One of the Biggest Online Poker Scams? Attacker Allegedly Saw Opponents' Hole Cards for Months

Article cover

If these allegations are confirmed, it would mark one of the most sophisticated scams in online poker history. The attacker wouldn't need to breach the security of the poker site itself. They only needed to install malicious or compromised software on a player's computer to view exactly what that player saw on their screen. The initial public information came from an anonymous security researcher operating under the name "WolfSec0x0" on the X network. According to their findings, a tool called Mesh Agent was installed on the devices of several professionals, allowing remote management of the computer.

Although a legitimate software, the accusations claim it was installed without the players' knowledge and connected to a server controlled by the attacker. Names of specific players, suspicious accounts, and results from high-stakes cash games started to surface. Canadian player Paul Gregg became a focal point in the community investigation, with several sources linking him to accounts on GGPoker, CoinPoker, and Winning Poker Network.

All current information stems mainly from security analysis, community investigation, and publicly available game data. There is no complete forensic report or official statement to definitively confirm the full extent of the scam, the number of affected players, or the total financial loss. However, what has been revealed suggests this isn't about the usual use of banned solvers or RTA. If someone truly accessed opponents' screens, they could see hole cards in real-time and selectively target players whose devices were compromised.

The Attack May Have Started as Early as March 2024

The security researcher known as “WolfSec0x0” reported that the Mesh Agent tool, part of a legitimate open-source platform called MeshCentral, was installed secretly on players' computers. According to their investigation, the first known activity appeared on March 16, 2024, and the compromised software could have remained on some computers for several months, possibly over a year. The current estimate suggests about 10 to 30 affected players in Europe, North America, and Oceania. This was not a virus created specifically for poker.

MeshCentral is a legitimate tool for remote management. But if someone installs its agent secretly and connects to their own server, they can gain nearly full remote access to the computer. In the case of the compromised poker players, this meant the ability to view the screen in real-time, thus seeing even the hole cards during play. The attacker potentially had access to files, stored passwords, session cookies, payment details, and cryptocurrency wallets.

Paul Gregg Became the Focus of the Investigation

A significant development is the identification of accounts linked to Paul Gregg by the high-stakes community.

According to information released by Aleksey “Avr0ra” Borovkov and further reported by PokerListings and other media, Gregg is associated with the following accounts:

  • GGPoker: Paul Gregg

  • CoinPoker: Europe

  • Winning Poker Network: JackKlompus

  • Winning Poker Network: OxOO

  • Winning Poker Network: Ez[Pz]

These connections currently arise from community investigations and released data and cannot be regarded as the final result of an official investigation. The focus was mainly on the exceptionally strong results of some of these accounts. According to SmartHand data, quoted by PokerListings, the OxOO and JackKlompus accounts achieved a combined profit exceeding $837,000. The accounts repeatedly appeared among the most profitable players in high-stakes cash games.

For example, in May 2026, Paul Gregg was reportedly the most profitable player at NL2K with a profit of around $55,000. StatName listed JackKlompus with approximately $232,000 for the year 2025, and OxOO with $162,000. This by itself is not evidence of cheating. More important were the patterns discovered during a detailed analysis of games.

More Than 90% of Hands Against Certain Opponents?

High-stakes players began to examine who the suspicious accounts played against most frequently and from whom they gained the most money, based on disclosed information. The result was an extraordinarily peculiar pattern. In some accounts, more than 90% of played hands were concentrated against a specific group of players. Some of these opponents later found the Mesh Agent on their computers.

If this connection is definitively confirmed, it would explain how the alleged cheating could have gone undetected by poker sites for so long. The suspect didn't need to see all players' cards at the table. They only had an advantage against opponents whose computers were compromised. Against others, they could play normally. This model also allowed them to target specific victims—classic “bumhunting,” but with the knowledge that against the chosen opponent, the attacker could potentially see their hole cards.

Gregg Was Suspicious for Several Months

According to Poker-Red, Russian high-stakes player Gleb “psyhoagromor” Kovtunov stated that he privately discussed his doubts about Paul Gregg's play since April. Some decisions, sizings, and lines seemed too perfectly tailored to the specific strength of the opponent's hand. About a month before the public outbreak of the scandal, he reportedly passed his suspicion to a group of high-stakes players focused on combating RTA and other cheating forms.

According to his account, Gregg stopped appearing at the tables roughly two days later. Kovtunov later claimed that Mesh Agent was also found on his own computer. Another player confirmed the presence of the program and indicated that Gregg was the player who won the most money from him on GGPoker. However, these statements are still part of the community investigation and have not yet been comprehensively confirmed with an independent forensic report.

CoinPoker May Have Blocked Him About Two Years Ago

Another intriguing detail surfaced in the controversy. Patrick Leonard revealed that CoinPoker blocked an account registered under the name Paul Gregg, who used the nickname "Europe" on the site. This reportedly occurred about two years ago. According to Leonard's account, CoinPoker's security team detected activity considered a severe violation of rules, blocked the account, and confiscated approximately $100,000. These funds were later redistributed to affected players.

