On Sunday, September 27, 2026, somebody logged into a handful of poker players' computers that they had no business being on, ran a script that uninstalled a piece of remote-control software, deleted the script, and left. It was housekeeping. The net was closing, the victims had started comparing notes in private groups, and whoever had been watching their screens for the best part of two years wanted the evidence gone before anyone with a forensic toolkit got there.
They were about two days too late. By Tuesday night an anonymous security researcher had published a full incident report, by Wednesday one of the software vendors used to deliver the thing had confessed in writing, and by the time you read this, every high-stakes cash regular on GGPoker, ACR and CoinPoker has either run a PowerShell command or is pretending they have. This is the story of how a legitimate IT tool ended up reading hole cards at $25/$50, who the community thinks was behind it, and what is proven versus what is merely very loud.
A tool built for IT departments, pointed at poker tables
The software at the centre of this is called MeshCentral. If you have never heard of it, that is because you are a poker player and not a sysadmin. It is an open-source remote administration platform created by Ylian Saint-Hilaire and sponsored by Intel until 2022, and the small program it installs on each managed PC is called the Mesh Agent. Companies use it so a help desk in one city can fix a laptop in another: watch the screen, move the mouse, run commands, copy files. Nothing about it is secret or illegal, which is exactly why it makes such a good weapon. Antivirus products tend to wave it through, because for every criminal who installs it there are ten thousand IT departments who did so on purpose.
Install it quietly on a poker player's Windows machine, point it at a server you control, and you have what the industry spent fifteen years calling a superuser account, except this time the poker room never knows. According to the public report by the researcher posting as @wolfsec0x0, the agent ran as a Windows service named "Mesh Agent" with full system privileges, hid its own files, kept an encrypted connection open to the attacker's server, and started a system-level PowerShell process roughly every 20 minutes while connected. On several machines it had also added a Microsoft Defender exclusion covering the entire C:\Windows folder, which is the digital equivalent of telling the security guard not to look at the back door.
Live view of the whole screen, hole cards included, during real-money play.
Control of mouse and keyboard, and commands run as SYSTEM.
File transfer both ways, which means browser-saved passwords, session cookies and saved payment cards were reachable.
Remote uninstall via self-deleting scripts, observed on September 27, 2026.
Any breach of a poker room's servers or client. The researcher says GGPoker and ClubWPT Gold are "not involved"; no room has reported a compromise.
Access to opponents who were not infected. The edge existed only against the ten to thirty players with the agent installed.
A public forensic link between the agent's server and any named poker account. That link so far rests on results data and player testimony.
Source: public incident report by @wolfsec0x0, September 29, 2026. Analysis was static only; no sample was executed and no connection was made to attacker infrastructure.
The update that wasn't an update
The clever part, and the part that should worry anyone who multi-tables, is how it got there. Nobody had to phish a world-class reg into clicking a dodgy link, although the attacker apparently ran fake poker-room sites too. Instead, two legitimate, code-signed third-party poker utilities were turned into delivery vehicles. The researcher's report calls them Tool A and Tool B and refuses to name them. The vendors did the naming themselves.
Jurojin, the table-management and hotkey suite, published a security notice on Wednesday, September 30, 2026, also carried in full by PokerNews. Between June 2025 and June 2026, it says, "an attacker was able to intermittently replace the update package delivered to one specific group of Jurojin users with a tampered version," and some of those packages included a remote-access tool. Then the sentence that turns a security incident into a poker story: "It was carried out by a known cheater aiming at specific opponents, mostly at high stakes, with the goal of viewing their hole cards remotely." Jurojin adds that it was one of several applications hit by the same actor, "including IntuitiveTables," and that the actor "also operated phishing sites impersonating poker rooms and well-known poker tools." IntuitiveTables, a rival table manager, has confirmed its own compromise according to PokerStrategy; we have not seen a standalone statement from that vendor at the time of writing.

Read Jurojin's statement again and notice what kind of attack this was. Not every user got the poisoned update. Only "one specific group" did, and the swap was, in the company's words, "carried out by hand by the actor, not a mass or automated blast." Somebody sat on the update server and chose which players would receive the backdoor, which means they already knew who they wanted to play against before a single card was dealt. The researcher's timeline puts the first confirmed agent activity on March 16, 2024, so some victims predate Jurojin's June 2025 window, which is consistent with two tools, two time periods, and a phishing side-business filling in the gaps. One backdoored build was signed with the vendor's own valid code-signing certificate in early March 2026, one day after a clean build. If you ever wondered what "supply-chain attack" means in a poker context, that is it.
