Interesting

New Online Poker Scandal: What We Know So Far

By:

October 1, 2026 · 8 minutes

Online poker table illustrating a high-stakes poker scandal and potential cheating

A new online poker scandal has sent shockwaves through the high-stakes poker community after a cybersecurity researcher claimed that remote-access software was secretly installed on the Windows computers of multiple high-stakes poker players.

According to the investigation, the software could give an attacker real-time access to an affected player's screen, potentially allowing them to see hole cards while games were in progress. The software could also provide much broader access to the compromised computer.

Importantly, the available information so far points to compromised third-party poker software rather than a direct breach of an online poker site‘s own client or servers. The software at the center of the investigation is known as MeshAgent, a legitimate remote-management tool that was allegedly used to gain unauthorized access to players' computers.

The investigation is still developing, with questions remaining about how many players were affected, how the access was used, and whether the alleged cheating can be linked to specific poker accounts.

What Happened? The WolfSec0x0 Investigation

The online poker scandal came to light on September 29, 2026, when a cybersecurity researcher operating under the name WolfSec0x0 published a series of posts on X warning online poker players about a covert remote-access agent found on Windows PCs.

According to the researcher, the agent had been installed through compromised third-party poker software and could give an attacker real-time access to an affected computer. This included viewing the player's screen, potentially exposing their hole cards, as well as controlling the mouse and keyboard. The attacker could also access data stored on the PC, including browser-saved passwords, session cookies, and saved payment card information.

WolfSec0x0 estimated that around 30 high-stakes poker players across Europe, North America, and Oceania may have been affected, with activity potentially dating back to March 2024.

The agent was identified as MeshAgent, a component of MeshCentral, a legitimate open-source remote-management platform. According to the investigation, it was installed as a hidden Windows service with system-level access.

Importantly, the poker sites themselves were not identified as the source of the compromise. Instead, the investigation pointed to compromised third-party poker tools. WolfSec0x0 said the investigation was ongoing and that current versions of the affected software were no longer distributing the malicious code.

How Did the Attack Reach Poker Players?

Available evidence suggests the remote-access agent reached players' computers through compromised third-party poker software rather than the poker sites themselves.

Two poker utilities have now been identified: Jurojin Poker and IntuitiveTables. Jurojin has confirmed that an attacker intermittently replaced update packages delivered to a specific group of users, with some compromised versions containing the remote-access tool. IntuitiveTables has also confirmed that its software was compromised.

The attack appears to have been highly targeted rather than a mass distribution campaign. According to Jurojin, the compromised updates were selectively served to a specific group of users, while the cybersecurity investigation estimates that between 10 and 30 high-stakes players may have been affected.

What We Know vs. What Remains Unclear

What We KnowWhat Remains Unclear
MeshAgent was found on affected Windows PCsWho controlled the remote-access infrastructure
Two third-party poker tools were compromisedThe full number of affected players
Jurojin and IntuitiveTables have been identifiedThe total financial losses
The agent could provide remote access to affected PCs, including access to players' screens and hole cardsWhich specific poker accounts benefited from the access
The earliest confirmed activity dates back to March 16, 2024How much money, if any, was won through the alleged access

The investigation is still developing, so some of these answers may become clearer as poker sites, software providers, and cybersecurity researchers examine the affected systems and account histories.

The Alleged Superuser Connection

As details of the security investigation emerged, a separate community investigation began focusing on several high-stakes poker accounts that appeared to be connected to Canadian player Paul Gregg.

The screen names identified in reports include:

Poker SiteScreen Name
GGPokerPaul Gregg
CoinPokerEurope
WPNJackKlompus
WPNOxOO
WPNEz[Pz]

According to PokerListings, SmartHand data shared by high-stakes regular Aleksey “Avr0ra” Borovkov showed that the OxOO and JackKlompus accounts generated more than $837,000 in combined profit. The accounts also showed unusually strong results at high stakes.

WPN poker results and statistics for the JackKlompus and OxOO accounts
OxOO and JackKlompus accounts won more than $837,000 in combined profit

However, these results alone do not establish that the accounts were involved in cheating. Separate community investigations have linked several high-stakes screen names to Paul Gregg, but these allegations have not been independently verified.

The distinction is important because the cybersecurity investigation and the account allegations are currently two related but not fully established parts of the story. WolfSec0x0's research identified the remote-access agent on players' computers, but did not publicly name Paul Gregg or link the MeshAgent investigation to any specific poker account.

Why This Could Be a Superuser Scandal

The term superuser has a specific meaning in online poker. It generally refers to an account or system access that lets someone see information ordinary players cannot, most importantly, their opponents' hole cards.

This differs from real-time assistance (RTA). With RTA, a player uses software or external tools to receive decision-making assistance while playing. The player still has to make decisions based on the information normally available to them.

In the current case, however, the allegation is fundamentally different. If the reported remote access worked as described, an attacker could potentially see an affected player's screen in real time, including their hole cards. That would mean gaining access to information that the opponent is never supposed to see.

There is also an important technical distinction: this does not appear to be a traditional superuser account built into a poker site's software. Instead, the alleged access was obtained through the player's own computer. The poker client could therefore be functioning normally while someone remotely viewed the information displayed on the player's screen.

How Does This Compare With Past Superuser Scandals?

