Mesh Agent Scandal Update: What We Got Wrong, and What the Rooms Still Won't Say
← Back to Articles
news

Mesh Agent Scandal Update: What We Got Wrong, and What the Rooms Still Won't Say

On Wednesday we published a long read on the Mesh Agent scandal, the case in which a remote-access tool was slipped onto high-stakes players' PCs through two poisoned poker utili...

On Wednesday we published a long read on the Mesh Agent scandal, the case in which a remote-access tool was slipped onto high-stakes players' PCs through two poisoned poker utilities, and a Canadian cash reg named Paul Gregg became the community's prime suspect. That piece was written while the story was still mostly a hacker's thread and a Russian Telegram channel. Forty-eight hours later it is something else: a vendor's forensic write-up, two poker-room ambassadors on the record, a victim putting a dollar figure on it, and an operator admitting it had a warning in its inbox a month before the story broke.

This is the update. Where Wednesday's article got something wrong, we say so below. Where the new material changes the picture, it is mostly in one direction: the cheat was cruder, and more patient, than the first reports suggested, and the rooms had more chances to stop it than they have so far admitted.

What changed between Wednesday and Saturday
We reported

Jurojin's tampered updates ran from June 2025 to June 2026.

Now known

Jurojin's revised notice dates the last tampered upload to January 28, 2026. The poisoning ran about seven and a half months, not twelve.

We reported

CoinPoker banned an account under Gregg's name "about two years earlier."

Now known

Patrick Leonard now says "around 1 year ago"; Mario Mosböck says "2+ years ago." Both agree on the $100,000-plus confiscation and refund. The date is unresolved.

We reported

Roughly 30 players infected, the researcher's estimate.

Now known

Thirty was the number of players who had confirmed an agent on their own PC when the thread went up. The researcher says "a much larger number" have been found since.

Sources: Jurojin security notice (updated October 2, 2026); Patrick Leonard and Mario Mosböck on X, October 2; @wolfsec0x0 on X, October 2.

One capital letter

Start with the part nobody had on Wednesday, because it is the most poker thing in the whole affair. Jurojin, the table manager at the centre of this, has now published a plain-language technical account of how its updates were switched, and the trick turns out to be about as sophisticated as a chip-dumping scheme. Jurojin stores its builds on Amazon S3, a cloud file store, and each group of users has a saved address for its update file. The attacker created a second folder whose name differed from the real one by a single letter, a lowercase n where the original had a capital N. Amazon treats those as two different places. Swap a group's saved address to the lowercase version, drop a tampered zip there, and every account in that group downloads the backdoor at its next update while the signed launcher behaves exactly as it always does. Swap the address back afterwards, move the accounts out of the group, and anyone glancing at the configuration later sees a normal address and a different set of people.

Because S3 keeps every previous upload, Jurojin could reconstruct the whole on-off cycle. Its count: between June 11, 2025 and January 28, 2026 the tampered file was uploaded, replaced with a clean one, then uploaded again, across 92 separate windows. The longest lasted about five days; many lasted hours. Added together, the poisoned build was the live download for 72.7 days, and a clean one for 158. That span is 231 days, and 72.7 plus 158 comes to 230.7, so the arithmetic closes. The average window works out to 72.7 divided by 92, about 0.79 of a day, or 19 hours. Somebody was logging in, flipping the switch, waiting for a specific player to update, and flipping it back, roughly every two or three days for seven months. That is not a hacker spraying malware. That is a grinder with a schedule.

The on-off update, June 11, 2025 to January 28, 2026

231 days on the altered download path, by Jurojin's own S3 version history.

 
 
72.7 days

Tampered zip was the live download, spread across 92 windows.

158 days

Clean build in place between windows, so the group looked normal.

~19 hours

Average window. The longest ran about five days.

Source: Jurojin, "How an update works, and how this one was changed," published October 2, 2026. Last tampered file replaced January 28, 2026 at 14:25 UTC.

