Understanding the Fraud
If you read our initial article on this case, then you're aware of one of the biggest scandals in online poker history, where the attacker could see uncovered cards of opponents on high-stakes tables for months in real-time.
The scam didn’t involve hacking poker sites directly; instead, the attacker discreetly installed a legitimate remote screen management tool (Mesh Agent) on the victims' computers. This allowed complete oversight of selected professionals' cards, robbing them of hundreds of thousands to millions of dollars.
Confirmed Source of Infection
The crucial development is the precise identification of how the Mesh Agent software infiltrated victims' computers. Developers of the popular multi-tabling management tool, Jurojin Poker, officially confirmed that the attacker gained access to their server keys and admin panel account.
Between June 2025 and June 2026, the attacker could include selected high-stakes players in special update groups. When these players launched Jurojin, they downloaded an altered update package. It contained a fake executable file that secretly installed Mesh Agent in the background before running the legitimate, digitally signed Jurojin application. Players suspected nothing since the software functioned normally.
Jurojin also admitted a significant limitation in reconstructing the infection. Their database backups recorded group compositions only at certain intervals. If the attacker added and removed a player from the group quickly, no log record remained.
We have made a new page with a more technical explanation of how the attack worked for everyone to see: https://t.co/Qmgs5s9cb7
— Jurojin Poker (@JurojinPoker) October 2, 2026
Victims' Statements
Testimonies from affected professionals reveal the devastating impact on their bankrolls. Spanish high-stakes pro Nacho Morón described a session where the account “Europe” (linked to suspect Paul Gregg) took $60,000 from him in a heads-up match within 15 minutes.
Morón estimates total losses between $100,000 and $200,000. He also highlighted a crucial point: “This person didn’t attack blindly. He not only saw the cards but played poker really well, which is why it took so long to uncover.”
Manuel Saavedra had spyware on his computer for over a year, documenting $59,275 in losses on GGPoker against Gregg's account and a further €43,176 on ACR Poker. Saavedra described how the attacker would open heads-up tables for him and use his card information as “extra blockers” against unaware players at the table.
Ignored Numbers by GGPoker
A key piece of the puzzle is an analysis compiled on September 1, 2026, by Mobius Poker founder Patrick Howard, after his friend nearly quit poker due to huge losses against Gregg. Howard reviewed 32,780 hands of Paul Gregg on GGPoker and sent a report to the site's management.
Gregg's overall win rate of +13.9 bb/100 on 10/20 6-max tables was highlighted. The probability of an average player achieving this purely by variance was 1 in 35,100.
While in small pots (up to 40 bb) Gregg lost -802 bb, in pots over 150 bb he earned a staggering +2,497 bb, winning at showdown 74.3% of the time.
In pots over 40 bb, he executed 153 aggressive actions on the river, reaching showdown 78 times and winning 59 of them (75.6% win rate), markedly exceeding the average win rate of other regulars (58.2%). When calling river bets, he won 52 out of 81 times (64.2% vs. an average of 48.6%).
GGPoker ignored this warning report for an entire month, contacting Patrick Howard only on the evening of October 2, after Spanish magazine Poker Red published an article about the ignored report, which spread across the X network.
Quick clarification on the Poker-Red article: the report was a database review I did in early September, flagging anomalies for GG to keep monitoring, not an accusation. GG reached out to me today. The investigation is led by @wolfsec0x0 with help from affected players. His… https://t.co/dkt1XActXB
— Mobius Poker (@mobiuspoker) October 2, 2026
Platform Responses
The case clearly highlighted differences in responses from various poker platforms. While other sites let suspicious accounts play for months or even years, CoinPoker detected and banned the account “Europe” (registered directly to Paul Gregg) after just one week.
Renowned professional and site ambassador Patrick Leonard revealed that CoinPoker immediately blocked the account, seizing over $100,000 and redistributing it to affected players. Nacho Morón confirmed, stating that the site returned $60,000 he lost in a heads-up match against Gregg.
Gregg even appealed to the regulator, but after CoinPoker presented evidence, he dropped the dispute. Leonard admitted that at the time, no one knew it was a larger issue involving Jurojin, which he himself used.
In response to the issue, ACR Poker quickly introduced a solution. CEO Phil Nagy unveiled the new Screen Shield feature, which blocks any screen capture or sharing tools while the poker client is running. The site also sent hand histories for analysis and promised compensation to affected players.
🚨 WPN Security Update : Screen Shield
— ACR Poker (@ACR_POKER) October 2, 2026
Join @WPN_CEO Phil Nagy LIVE on Kick streaming High Stakes on ACR Poker!👇https://t.co/qd4uoX57cK
🔴 LIVE NOW #acrpoker https://t.co/LanmZpWpPs pic.twitter.com/zyhoW8Y1mO
However, each site reacts independently, and a lack of communication between them is evident. Both Nacho Morón and Patrick Leonard strongly criticized poker sites for not sharing information about banned cheaters.
Morón compared the situation to casinos in Las Vegas: “If you're caught cheating in one Las Vegas casino, all others will have your picture in minutes and won’t admit you. Poker sites must learn to communicate.”
What Players Should Do Right Now
This scandal raises critical security questions regarding support software. Even though Jurojin’s developers assured that malicious code was removed from their updates, security experts and Jurojin themselves strongly urge all players to perform a thorough check for the presence of Mesh Agent.
If there's any doubt, don't just delete the program—perform a complete Windows system reinstall and disk formatting. Additionally, change passwords to gaming sites, emails, and crypto wallets from another uncompromised device.
Sources: Poker-Red, X, YouTube