TLDR
- Malware hidden in poker software updates let a cheater view high-stakes players’ screens and hidden cards in real time.
- Jurojin Poker and IntuitiveTables were both compromised, with Jurojin’s tampered updates sent between June 2025 and January 2026.
- CoinPoker banned an account registered in Paul Gregg’s name, confiscated over $100,000, and repaid affected players.
- One player says he lost between $100,000 and $200,000 to the suspect account.
- ACR Poker has launched a “Screen Shield” to block screen-capture and screen-sharing programs.
High-stakes online poker players were targeted by a malware attack that let a cheater secretly see their screens and hidden cards in real time. The scheme came to light this week.
The attacker is believed to have broken into third-party software that serious players use to manage several tables at once. These programs also set up hotkeys and other game tools.
Jurojin Poker, one of the software makers affected, confirmed that an attacker swapped some of its updates with tampered versions. Those versions contained remote-access software.
“This was a highly targeted operation, not a mass attack,” Jurojin said. The company described the attacker as a “known cheater” who went after specific high-stakes opponents.
A second program, IntuitiveTables, was also compromised, according to Jurojin and reports on the investigation. Neither company has been accused of knowingly taking part.
How the Malware Worked
The malware was built on MeshCentral, a legitimate tool IT departments use to access computers remotely. Once hidden on a player’s machine, a “Mesh Agent” could reportedly let the attacker watch the screen and control the computer.
In online poker, that means seeing an opponent’s face-down cards while a hand is being played. It gives the cheater a huge edge.
A cybersecurity researcher known as “WolfSec0x0” first exposed the operation on X. The researcher initially found between 10 and 30 affected computers across Europe, North America, and Oceania.
Jurojin said its tampered updates went out on and off between June 2025 and January 2026. Only a small group of users was targeted.
Suspicions Around One Account
Some high-stakes players had already raised concerns about accounts posting unusually strong results. PokerNews reported that an account using the name “Paul Gregg” had been flagged before the malware became public.
Poker coach Patrick Howard reportedly sent GGPoker an analysis in September pointing to unusual results. He asked the company to investigate but did not accuse the player of cheating.
CoinPoker ambassador Patrick Leonard said the crypto poker site had earlier banned an account called “Europe.” He said it was registered in Paul Gregg’s name. The site confiscated more than $100,000 and repaid affected players.
High-stakes player Ignacio Morón claims he lost between $100,000 and $200,000 against the suspect account. That includes about $60,000 in a single 15-minute session.
The case has drawn comparisons to older scandals. In 2007, an Absolute Poker account called “Potripper” was exposed by players on the TwoPlusTwo forums.
Absolute Poker later admitted seven accounts had cheated players over 40 days and promised $1.6 million in refunds. Insiders had used software that showed opponents’ hole cards, a feature players called “God Mode.”
A larger scheme hit sister site UltimateBet. Investigators named former WSOP Main Event champion and UltimateBet consultant Russ Hamilton as the main offender.
Jurojin said it has contacted potentially affected customers. It has also shared information with law enforcement and poker-site security teams.
ACR Poker has already responded with a new “Screen Shield.” The tool is designed to block its tables from being seen by screen-capture and screen-sharing programs.
