Last Updated on September 30, 2026 by Bala Kumar
Imagine sitting at a 200/400 table, three-betting with a hand you’d never show anyone, and somewhere else a stranger is watching your screen like it’s a livestream. No hidden camera. No crooked dealer. Just a quiet little program running on your own PC.
That is the scenario high-stakes regulars woke up to on 29 September 2026, when a security researcher on X claimed that around 30 players had been infected with a remote-access tool that let an attacker see their hole cards in real time. The headlines called it a “new superuser.” That label is catchy, but as you’ll see, it’s not quite right, and the difference matters a lot for how you protect yourself.
I’ve followed online poker security stories since the Absolute Poker days. Here’s what we actually know, what’s still rumour, and the practical steps worth taking tonight, whatever stakes you play.
Live Status Tracker (Last Checked: 30 September 2026)
The story is roughly 36 hours old. Here’s where every major claim stands right now, so you can separate what’s confirmed from what’s still chatter.
| Claim | Status | Source |
| A remote-access agent (“Mesh Agent”) was planted on players’ PCs via compromised poker software | Claimed by researcher; no independent confirmation yet | @wolfsec0x0 via PokerNews |
| About 30 high-stakes players affected across Europe, North America and Oceania | Researcher’s estimate; no list published | PokerNews |
| Activity dates back to 2024 | Claimed; timeline not independently verified | PokerNews |
| GGPoker and ClubWPT Gold not involved in the compromise | Stated by researcher | PokerNews |
| Current versions of the two affected tools are clean | Stated by researcher; vendors not named | PokerNews |
| 10+ regulars lost “several million dollars” at GG, ACR and CoinPoker tables | Unverified forum claim | CardsChat |
| Suspect played 90%+ of hands against infected players | Unverified forum claim | CardsChat |
| Official statement from GGPoker, ACR or CoinPoker | None found as of 30 Sept | Our search of news and operator channels |
| Refunds announced | None yet | — |
We’ll refresh this table as operators, the researcher or the software vendors respond.
What Happened: The Allegations So Far
The alarm came from an X account called @wolfsec0x0, which describes itself as a cybersecurity professional and poker enthusiast. According to PokerNews, the account had only about 230 followers before its thread spread across poker Twitter on Tuesday, 29 September.
The account isn’t a complete unknown, though. Back in March 2026, the same handle flagged security concerns at CoinPoker through responsible disclosure and later publicly praised the site’s response, as CardPlayer reported. That track record is one reason players took this thread seriously.
Here’s the claim in plain terms:
| Detail | What was claimed (29 Sept 2026) |
| Victims | About 30 players, all high-stakes, across Europe, North America and Oceania |
| Infection route | Compromised third-party poker software, not a poker site’s own client |
| The malware | A hidden Windows service named “Mesh Agent” running with system-level privileges |
| What the attacker could do | Watch the screen live (including hole cards), control mouse and keyboard, reach saved passwords, cookies and cards |
| Timeline | Activity said to date back to 2024 |
| Sites cleared | GGPoker and ClubWPT Gold named as “not involved” in the compromise |
| Current status | Researcher says no current version of either affected tool still serves malicious code; vendors not named because they are cooperating |
Forum chatter has gone further than the original thread. A CardsChat post claims more than ten regulars lost several million dollars combined at GG, ACR and CoinPoker tables, and that the suspected cheater played over 90% of his hands against infected players. None of that has been confirmed by any operator, and the named-software speculation on forums remains just that. As veteran poker journalist Todd Witteles pointed out, the problem appears to be a third-party tool, not the poker sites’ own software.
One detail worth untangling: “GGPoker isn’t involved” and “players lost money at GG tables” can both be true. If your PC is infected, the cheater can sit with you on any site. The site itself doesn’t need to be hacked.
Superuser vs. Remote-Access Trojan: Why the Label Matters
In poker slang, a superuser is someone with “God Mode”: the ability to see every player’s hole cards from inside the poker site’s own systems. It’s an inside job. The classic example is Absolute Poker and Ultimate Bet in 2007–2008, where insiders abused internal tools to view opponents’ cards.