Two more details from the same document matter for anyone deciding whether to panic. First, not every tampered zip carried the remote-access tool, and not everyone in the group updated during a window, so being served a bad package is not the same as being infected. Second, the Jurojin build did not check who you were. If you were in the group and updated at the wrong moment, you got it. The targeting-by-screen-name behaviour that the researcher @wolfsec0x0 described on September 30, where the compromised software read your hand-history folders, compared the username against a list on the attacker's server and only then pulled down the payload, belongs to the IntuitiveTables variant according to Jurojin, "as far as we know." IntuitiveTables itself has told its Discord that a "known cheater" targeted multiple poker applications to plant spyware on specific high-stakes players' devices, in a notice shared as a screenshot on X; we have not found a public statement page from that vendor.

Jurojin has also quietly added two screen names to its list of accounts players should report to their rooms: "2x pgs" and "Joey Peeps," which it says are "known to be part of this," room not known. They sit alongside the names from Wednesday, Paul Gregg on GGPoker, JackKlompus, OxOO and Ez[Pz] on the Winning Poker Network, and Europe on CoinPoker. The company is careful to call all of them community accusations rather than verified facts, and it is right to be.

The room that needed a week

On Friday, October 2, Patrick Leonard, the English high-stakes pro who fronts CoinPoker, deleted what he called his "ambiguous posts" from the week and replaced them with a summary. The same player, he wrote, "has played across basically all the sites." CoinPoker "caught him around 1 year ago after he had played less than a week on the site. ofc we didn't know exactly what he was doing, but it was obvious he had more information than other players." The account holder took the case to regulators, CoinPoker "fully obliged," the process "lasted a short while," and the room then refunded every affected player.

Then the sentence that will follow the other rooms around for a while. "A group of around 100 regs came together and told those sites starting a couple years ago what they suspected with very good details. He somehow was allowed to continue playing on those sites, winning and withdrawing at win rates that were likely not possible and showdowns that didn't make sense."

Mario Mosböck, the Austrian high-stakes player who is CoinPoker's other ambassador, filled in the texture. The security team, he said, caught Paul Gregg "2+ years ago and refunded Ignacio Moron and others 100,000$+," and had asked him and Leonard for advice "as it was very hard to make sense of it." The problem was that Gregg "was a decent player so spotting it was not easy. However the data was quite clear and crushing one of the best HU players seemed impossible." After the confiscation, Mosböck says, Gregg "continued to lie and threatend." Note the timing gap: Leonard says around a year, Mosböck says more than two. Both are speaking from memory on a Friday and neither has posted a date. Until CoinPoker publishes one, treat the ban as "2024-ish."

The obvious follow-up came within the hour: if CoinPoker knew, why did nobody else? Leonard's answer was blunt and, in fairness, accurate about how this industry works. "Every site bans people every day, no site has ever told another site the players they have banned." CoinPoker did not know how he was doing it, he added, because nobody did. "I've used Jurojin every single poker session since, if we knew that I wouldn't have done that!!" He also noted that "Coin had been fully banned from gg/wsop/acr anyway, no patches allowed anywhere, no cooperation," which is a crypto room pointing out that the big rooms will not take its calls. Whether that excuses silence about a confirmed six-figure cheat is a question for the whole industry, not one operator. Rooms do not share blacklists. Until this week that was an inconvenience. Now it has a price tag.

The report in GGPoker's inbox

The most uncomfortable new detail belongs to GGPoker, and it arrived via Spain. On Thursday, October 1, Poker-Red, the long-running Spanish poker outlet, reported that Patrick Howard, the high-stakes player and coach behind Mobius Poker, had sent GGPoker a database review of the Paul Gregg account dated September 1, 2026, a full four weeks before the Mesh Agent thread went public. Howard had pulled 32,780 hands after a friend's losses stopped making sense.

What 32,780 hands of "Paul Gregg" looked like
+13.9

bb/100 overall win rate across the sample

75.6%

of river showdowns won when playing deep

+2,497 bb

won in pots larger than 150 big blinds

~55%

of total profit from those big pots (our arithmetic, below)

Figures from Patrick Howard's September 1, 2026 review as reported by Poker-Red. Howard's own conclusion: "no clear superuser signal, keep monitoring."

