Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Verified social media accounts can still be hijacked for crypto scams

Hackers briefly took over Microsoft’s verified X account and used it to promote a fake cryptocurrency, highlighting how verification badges do not guarantee current control.

Microsoft confirmed that its official X account, followed by over 13 million users, was compromised and used to repost content promoting a fictitious cryptocurrency called $Clippy. Two unauthorized posts - a quote about the Clippy character and an apology - were later removed after the breach was secured. Similar attacks have targeted other verified profiles, including HBO Max’s Reddit account, which pushed hundreds of malicious ads, and the SEC’s X account, whose false Bitcoin-ETF announcement briefly spiked the market.

Hackers exploit credential theft methods such as phishing and SIM-swap to bypass two-factor authentication, showing that a verification badge only confirms past ownership, not present control. The piece outlines seven safeguards, from cross-checking announcements on official websites to using strong passwords and 2FA. It also advises immediate actions if a user clicks a suspicious link, enters credentials, or connects a crypto wallet.

Why it matters

A hijacked verified account can lend false credibility to scams, risking financial loss for millions of followers.

In this story

verified accountsocial media scamcryptocurrency pump-and-dumpaccount takeoverSIM swapphishingsecurity checklistcrypto wallettwo-factor authentication
Get the beta ↗