Jurojin's notice also publishes a list of phishing domains it says were hosted on the same server as the attack infrastructure, and it reads like a who's who of the sites this audience plays on: lookalikes for Bodog, Ignition, ACR, GGPoker, PokerKing, the Winning Poker Network and BCPoker, plus fake download pages for Hand2Note, IntuitiveTables and a "GTO software" domain. Some use the old trick of a foreign-alphabet character swapped into a familiar name so the address looks right at a glance. The company says nothing further was uploaded to its servers after January 28, 2026, that its own records show "only a handful of high-stakes players were harmed by actually playing against the attacker while their hole cards were exposed," and that every user who may have received a tampered package has been emailed from its support address. If you use Jurojin and got no email, their position is that your install never received the bad build.
A short list of high-stakes regs, mostly cash, who use a specific tool.
Only those users receive a tampered package; everyone else gets the clean build.
A hidden Windows service with SYSTEM rights, plus a Defender exclusion so nothing gets scanned.
Encrypted link to the operator's server; a screen feed is available whenever the victim sits down.
Play 90%+ of your hands against infected regs, play normally against everyone else, bank the difference.
Steps 1 to 4 per Jurojin's statement and the @wolfsec0x0 report. Step 5 per Aleksey "Avr0ra" Borovkov's reconstruction, reported by GipsyTeam.
The cast
Because this broke in Russian Telegram channels, closed high-stakes chats and an X account with 230 followers before it reached any newsroom, the names flying around are not all household ones. Here is who matters.
Anonymous, credits a "KCC Discord," had 230 followers on Tuesday morning and more than 750,000 views on the thread by Thursday. Published a full technical report with file hashes and a MITRE ATT&CK mapping, which is not how hoaxes usually dress.
Canadian high-stakes cash player who used his real name on GGPoker. Named by Avr0ra, by victims, and indirectly by CoinPoker's Patrick Leonard. Has not responded publicly. No room has confirmed his involvement and no charges have been announced.
Russian NL1K to NL40K cash reg based in Argentina, Super Millions streamer, and the person who wrote up the first detailed public reconstruction on Telegram, including the 90% opponent-selection pattern.
Russian high-stakes player who says he privately accused Gregg from April 2026, found the Mesh Agent on his own PC, and believes he lost the most money of anyone.
British pro and CoinPoker's most public face. Called it "one of the biggest things that has happened in online poker" and disclosed that CoinPoker had banned an account under Gregg's name about two years earlier.
Two table-management and hotkey programs popular with multi-tablers. Both confirmed compromised. Neither is accused of complicity; both were the delivery truck, not the driver.
Following the money across three networks
The accusation against Gregg did not start with malware. It started the way most online cheating cases start: with results that were too good against the wrong people. The account names the community has tied to him are "Paul Gregg" on GGPoker, "Europe" on CoinPoker, and "JackKlompus," "OxOO" and "Ez[Pz]" on the Winning Poker Network, home of ACR. The figures below come from the public results trackers StatName and SmartHand, as compiled by Avr0ra and reported by PokerListings and Poker-Red. They are tracker numbers, not audited ones, and they show profit, not how much of it came from infected opponents.
A sanity check on the numbers, since this is a site that likes its arithmetic shown. The 2025 figures alone, $232,000 plus $162,000, come to $394,000 across the two WPN names. High-stakes player Frankie Carson posted on September 30 that JackKlompus won around $400,000 in early 2024 at "+24bb/100 vs the best in the world," went quiet in the summer of 2025, and resurfaced in October as OxOO for another $400,000. Two times $400,000 is $800,000, which is close enough to SmartHand's $837,000 to suggest everyone is looking at the same database. For scale, 24 big blinds per hundred hands at $25/$50 is $1,200 per hundred hands, a win rate that would make the best regs in the world blush and that, against the best regs in the world, is not supposed to exist. Carson also claims the account then deliberately dumped at lower stakes to drag its blended win rate down to a more believable 11bb/100. That is his read, not an established fact, but it would fit the profile of someone who understood that security teams look at outliers.
GipsyTeam's headline figure is "almost $900,000" on WPN alone; Avr0ra wrote of "10+ (and maybe even more) regs" scammed "for several million dollars on GG, AKR, and Coin." The honest range, then, runs from the $837,000 that can be pointed at in a tracker to a multi-million total that nobody has itemised in public. Treat the big number as a community estimate until a room publishes one.