Run the numbers and you see why the report read the way it did. At 13.9 big blinds per hundred over 32,780 hands, total profit is 32,780 divided by 100, times 13.9, which is about 4,556 big blinds. Of that, 2,497 came from pots over 150 big blinds, so roughly 55 percent of the win came from the biggest pots, and Howard noted the edge grew as pots got larger. That is exactly what a player who can see cards would produce: unremarkable in small pots, where seeing cards barely matters, and lethal in the ones that decide a session. It is also what a strong, aggressive reg on a heater would produce, which is why Howard's conclusion was cautious. The document described itself as a review of anomalies, "not an accusation nor proof of misconduct," and asked GGPoker to keep watching with the same criteria.

As of Poker-Red's publication, GGPoker had not replied to him. Howard confirmed the sequence on X on Friday evening: the report was "a database review I did in early September, flagging anomalies for GG to keep monitoring, not an accusation. GG reached out to me today." Today was October 2, 2026, the day after the story about the report ran. GGPoker has not published a statement, though as we reported Wednesday it has emailed some players telling them its systems detected MeshAgent on their machines. For a room that promised to double its security team after the December 2023 client exploit, the optics of a month-old anomaly report sitting unanswered are not good, and it knows it.

"He also knew how to play poker"

Ignacio "Nacho" Morón is the first victim to put his name and a number on the record. The Spanish high-stakes reg told Poker-Red on Friday that he sat down heads-up with the account and, in our translation, "in the space of 15 minutes he took about 60,000 dollars off me." That is $4,000 a minute, for anyone keeping score at home. His total, he says, is "minimum, very very conservatively, 100,000 dollars for sure," and "possibly 150k or 200k." CoinPoker refunded him around $60,000 after its ban, which lines up with Mosböck's "Ignacio Moron and others."

His sharpest observation is the one that explains how this lasted so long. "He didn't just see your cards, he also knew how to play poker." A clown with a hole-card feed shows up in a week, as CoinPoker's experience suggests. A competent reg with a hole-card feed who only uses it against five people, and plays normally against the other thousand, looks like a competent reg. Morón says he and others filed reports on related accounts "more than 20 or 30 for sure," puts the responsibility on the rooms because "it's too much time," and wants them to talk to each other. His own guess at Gregg's take, "around a million on ACR and around a million and a half on GGPoker," is a figure he heard, not one he can show, and he says so himself.

A second Spanish reg, Manuel Saavedra, who plays as J0hn Mcclean, wrote on September 30 that the agent sat on his PC for more than a year, that the suspect was "practically all day in the lobby" and would open heads-up tables specifically to play him, and made a point that gets lost in the big-number headlines. Every time the suspect sat at a full table with an infected player, he was not just beating that player. He knew two more cards than everyone else at the table, "two extra blockers the others could not know." The uninfected regs at those tables were being cheated too, just less directly, and no room has yet said whether its refund review will extend to them.

Thirty was the floor

The researcher who started all this has spent the week fielding one question above all others, and late on Thursday, October 1 answered it. The "~30" in the original thread "was the CONFIRMED number of players that had found MeshAgent running on their boxes." Since then "a much larger number of players have been found," and the poker sites, WolfSec lists "WPN, COIN, WPT, etc," have emailed anyone they have a record of playing with the agent present. The second half of that is notable: it means at least three networks can tell, after the fact, which of their players had a MeshAgent process alongside the client. The researcher is now specifically asking to hear from anyone who found an active agent and has never used Jurojin or IntuitiveTables, which is the polite way of saying the two-tool theory may not be the whole theory.

One infrastructure detail surfaced on Friday via Poker-Red, attributed to a member of the high-stakes group tracking the case: every known infection phoned home to the same IP address in Moldova, which was also associated with the poker phishing pages. That is hearsay from a closed group, but it is consistent with Jurojin's list of lookalike domains for Bodog, Ignition, ACR, GGPoker, PokerKing and friends all living on one server, and it is the kind of detail that makes "someone installed this legitimately" impossible to argue.

