Canadian Pro Paul Gregg Accused of

A security researcher says a remote-access tool was planted on about 30 players' PCs via compromised Jurojin poker utilities, and the high-stakes community has named Canadian player Paul Gregg as the alleged culprit.
What Is Being Alleged
A security researcher has reported that a remote-access tool was planted on the personal computers of approximately 30 poker players through compromised poker utility software. The tool, described as a remote-access trojan, would in principle allow an outside party to view a player's screen and observe hole cards in real time — the core mechanic behind what the poker world calls "superusing."
The software at the center of the allegations is Jurojin, a poker utility used by some high-stakes players. According to the researcher's account, the compromise was not a single isolated incident but a sustained campaign delivered through tampered software updates.
Jurojin Confirms Tampered Updates
Jurojin has confirmed that its update mechanism was tampered with between June 2025 and June 2026. In other words, the distribution channel players trusted to deliver legitimate patches was, for a period of roughly a year, also capable of delivering something else.
That detail matters because it changes the threat model. Players who install a poker tool generally accept some risk in exchange for functionality. They do not expect the update pipeline itself to be the attack vector. When an update server is compromised, even cautious users can be affected without any obvious warning sign.
The Community Names a Suspect
The high-stakes community has named Canadian player Paul Gregg as the alleged culprit behind the scheme. It is important to be precise about what that means: the accusation is circulating within the poker community and has been tied to the security researcher's findings, but naming a suspect is not the same as a formal finding of guilt. No independent adjudication of the allegation has been described in the available material.
Allegations of this kind tend to move quickly through high-stakes circles, where the player pool is small, reputations are visible, and the financial stakes are large. They also tend to be difficult to resolve quickly, because the technical evidence often sits with private security researchers rather than with a public regulator.
Why Superusing Is So Damaging
Superusing is considered one of the most serious forms of cheating in online poker. In a typical case, a cheater gains access to one or more opponents' hole cards — either through a shared screen, a compromised device, or a colluding account. With that information, decisions that should be probabilistic become near-deterministic.
The damage is not limited to the hands actually played. Once players suspect that hole cards may be exposed, the integrity of the entire game is called into question. Regulated sites invest heavily in detection, but detection depends on knowing what to look for, and a compromised third-party utility can sit outside a site's direct visibility.
The Broader Risk: Third-Party Poker Tools
This case highlights a structural issue in online poker. Many players use auxiliary software — trackers, HUDs, equity calculators, and training tools — that runs locally on their machines. These tools are often built by small teams, distributed outside major app stores, and updated automatically.
That combination creates a supply-chain risk. A single compromised update can reach many users at once. Players who want to reduce exposure generally have a few practical options:
- Limit third-party tools to those with a clear, verifiable publisher and a transparent update process.
- Keep separate devices or user profiles for poker and for general browsing.
- Treat unexpected software behavior, unusual lag, or unexplained system changes as a reason to investigate.
- Prefer tools that are explicitly permitted by the poker site's terms of service.
None of these steps is a guarantee. They are risk-reduction measures, not immunity.
What Happens Next
The key open questions are technical and procedural: how the update mechanism was compromised, how many accounts were actually affected, and whether any poker site or regulator will conduct a formal review. Until those questions are answered, the appropriate posture is caution rather than conclusion.
For the high-stakes community, the immediate effect is likely to be renewed scrutiny of third-party software and a push for stronger verification of the tools players install. For the wider poker public, the case is a reminder that in online poker, security is not only about the site's servers — it also extends to every program running on a player's own computer.
FAQ
- Superusing is a form of cheating in which a player gains access to opponents' hole cards, typically through a compromised device, shared screen, or colluding account, allowing near-perfect decision-making.