Online Poker Screen-Hack Scandal

A security researcher alleges a remote-access tool let someone view high-stakes players' screens, including hole cards, for months. No official forensic report exists yet.
A Remote-Access Allegation, Not a Site Breach
The online poker community is examining allegations that an attacker, or a group of attackers, installed remote-management software on the computers of high-stakes players and used it to view their screens during play, including their hole cards. If confirmed, it would rank among the most sophisticated cheating schemes in online poker history.
The critical detail is where the compromise allegedly happened. The attacker did not need to breach a poker site's own security. They only needed malicious or compromised software running on a player's computer to see exactly what that player saw.
All current information comes from security analysis, community investigation, and publicly available game data. There is no complete forensic report and no official statement confirming the full scope, the number of affected players, or the total financial loss. Any figures below should be read as claims under investigation, not established facts.
How the Alleged Tool Worked
Public attention began with an anonymous security researcher posting as "WolfSec0x0" on X. According to that research, a tool called Mesh Agent was installed on the devices of several professionals, allowing remote management of those computers.
Mesh Agent is part of MeshCentral, a legitimate open-source platform for remote IT management. It is not malware written for poker. The allegation is that its agent was installed without players' knowledge and pointed at a server controlled by the attacker. In that configuration, a remote operator can gain near-full access to a machine: real-time screen viewing, files, stored passwords, session cookies, payment details, and cryptocurrency wallets.
The researcher reported that the first known activity appeared around March 16, 2024, and that the software could have remained on some computers for several months, possibly longer than a year. The current estimate is roughly 10 to 30 affected players across Europe, North America, and Oceania.
Because the tool is legitimate software, its mere presence is not proof of an attack. It is widely used in corporate and IT environments. The concern applies when a user has no legitimate reason for it to be there.
Accounts Under Scrutiny
Canadian player Paul Gregg became a focal point of the community investigation. High-stakes players, including Aleksey "Avr0ra" Borovkov, circulated links between Gregg and several accounts, later reported by PokerListings and other outlets:
- GGPoker: Paul Gregg
- CoinPoker: Europe
- Winning Poker Network: JackKlompus
- Winning Poker Network: OxOO
- Winning Poker Network: Ez[Pz]
These connections come from community investigation and released data. They are not the conclusion of an official investigation.
Attention focused on the accounts' unusually strong results. According to SmartHand data cited by PokerListings, the OxOO and JackKlompus accounts showed a combined profit exceeding $837,000. Published figures also list JackKlompus at roughly $232,000 for 2025 and OxOO at about $162,000, with one report placing Paul Gregg as the most profitable player at NL2K in May 2026 at around $55,000.
Strong results alone are not evidence of cheating. The more significant claims concern game-selection patterns.
The Pattern That Raised Flags
Analysts examined who the suspicious accounts played against most often and from whom they won the most. In some cases, more than 90% of played hands were concentrated against a specific group of opponents, and some of those opponents later reportedly found Mesh Agent on their computers.
If that link is confirmed, it would explain how the alleged scheme avoided detection for so long. The operator would not need to see every player's cards at a table. They would only hold an edge against opponents whose machines were compromised, and could play normally against everyone else. That model also allows deliberate targeting: a form of bumhunting combined with the ability to see the chosen opponent's hole cards.
Russian high-stakes player Gleb "psyhoagromor" Kovtunov reportedly said he had privately questioned Gregg's play since April, citing decisions, sizings, and lines that seemed too perfectly matched to the strength of an opponent's hand. He reportedly shared those doubts with a group of high-stakes players focused on fighting real-time assistance and other forms of cheating about a month before the story went public. According to that account, Gregg stopped appearing at the tables roughly two days later. Kovtunov later claimed Mesh Agent was also found on his own computer.
A Prior CoinPoker Block
Patrick Leonard said CoinPoker blocked an account registered under the name Paul Gregg, using the nickname "Europe" on the site, roughly two years ago. According to Leonard, CoinPoker's security team detected activity it considered a severe rules violation, blocked the account, and confiscated approximately $100,000, which was later redistributed to affected players. Leonard further claims Gregg disputed the decision with the relevant gambling commission, and that the complaint did not proceed further.
The detail matters because the nickname "Europe" also appears among the accounts currently under scrutiny. This remains primarily a public statement and secondary reporting; CoinPoker has not published complete documentation of the case.
How the Software Reportedly Spread
The open question was how Mesh Agent reached players' computers. WolfSec claims the remote agent was distributed through compromised third-party poker software, with at least two tools involved. One manufacturer confirmed a compromise; for the other, researchers identified a modified version through code analysis.
PokerStrategy reported that IntuitiveTables, a tool mainly used for organizing poker tables, publicly confirmed it was among the compromised applications. That does not mean it was the only infection route. One affected player claims never to have used the program, yet Mesh Agent was found on their machine. Investigators do not rule out multiple distribution methods, including other compromised poker software, phishing emails, fake pages, or individually targeted attacks.
Why This Differs From Past Superuser Scandals
This case differs from historical superuser scandals such as Absolute Poker and UltimateBet. There is currently no evidence that attackers gained privileged access inside a poker site's systems. According to WolfSec, the poker clients themselves were not compromised; information was gathered from the opponent's computer. WolfSec explicitly stated that platforms such as GGPoker and ClubWPT Gold were not sources of compromised code.
For the player, the practical result is nearly the same: an opponent can see their cards before acting.
Early community reports suggested victims could collectively have lost several million dollars. That figure has not been confirmed. Borovkov spoke of losses in the millions across various sites, but no public breakdown proves it. Documented evidence currently involves hundreds of thousands of dollars tied to accounts under investigation, and it cannot be assumed that all winnings were the product of cheating.
One further finding is troubling. According to PokerStrategy, WolfSec noted cases where someone connected remotely to a compromised computer and uninstalled Mesh Agent or removed used scripts. That means additional players may have been affected without the program still being present. Windows may retain traces of a previous installation.
What Players Can Do
For players who have used Windows and third-party poker tools in recent years, a security check is reasonable. WolfSec advises checking for the Mesh Agent service, MeshCentral records, and unusual Windows Defender exceptions. Again, MeshCentral alone does not indicate an infection; it is legitimately used in corporate IT. If a user cannot identify a legitimate reason for its presence, it should be treated as a potential risk.
If a device compromise is suspected, the standard steps apply: disconnect from the internet, preserve evidence, run reputable security scans, change passwords from a separate trusted device, and enable two-factor authentication. Players should also consider whether they reused passwords across poker accounts, email, and crypto wallets.
What Remains Unproven
Several core questions remain open. There is no independent forensic report confirming the full extent of the scheme, the exact number of victims, or the total losses. The account links rest on community investigation and published data. The CoinPoker episode rests largely on public statements. The distribution method is only partly confirmed.
What is clear is the structural lesson. When a player's own computer is compromised, no amount of site-side security can protect the cards on their screen. That is why the community response has focused on device hygiene and third-party software risk as much as on any single platform.
FAQ
- No evidence currently indicates that. According to the security research, the poker clients were not compromised. The alleged access came from remote-management software installed on players' own computers, which let an operator view their screens.