Show summary Hide summary
Allegations that a third‑party software update was hijacked to give a player realtime access to opponents’ hole cards have sent shockwaves through online poker this week. The claim — if proven — would reopen wounds from the early 2000s and raise urgent questions about how sites and players verify the tools they use.
Investigators say the intrusion began with two widely used table‑management programs, Jurojin and IntuitiveTables. In both cases, an update apparently delivered a component called Mesh Agent, part of the open‑source MeshCentral project. Because Mesh Agent is legitimate software, it went under the radar of many antivirus systems. Once installed, it can stream a machine’s screen, accept remote mouse and keyboard input, and reveal everything shown on that computer — including hole cards.
Third‑party utilities are common among serious players. They help manage multiple tables, automate bet sizing and display statistics. That ubiquity is part of the problem: tens of thousands of grinders install these programs voluntarily, and most users do not subject them to formal security audits.
Free fall clothing and household items in Kankakee: Still I Rise hosts community giveaway
Online poker teeters after massive cheating scandal: industry and players hit hard
What investigators and players say happened
The individual named in multiple reports is a Canadian player identified as Paul Gregg. He is accused of exploiting the compromised updates while playing mid‑ and high‑stakes on sites including GGPoker, CoinPoker and the Winning Poker Network (including ACR). Gregg has not publicly commented and no criminal charges have been reported.

Data shared among players and analysts points to concentrated success that many describe as implausible without illicit information. One account linked to Gregg — known online as JackKlompus — reportedly collected roughly $402,700 over 32,200 hands on WPN, producing an extraordinary win rate measured in big blinds per 100 hands. Observers note that at those stakes a top pro might typically achieve a modest single‑digit win rate; the figures tied to this account are far beyond that range in several sessions.
There are also patterns suggesting attempts to mask the anomaly. In one brief run at micro stakes the same account lost enough, unusually quickly, to lower its long‑term average — a tactic some players say was used to make results appear less suspicious.
Past warnings, uneven responses
Some platforms were alerted long before the current public focus. CoinPoker, according to its own statements, flagged an account playing under the name “Europe” two years ago, banned it and redistributed more than $100,000 to the players who had been beaten. The platform says the banned player challenged the decision with a regulator and later withdrew the complaint.
Elsewhere, players and coaches say reports went unanswered. Coach Patrick Howard says he catalogued more than 32,000 hands after a teammate’s unexplained losses and submitted a detailed analysis to GGPoker; he says it produced no visible action. High‑stakes regulars describe repeated reports — in some cases “dozens” over a two‑year span — while the alleged accounts stayed active.
- Vector: Compromised updates for Jurojin and IntuitiveTables, swapping in Mesh Agent.
- Period reported: Investigators cite incidents between March 2024 and June 2026.
- Platforms involved: CoinPoker, GGPoker, and Winning Poker Network sites including ACR.
- Notable action: CoinPoker banned “Europe” and recovered six figures two years ago; other rooms received reports but appear to have taken limited steps.
- Status: Allegations under investigation; no public criminal charges reported and the named player has not responded publicly.
That sequence matters now because the economic context of online poker has changed. During the early 2000s “poker boom,” the market could absorb large, headline‑grabbing thefts without collapsing. Today the player pool is smaller and more competitive; recreational traffic and new money are not returning at the same rate. Confidence that operators and regulators are policing the games is therefore far more fragile.
For professional and recreational players alike, the immediate consequences are practical and reputational. Beyond direct losses, a sustained perception that rooms fail to detect or act on cheating could shift liquidity away from regulated platforms, push players toward less‑transparent venues, or intensify pressure for stronger external oversight.
Industry responses in the coming days will be telling. Platforms can harden update delivery, increase binary signing and auditing, and improve monitoring of anomalous win patterns. Regulators and criminal authorities may also take an interest if financial harm proves widespread. For now, the episode is a reminder that trust in the ecosystem — once eroded — can be difficult to restore.
Whether this scandal will match the scale and fallout of the UltimateBet case two decades ago remains to be seen. What is clear already: security gaps in third‑party software represent a systemic risk, and several high‑profile reports suggest those gaps went unaddressed for an extended period.











