock is the login: shared passwords, no hardware key, one phone that can approve everything. I do not click an official-account crypto post until the company confirms it on a second channel. Hardware keys go on every brand social login I run.