What’s being described now is different. A remote-access trojan (RAT) doesn’t touch the poker site at all. It lives on your computer and shows the attacker exactly what you see. Think of it as someone looking over your shoulder, from another country.
That difference changes three things:
• Who’s exposed. A superuser hurts everyone at the table. A RAT only hurts the people who are infected, which is why the targets were a small, specific group of high-stakes regulars.
• Who can stop it. A site can shut down a superuser by fixing its own servers. A RAT can only be removed by you, on your machine, although sites can still catch the cheater through their play data.
• What else is at risk. A superuser sees cards. A RAT can also grab your saved passwords, session cookies and payment details, so the damage can reach far beyond the poker table.
Mesh Agent itself is worth a sentence of explanation. It’s the client side of MeshCentral, a legitimate open-source remote-management tool used by IT teams. Attackers like it for exactly that reason: it looks like normal software. Cybersecurity News documented a 2025 campaign where a malicious Mesh agent hid under a fake Microsoft Edge path and talked to its server over ordinary web ports, slipping past firewalls.
How This Compares to Poker’s Biggest Security Scandals
Poker has been here before, and the history is useful because it shows how these cases usually end. The pattern: statistical outliers get spotted by players first, operators confirm later, and refunds depend on who’s responsible.
| Year | Case | Type | Who caught it | Outcome |
| 2026 | Mesh Agent campaign (alleged) | Client-side RAT via compromised third-party tools | Security researcher + player win-rate analysis | Developing; ~30 players said to be affected; no operator statement yet |
| 2025 | GGMillion$ coaching and ghosting cases | Real-time assistance and account sharing | GGPoker security team | Two permanent bans; $346,903 and $115,752 returned to affected players (Casino Industry News) |
| 2015 | Odlanor trojan | Malware screenshotting PokerStars and Full Tilt tables, hidden in poker tools like Poker Office and Tournament Shark | ESET researchers | PokerStars said an initial review found no evidence of lost funds (PokerNews) |
| 2013 | Kyllönen hotel-room attack | RAT installed by USB on a pro’s laptop at EPT Barcelona | Victim noticed the laptop acting up; F-Secure analysed it | Same trojan found on his roommate’s laptop (The Register) |
| 2008–2014 | Peter Jepsen spyware | RAT installed on high-stakes rivals’ laptops, mostly at EPT stops | Danish police investigation | Three-year prison sentence on appeal (2020) and DKK 22.4M (over $3.6M) confiscated (VIP-Grinders) |
| 2008 | F-Secure “poker tool” case | Trojan hidden inside an odds tool that a regular opponent sent the victim | F-Secure | Early proof that trusted poker software is the easiest infection route (SpamFighter) |
| 2008–2009 | Ultimate Bet | Insider superuser (“God Mode”) | Players flagged “NioNio” results on forums | $1.5M fine, $22M in ordered refunds; total losses estimated above $50M (PokerNews) |
| 2007 | Absolute Poker / “POTRIPPER” | Insider superuser | Players decoded a leaked hand spreadsheet | $1.6M refunded, $500K regulatory fine (PokerNews) |
Two takeaways jump out. First, insider superuser scandals have essentially disappeared since regulated sites adopted independent audits and tighter internal access controls. Second, the threat has moved to the player’s own device, which is harder for operators to police and easier for attackers to scale.
The 2026 case looks like a scaled-up version of the 2008 and 2015 playbooks. Instead of breaking into hotel rooms one laptop at a time, the attacker allegedly poisoned software that high-stakes players already trusted and installed themselves. And the Jepsen conviction shows how these cases can end: in a criminal court, not just a site ban.
How Hole-Card Cheaters Get Caught
Here’s the reassuring part: seeing someone’s cards gives you a huge edge, but it also leaves fingerprints. Nobody plays perfectly by accident for 50,000 hands.
These are the red flags security teams and sharp regulars look for, explained without the jargon:
1. Who they play against. The CardsChat thread claims the suspect played over 90% of his hands against a specific group of regulars. Normal pros table-select weak players, not the same handful of strong ones.