Who has said what, as of Saturday, October 3, 2026
CoinPoker

Banned "Europe" after under a week of play, confiscated $100,000-plus, refunded victims. Date disputed between its own ambassadors (one vs. two-plus years ago). Leonard, October 2: "Your funds will be seized, the players won't be cheated. Try somewhere else."

ACR / Winning Poker Network

Official statement October 1: Security and Game Integrity teams "actively reviewing"; contacted relevant players on Tuesday, September 29 and applied "additional precautionary protections." CEO Phil Nagy presented a measure branded Screen Shield on stream October 2; no written detail yet.

GGPoker

No public statement. Emailed some players about MeshAgent detections. Received Howard's anomaly report September 1; contacted him October 2, after press coverage. The "Paul Gregg" account's status has not been announced.

WPT Global

Named by the researcher among rooms that have emailed affected players. No public statement found. Not a compromised client, per the researcher.

Jurojin

Full notice plus technical account, updated October 2. Logs handed to law enforcement and room security teams. Free Mesh Check tool; still recommends a clean Windows reinstall.

IntuitiveTables

Confirmed to its Discord that a "known cheater" targeted it to plant spyware on specific high-stakes players. No public notice page found. Its variant, per Jurojin, did the screen-name matching.

Gold bar: has published a substantive account. Grey bar: has not, or has only emailed privately. Compiled from the operators' and vendors' own posts and pages, linked in the text.

On the ACR side, the October 1 statement is worth reading for what it says and does not say. It confirms the network reached out to "relevant players" on Tuesday afternoon, which was the day the thread went viral, and locked something down on their accounts. It does not mention refunds, confiscations, or the JackKlompus and OxOO accounts that trackers tie to the bulk of the money. Nagy promised to address all of that live across Friday, Saturday and Sunday streams, and the October 2 stream was billed as a "Screen Shield" security update. If you play on WPN, that stream is the primary source until someone writes it down.

What is still not proven

A lot has hardened since Wednesday, so it is worth restating what has not. No poker room has publicly confirmed that any named account was operated by Paul Gregg, or by anyone. CoinPoker's ambassadors have said it on X; the company has not said it on letterhead. No server log has been published tying the Moldovan infrastructure to a poker login. The dollar totals above a few hundred thousand, Morón's "million and a million and a half," the "several million" from Russian Telegram, remain estimates by people who were on the wrong end of them. Howard's own report said there was no clear superuser signal, and he is right that 13.9 big blinds per hundred, on its own, convicts nobody. And nobody has yet explained the gap between March 2024, the earliest agent activity in the researcher's timeline, and June 2025, when Jurojin's poisoning began. IntuitiveTables, phishing, or a third delivery route are all candidates; the researcher's appeal for infected players who never used either tool suggests he is wondering the same thing.

What is no longer in doubt is the shape of the thing. A capable high-stakes player, or a small team fronted by one, ran a hole-card operation for the better part of two and a half years using a one-letter typo in a cloud storage path, was caught by the smallest of the rooms he played on inside a week, and kept playing on the biggest ones for another year or more while a hundred regs and at least one formal report told those rooms something was wrong. The malware was clever. The part that let it work was not.

Before you load the lobby

Which rooms refund, which rooms confiscate, and which ones answer their email.

Our room reviews cover each operator's record on cheating cases, third-party tool rules and what they have actually paid back to players, including CoinPoker, ACR and WPT Global.

Compare poker rooms on GlobalPokerSites.com

Sources: Jurojin security notice and technical account (updated October 2, 2026); Patrick Leonard and Mario Mosböck on X; Poker-Red interview with Nacho Morón; Poker-Red on the Howard report; Patrick Howard on X; @wolfsec0x0 on X; ACR Poker statement on X; Manuel Saavedra on X; PokerNews; Card Player on GGPoker's 2023 breach.

Worth passing on?
Send it to someone who'd want to read this.
GlobalPokerSites Jay
Jay has been grinding online and live poker for over a decade and covers strategy, industry news, and the wilder corners of poker history for GlobalPokerSites.
All articles →