Leonard further claims that Gregg disputed the decision and appealed to the relevant gambling commission, but this complaint allegedly did not proceed further. This event is highly relevant because the nickname "Europe," linked with the former CoinPoker account by Leonard, also appears among current accounts under investigation. However, it is primarily Leonard's public statement and secondary sources. CoinPoker has yet to provide complete public documentation clarifying all circumstances of the case.

Confirmation of Third-Party Poker Software Compromises

The initial version of the case left the crucial question open: How did Mesh Agent make its way onto players' computers? New information has since emerged on this front. WolfSec claims that the remote agent was distributed via compromised third-party poker software. According to their analysis, at least two tools were used. The manufacturer confirmed the compromise for one, while security researchers identified a modified version through code analysis for the other.

PokerStrategy reported that IntuitiveTables, a tool mainly used for organizing poker tables, publicly confirmed it was among the compromised applications. This does not automatically mean IntuitiveTables was the only infection route. One affected player claims never to have used this program, yet Mesh Agent was found on their computer. Investigators do not rule out multiple distribution methods, including other compromised poker software, phishing emails, fake pages, or individually targeted attacks.

Poker Platforms Themselves Likely Unbreached

This remains one of the key differences from historical superuser scandals like Absolute Poker and UltimateBet. There is currently no evidence that attackers gained "god mode" directly in the poker site's systems. According to WolfSec, the poker clients themselves were not compromised. The attacker was gathering information directly from the opponent's computer.

For the player, however, the result is almost identical: an adversary can see their cards before making decisions. WolfSec explicitly stated that platforms like GGPoker and ClubWPT Gold were not sources of compromised code. Early community reports suggested that the victims could collectively have lost several million dollars. However, such a figure has not been confirmed.

Aleksey Borovkov spoke of losses in the millions across various sites, but there is no publicly available complete breakdown to definitively prove these figures. Extensive evidence currently involves hundreds of thousands of dollars recorded for accounts under investigation. The OxOO and JackKlompus accounts displayed more than $837,000 combined profit according to published data. It cannot be automatically assumed that all these winnings were the result of cheating.

Another alarming finding is the behavior of the remote agent after suspicions began circulating among players. According to PokerStrategy, WolfSec noted cases where someone remotely connected to a compromised computer and uninstalled Mesh Agent or removed used scripts. This means additional players might have been compromised without the program still being present on their computers today. However, Windows may retain certain traces of its previous installation.

What Should Online Players Do?

New information makes a security check particularly urgent for players who have been using Windows and various third-party poker tools in recent years. WolfSec advises checking for the presence of the Mesh Agent service, MeshCentral records, and unusual exceptions in Windows Defender. However, the presence of MeshCentral alone does not automatically indicate an infection. The software is legitimately used in corporate and IT environments. If a user is unaware of any legitimate reason for its presence, they should consider it a potential security risk.

If there is a suspicion of device compromise, recommendations include:

  • disconnecting the computer from the internet,

  • not removing potential evidence before securing it,

  • changing email passwords from another secure device,

  • subsequently changing passwords to poker sites, cryptocurrency exchanges, and other accounts,

  • signing out of all active sessions,

  • enabling two-factor authentication,

  • contacting poker sites and relevant authorities,

  • and performing a thorough clean system reinstall after securing necessary evidence.

 

WolfSec cautions that simply removing the Mesh Agent may not be sufficient. If the attacker had full access to the system for an extended period, it's uncertain what other alterations were made to the device. Players should also avoid downloading random “detectors” or repair programs distributed via Telegram, forums, or private messages.

More of an Organized Cyber Attack Than a Classic Superuser

With each new piece of information, the case begins to resemble less of a classic poker superuser scandal and more of a targeted cyber operation against high-stakes players. Attackers potentially had to identify lucrative victims, get malicious code onto their computers, maintain remote access, find out when and where they played, and subsequently infiltrate their tables. Some sources are considering the possibility that the operation wasn't the work of a single person. However, the existence of an organized group hasn't been definitively proven yet.

Compared to the initial hours after the case's disclosure, there is now significantly more concrete information. We know the first suspicious accounts, there are public database results, several players claim to have found Mesh Agent on their computers, and security analysis already links remote agent distribution with compromised third-party poker software. However, still missing is a fundamental element—a complete public forensic report and the results of investigations by individual poker sites.

It's not definitively known how many players were affected, the overall financial damage, which accounts were truly controlled by the same person or group, and who exactly was behind the entire operation. If the already published technical findings are combined with evidence linking remote access to specific poker accounts and financial results, online poker could be facing one of the most significant cheating scandals in recent years.

 

Sources: PokerNews, original thread on X, Two Plus Two, Pastebin.com, Poker-Red, PokerListings, GipsyTeam