2. Folding when behind, too often. Every winning player folds sometimes. A cheater folds strong hands at exactly the moments they happen to be beaten, far more than chance allows.
3. Never getting caught bluffing into a monster. Bluffs work only when the opponent is weak. A cheater’s bluffs land against weakness with suspicious reliability.
4. Bet sizing that ignores the board. Overbetting a scary board only when the opponent holds a hand that can’t fold is a classic tell. One such hand proves nothing; hundreds of them build a case.
5. Win rates that don’t fit. A player jumping from break-even to an elite win rate overnight, only against certain opponents, gets flagged.
What’s worth stressing for beginners: one weird hand is not evidence. Plenty of legitimate players make strange calls and odd sizings. It’s the pattern across thousands of hands that exposes a cheater. That’s also why the victims here are high-stakes players. Big pots make the scheme profitable, and a small pool of regulars makes the pattern show up quickly.
How to Check Your PC and Protect Yourself
You don’t need to play 200/400 to take this seriously. The same tricks work at any stake, and a RAT that steals your email password is a problem even if you only play freerolls.
Check for Mesh Agent right now (Windows, five minutes):
1. Press Win + R, type services.msc and press Enter. Sort by name and look for anything called “Mesh Agent” or a service you don’t recognise with a vague description.
2. Open Task Manager (Ctrl + Shift + Esc), go to the Details tab and look for MeshAgent.exe, or a familiar name like msedge.exe running from an unusual folder. Right-click any suspicious process and choose “Open file location.”
3. In File Explorer, turn on “Show hidden items” and check C:\Program Files and C:\ProgramData for a Mesh folder you didn’t install.
4. If you find something, disconnect from the internet first, then contact a security professional. Don’t just delete it; you want evidence for the poker sites and a clean wipe.
Habits that cut your risk long-term:
• Treat third-party poker tools like banking apps. HUDs, trackers and table managers need deep access to your system. Download only from the official developer site, keep them updated, and drop tools whose developer goes quiet.
• Use a dedicated poker machine if you play serious stakes. No email, no random downloads, no browser logins. It’s the single biggest upgrade a high-stakes player can make.
• Stop saving passwords in your browser. Use a proper password manager and turn on two-factor authentication for every poker account, email and crypto wallet.
• Watch for phishing. The forum reports say the malware may have spread by email too. “Updated version” links sent to you are a red flag; get updates from inside the app or the official site.
• Save your hand histories. If you’re ever cheated, your own database is the evidence that gets refunds approved.
If you think you’ve played against a cheater, report it to the site’s security team with hand numbers. Operators like GGPoker, ACR and CoinPoker have all investigated security complaints before, and they have far more data than any single player.
Our Take: Is Online Poker Still Safe?
For most players, yes, with a big asterisk. Nothing reported so far suggests that GGPoker, ACR, CoinPoker or any other site had its servers breached or its shuffle compromised. The weak point was the player’s own computer, reached through tools that serious players install as a matter of routine.
That should shift how the poker world talks about security. For twenty years the fear was the crooked insider with God Mode. In 2026 the realistic threat is a poisoned download on a pro’s gaming rig. Sites can still help by catching the cheater’s betting patterns and freezing funds fast, but players have to own the other half of the job.
The timing makes it worse. Just two weeks earlier, on 17 September 2026, a Range Advantage report showed real-time assistance tools being promoted in public, and asked why operators were slow to respond. Integrity is already the top concern among serious online players this year. The operators that respond fastest and most openly to this case, as GGPoker did with its 2025 GGMillion$ refunds, will earn the most trust.
We’ll be watching for three things next: whether the researcher publishes evidence and a list of affected accounts, whether the two unnamed software vendors confirm the breach, and whether any operator announces refunds. We’ll update this article as those answers arrive.

Founder of PokerClubGames.com and a Poker Researcher with 10+ years of experience in SEO, WordPress development, and gaming content strategy. Specializes in researching online poker sites, poker apps, tournaments, bonuses, and poker strategies. Experienced in poker platform reviews, affiliate marketing, and creating SEO-focused poker content for global audiences.
For collaborations, media inquiries, or poker-related partnerships:
Contact: Info@hugecount.com