Why a site's security team never saw it
This is the piece that separates a merely nasty story from an important one. Every superuser scandal in poker history, from POTRIPPER at Absolute Poker to the Russ Hamilton era at UltimateBet, involved a hole in the operator. Someone inside, or someone with inside-level access, saw every card at the table. Operators got very good at detecting that pattern, because a player who wins against everyone, in every spot, lights up every anomaly model ever built.
What Avr0ra and the victims describe is different. The suspect could only see the cards of the specific players whose machines carried the agent. Against everyone else he was a normal, strong reg, probably winning a bit, probably losing a bit. So he did what any sensible cheat would do with a partial edge: he bumhunted. According to the reconstruction reported by GipsyTeam, "he won all his money from certain regs, and played 90%+ of his hands with them at the tables, meaning he was deliberately selecting them." To a room's models, that looks like an aggressive table selector, which at high stakes is practically everyone. The win rate against the whole pool stays plausible. The win rate against four or five specific opponents is obscene, but nobody was slicing the data that way.
The victims were. Kovtunov's account of what it felt like from the other side of the table is the closest this story has to a smoking gun that isn't a registry key: "when someone can't lose a pot more than 30bb, and always chooses perfect lines and sizings with any of your hands, it feels like you're just being spun around on a carousel of absurdity." He says he had been accusing Gregg in private messages since April 2026, posted his suspicions in a closed group called HS Anti-Rat about a month before the story broke, and that "two days later, he hit the jackpot and never showed up at the tables again." Kovtunov's theory, and it is only a theory, is that someone watching his screen also watched him type the accusation. The example hand doing the rounds, in which the suspect declines to 4-bet kings against him, is interesting only in aggregate; Avr0ra's point was that the suspect was not playing "completely stupidly" and was actively trying to look like a human.
CoinPoker had already thrown him out
The most damaging detail for Gregg did not come from a hacker or a rival. It came from an operator. In a post shared as a screenshot and quoted at length by Poker-Red and GipsyTeam, Patrick Leonard, the English high-stakes pro who fronts CoinPoker, said that roughly two years earlier CoinPoker's security team caught an account doing something serious enough that they banned it and confiscated $100,000, redistributing the money to the players it had been winning from. The account holder complained to the gambling regulator, insisted on his innocence, and then, per Leonard, did not pursue the claim once CoinPoker made clear it was happy to go to a hearing with its evidence. The registered name on the account, Leonard said, was Paul Gregg, and his CoinPoker screen name was "Europe." Leonard's framing of the severity was blunt: a confiscation on that scale is not what happens to someone caught leaning on a solver.
Why does that matter now? Because "Europe" is one of the accounts on the list the community has drawn up this week, which means an operator had already identified the same person as a serious cheat around 2024, and he kept playing, at the highest stakes, on other networks, for two more years. Leonard's own view, in the same post, was that someone like that could not keep getting away with it on GGPoker unless the room's security was either compromised from inside or badly below par. That is one operator's employee throwing shade at another operator and should be read as such, but it captures the mood: the rooms do not share blacklists, and this is what that costs.
What the rooms are saying, and what they aren't
Not much, so far, and that is partly fair. GGPoker has emailed at least some players; the French site Club Poker quotes a message telling recipients that during a routine security check the room's systems "detected the presence of MeshAgent on your computer," and advising them to investigate if they did not install it themselves. That is a sensible step and also an interesting one, because it suggests GG has at least some visibility into what runs alongside its client. Neither GGPoker, ACR nor CoinPoker had published a statement naming any account or confirming any confiscation by Thursday, October 1, 2026. The researcher was explicit that GGPoker and ClubWPT Gold were not the compromised software. Todd Witteles, who has spent a career on poker fraud, made the same point on X on day one: this is a third-party tool problem, not a client problem.
Law enforcement is the other open file. GipsyTeam reports that "the fraudster's data has already been transferred to the FBI and other agencies," attributed to a colleague of the Telegram poster who first raised the alarm. Jurojin says it holds logs of every compromised version and the date each one was served, has "already contacted anti-fraud and law-enforcement authorities," and has shared its findings with poker room security teams. Whether any of that becomes a case depends on a jurisdiction deciding that reading hole cards on a Curaçao-licensed site is a crime it wants to prosecute, which historically has been a slow decision.
Jepsen, POTRIPPER and the long history of seeing cards
If the method sounds familiar, it should. Peter Jepsen, a Danish pro, was convicted in Copenhagen in December 2019 of installing trojan software on the laptops of high-stakes regulars, often at European Poker Tour stops, between 2008 and 2014. The court handed him a three-year sentence with six months knocked off for time served, a fine of roughly 3.5 million euros, and confiscated about $3.9 million, which prosecutors said was roughly what he had won with the edge. Jepsen needed accomplices with physical access to hotel rooms. The 2026 version needed an update server and a list.
