To Top

Super User Scandal Rocks Poker, Cheats High-Stakes Players Out of Millions

A hidden remote-access tool let a cheater see pros’ hole cards through IntuitiveTables and Jurojin. Here’s what we know about the poker scandal.
Fishing Pole Comes Out of Laptop Screen with Red Hole and Poker Chips Around
Photo by Shutterstock.com / ImageFlow
Blaise Bourgeois Avatar
4 mins read
Share Share
Copy link Share on X Share on Facebook Share on Reddit Share via Email

Last week, a cybersecurity researcher who goes by @wolfsec0x0 on X, formerly Twitter, published an in-depth report revealing an active superuser scandal.

The anonymous researcher stunned the online poker world with the following statement, which kicked off a thread of about 20 posts.

Poker tools turned into spy software

The hacker exploited a vulnerability in IntuitiveTables and Jurojin, two popular programs that players use to manage tables while multitabling.

The attacker secretly installed MeshCentral, a legitimate, free, open-source remote monitoring and management server, on the computers of high-stakes pros. It ran in the background and was installed through a security flaw in the IntuitiveTables and Jurojin software.

The tool let whoever controlled it watch a player’s screen and see their hole cards. In theory, it could also have allowed control of the computer and access to sensitive data.

Roughly 30 players were directly affected, with losses totaling millions of dollars, but it’s unclear how many were actually compromised. Online poker sites themselves were unaffected.

Many reports have linked the scheme to a mysterious user called “Paul Gregg.” CoinPoker said it identified Gregg as a user with the nickname “Europe” and banned the player within a week of his registration.

According to high-stakes player Mario Mosbock, the unregulated site confiscated $100,000 from the user and redistributed it to affected players.

On ACR Poker, the same user is believed to have played as JackKlompus, posting an impossible win rate of 24.3 big blinds per 100 hands and winning $402,700 over the course of 32,200 hands.

Another user named “pgs” on the Winning Poker Network had an even higher win rate of 32.7 big blinds per 100 hands over more than 25,000 hands. A user named “OcOO” is also suspected of being involved.

Jurojin says attack was highly targeted

Jurojin Poker, one of the two compromised products, released the following statement:

“This was a highly targeted operation, not a mass attack. It was carried out by a known cheater aiming at specific opponents, mostly at high stakes, with the goal of viewing their hole cards remotely. 

“Jurojin was one of several applications targeted by the same actor, including IntuitiveTables. The same actor also operated phishing sites impersonating poker rooms and well-known poker tools.”

Red flags ignored across online poker sites

Patrick Howard, also known as MobiusPoker, reported a suspicious user to GGPoker in September. The account turned out to be Gregg’s. Howard’s review showed that he was winning about 14 big blinds per 100 hands and winning more than 75% on river hands. GGPoker nonetheless allowed the account to keep operating. 

Howard clarified: “The report was a database review I did in early September, flagging anomalies for GG to keep monitoring, not an accusation. GG reached out to me today. The investigation is led by @wolfsec0x0 with help from affected players.”

ACR Poker’s Phil Nagy said their company is launching a full investigation and using GTO Wizard for analysis. ACR also introduced a security tool called Screen Shield, which blocks screen sharing and screen captures during play. Streamers cannot use the feature, however.

Patrick Leonard claimed that CoinPoker caught the player “around a year ago” and that high-stakes players had raised concerns with operators.

“A group of around 100 regs came together and told those sites starting a couple years ago what they suspected with very good details. He somehow was allowed to continue playing on those sites, winning and withdrawing at win rates that were likely not possible and showdowns that didn’t make sense.”

Leonard also said CoinPoker failed to warn other sites because sites because operators don’t cooperate on security. In his view, no site has an incentive to spend the money when they’re getting help elsewhere.

Ignacio Morón recalls losing $60,000 in minutes

In an interview with Poker-Red, Spanish pro Ignacio Morón said Gregg had swindled him. He recalled one session in which he played several heads-up tables against Gregg at the same time.

“I started playing heads-up with him and in a matter of 15 minutes he wiped out about $60,000 from me.

Morón estimates he lost $150,000 to $200,000 overall. He also estimates that Gregg likely took a combined $2.5 million in profit from the ACR Poker and GGPoker ecosystems.

“At the very least, way below that, it’s definitely $100,000, and that’s being conservative; it could possibly reach $150,000 or $200,000.

“He not only read your cards, but he also knew how to play poker. If you read people’s cards for two years, you don’t make that money, you destroy the community.”

Morón hopes the scandal will push operators to work together more closely on security, citing brick-and-mortar casinos as a model.

 “You go to Las Vegas and any casino catches someone cheating and all the casinos know it, they have the picture and you go into another casino and they kick you out too.

“Perhaps this is a lesson, that the rooms should have more communication between them.”

About the Author
VIEW ALL POSTS
Blaise Bourgeois

Contributor

Blaise Bourgeois is a professional poker player who enjoys working on both sides of the industry. Blaise is a writer, editor, commentator, on-camera talent, and sports researcher with over 10 years of experience across poker, iGaming, and sports media. Blaise has also worked as a research statistician for FOX’s FIFA World Cup coverage and for NBC’s Summer Olympic Games coverage three times, with his contributions recognized with a Sports Emmy in 2025.

VIEW ALL POSTS