The idea of someone seeing opponents' hole cards is not new to online poker. Two of the most notorious historical examples are Absolute Poker and UltimateBet, where cheating investigations uncovered systems or accounts that gave unauthorized access to opponents' cards. A U.S. congressional hearing document later described both cases as involving “superuser” accounts capable of seeing other players' hole cards.

The current case differs in one important respect: the alleged access did not come directly from the poker site's internal systems. Instead, the attacker allegedly accessed the player's computer through compromised third-party software. If confirmed, the practical advantage could nevertheless be similar – seeing an opponent's hole cards before making decisions.

Paul Gregg and the Earlier CoinPoker Case

One of the most notable details to emerge from the community investigation is that Paul Gregg was reportedly involved in an earlier security case on CoinPoker.

Patrick Leonard said that CoinPoker's security team identified an account registered under Gregg's name approximately two years ago and detected activity serious enough to result in a ban. According to Leonard, around $100,000 was confiscated and later redistributed to players who were affected. Gregg reportedly disputed the decision and attempted to challenge it through the relevant gambling authorities, but the matter did not ultimately proceed.

The CoinPoker account was reportedly operated under the screen name Europe, the same screen name that has since appeared among the accounts linked to Gregg in the current community investigation.

That connection is significant, but it needs to be treated carefully. There is currently no public evidence establishing that the earlier CoinPoker case involved MeshAgent, compromised third-party software, or the same alleged method now being investigated. The details of the earlier case are primarily based on Leonard's account, and CoinPoker has not publicly released a complete account of the incident.

The earlier ban therefore does not prove that Gregg was involved in the current investigation. However, it is an important part of the background because the same player and screen name have now resurfaced in a separate, developing investigation into alleged access to opponents' hole cards.

What Should Online Poker Players Do?

The investigation also raises an important question for online poker players: what should you do if you have used Jurojin, IntuitiveTables, or other third-party poker software on a Windows PC?

Players who have used Jurojin can start by running the company's dedicated Mesh Check tool, which was created to scan Windows computers for Mesh Agent. The tool is available through Jurojin's security notice, giving players a way to check whether their computer may have been affected.

Jurojin Mesh Check tool for scanning a Windows PC for Mesh Agent
Jurojin's Mesh Check tool allows users to scan their Windows PC for Mesh Agent

If the scan identifies Mesh Agent or other suspicious activity, WolfSec0x0 advised potentially affected users to disconnect the computer from the internet and avoid deleting evidence before the system has been examined.

Players should then use a separate, trusted device to change important passwords, starting with their email account and then moving on to poker sites, financial services, and crypto accounts. Active sessions should also be revoked and two-factor authentication enabled where possible.

Because the alleged access could extend beyond poker information, players should also review saved payment information, browser sessions, and other sensitive data stored on the affected computer. Anyone who believes their poker account may have been compromised should also contact the relevant poker site's security team.

The investigation is still developing, so players should follow updates from the affected software providers and cybersecurity researchers rather than relying on unverified community claims.

What Happens Next?

The investigation remains ongoing, and several important questions have yet to be answered. It is still unclear exactly how many poker players were affected, how long the attackers had access to compromised computers, and whether any specific poker accounts can be conclusively linked to the alleged use of the remote-access software.

Poker operators and software providers are continuing to investigate the affected systems and account histories, while the poker community is also examining results and account activity for potential connections to the case.

For now, the reported connection between the MeshAgent investigation and the high-stakes accounts discussed by the community remains unproven. More information from poker sites, software providers, and cybersecurity researchers will likely be needed before the full scope of the incident becomes clear.

Conclusion

The latest online poker scandal highlights a different kind of security threat from the superuser cases of the past. Rather than compromising a poker site's own software, the reported attack allegedly used compromised third-party tools to gain remote access to players' Windows computers, potentially exposing their screens and hole cards.

While the investigation has already identified MeshAgent, Jurojin, IntuitiveTables, and several high-stakes accounts connected to the community investigation, important questions remain unanswered. Until further evidence emerges, the alleged links between the remote-access attack and specific poker accounts should be treated as unconfirmed.

FAQ About the New Online Poker Scandal

Article by
My relationship with cards started thanks to my father. I was still in elementary school when he first taught me how to play Rummy, and I still remember the long evenings spent playing cards with my family. During the poker boom I was still underage, but the televised tournaments immediately captured my attention. I became fascinated with the game and started learning different poker formats whenever I had the chance. Later in life, as an adult, I was fortunate enough to spend four years playing poker professionally. During that time I mainly focused on Heads-Up Sit & Go games, where I found the format that suited me best. Even though my professional career was relatively short, poker remains something I’m grateful to have experienced as a major part of my life. Today I play mostly as a hobby, while writing has become my main focus. That said, my enthusiasm for writing about poker is just as strong as my passion for playing the game once was.

Disclaimer: content on mypokercoaching.com may contain affiliate links to online gambling operators and other sites. When you use our affiliate links, we may earn a commission based on our terms of service, but that does not influence the content on the site since we strictly follow our editorial guidelines. Learn more about how we make money and why we always stick to unbiased content. All content on this site is intended for those 21 or older or of legal gambling age in their jurisdiction.

Copyright © iBetMedia UAB. All rights reserved. Content may not be reproduced or distributed without the prior written permission of the copyright holder.