The comparison everyone reaches for, though, is the Absolute Poker and UltimateBet affair of 2007 and 2008, when insiders could see every hole card at the table. Absolute refunded $1.6 million and was fined $500,000 by the Kahnawake Gaming Commission; the Russ Hamilton cheating at UltimateBet was later found to have run from 2004 to January 2008. Those were operator failures and they changed how the industry audits itself. This one is a player-hardware failure, and the industry has no audit for that, because until this week nobody had seriously considered that the weak point in a $10,000 pot might be a hotkey program that costs less than a month of Netflix.
Five minutes with PowerShell
If you play on Windows and have ever installed a table manager, a HUD, a hand converter or anything else that promised to shave a second off your clicks, do this today. It changes nothing on your machine; it only reads. Open PowerShell as administrator and run:
Get-Service -Name 'Mesh Agent' -ErrorAction SilentlyContinue Get-ChildItem 'HKLM:\SOFTWARE\Open Source' -ErrorAction SilentlyContinue Get-Item 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MeshCentralAgent' -ErrorAction SilentlyContinue (Get-MpPreference).ExclusionPath
The first three lines look for the service and the registry keys it leaves behind, which survive even after the operator remotely uninstalls it. Any output at all means a Mesh Agent is, or was, on that PC. The last line lists Windows Defender's folder exclusions; if C:\Windows appears and you did not put it there, the researcher's advice is to treat the machine as compromised even if no agent is found. One caveat he is careful to include: MeshCentral is used legitimately by employers and IT providers, so if your work laptop is managed by someone, ask them before you panic.
If you do find it, the order of operations matters more than the speed. Unplug the network cable before you delete anything, because the install logs and registry keys are evidence that poker sites and police will want. From a different, clean device, change your email password first, since email is the master key to everything else, then poker accounts, exchanges and banks, sign out of every session everywhere and turn on two-factor authentication. Ask your card issuer to replace any card your browser had saved. If a software crypto wallet lived on that PC, move the funds. Report it to every room you play on. Then wipe and reinstall Windows. Removing the agent is not enough, because an operator with SYSTEM access for a year could have left anything behind, and the whole point of this week is that you would not know. And whatever you do, do not install a "Mesh Agent detector" that someone kindly sent you on Telegram. Jurojin has published its own checker, built on the same commands above, and says the only official copy lives on jurojinpoker.com; the attacker in this story ran fake download pages for poker tools, so a mystery link to a "fix" is exactly the kind of thing to be suspicious of this week.
What is still unproven
It is worth being precise, because a lot of people are about to lose their minds and a few of them will be lawyers. What is confirmed by evidence: that a Mesh Agent was planted on multiple poker players' PCs without consent from March 2024 onward, that two code-signed poker tools were used to deliver it, that Jurojin was one of them and says it was done by hand to a chosen group, that IntuitiveTables was the other according to Jurojin and the trade press, and that someone remotely cleaned up on September 27. What is strongly supported but not forensically published: that the accounts JackKlompus, OxOO, Ez[Pz], Europe and Paul Gregg were the beneficiaries, which rests on tracker results, victims' testimony and the 90% opponent-selection pattern rather than on a server log tying the agent to a login. What is hearsay or estimate: the multi-million total, the FBI referral, and whether Gregg acted alone or, as Avr0ra and Boris Grabowski both suspect, as the front for a small team that did the phishing and the signing.
Jurojin's statement uses the phrase "a known cheater." WolfSec's report never uses a name at all. Somewhere between those two documents is the version of this story that ends in a courtroom, and that version has not been written yet. What has been written is a reminder, in registry keys, that the most dangerous piece of software on a poker player's computer is usually the one they installed on purpose.
Run the check above, then read how each room handles security, confiscations and refunds before you pick where to grind.
Our room reviews cover anti-cheating policy, third-party tool rules and what each operator has actually done when players were wronged, including GGPoker, Americas Cardroom and CoinPoker.
Compare poker rooms on GlobalPokerSitesSources: @wolfsec0x0 thread, September 29, 2026; full public incident report (Pastebin); Jurojin security notice, September 30, 2026; PokerNews, Jurojin statement; PokerNews, September 29; GipsyTeam; Poker-Red; PokerListings; PokerStrategy; Club Poker; Patrick Leonard on X; Frankie Carson on X; MeshCentral (Wikipedia); Card Player on Peter Jepsen; Absolute Poker / UltimateBet (Wikipedia); GipsyTeam interview with Avr0ra, 2023.

