Paul Gregg Superuser Scandal: Poker Sites Were Warned Before the Damage Was Done

Last Updated on October 3, 2026 by Bala Kumar

The warning signs were there

The online poker superuser scandal has taken a sharper turn. New reports say at least two poker sites were told about a suspicious account called “Paul Gregg” well before the full story broke. One site acted fast. The other is only now investigating.

For the players who sat across from this account, the gap between warning and action may have cost them six figures. That raises a hard question for the whole industry: when players raise the alarm, how quickly do poker rooms listen?

Latest updates (as of 3 October 2026)

Public estimates now put the alleged scheme’s profits at around $1 million, with one outlet citing up to $2 million across two years. Here is what has emerged this week:

•           The malware has a name. The remote-access tool is reported to be MeshAgent, a legitimate open-source remote-maintenance program allegedly installed on victims’ PCs without their knowledge. On 29 September, WolfSec0x0 confirmed it was planted through compromised poker software, affecting about 30 users across Europe, North America and Oceania.

•           The site that acted early is CoinPoker. It banned the account “Europe”, confiscated about $100,000 and returned the money to affected players.

•           A suspicious pattern gave it away. Players found the account played about 90% of its hands against a small group of regulars it kept beating.

•           Victims spoke up months ago. High-stakes pro Gleb “psyhoagromor” Kovtunov said he had been privately accusing the account of cheating since April.

•           Most of the money came from WPN. Reports estimate the alleged cheater took more than $800,000 out of high-stakes games on ACR/WPN.

Screen names linked to the account

These links come from community investigations, led by high-stakes regular Aleksey “Avr0ra” Borovkov. They are not the result of an official ruling.

Screen nameSiteReported results
Paul GreggGGPokerTop NL2K winner in May 2026 (55K);5thinAugust2026(21K)
JackKlompusWPN (ACR)Top-three overall cash winner of 2025 ($232K); $113K at NL/PL5K in 2024
OxOOWPN (ACR)Top-seven overall in 2025 ($162K); $44K in January, $28K in April and $24K in June 2026 at NL5K
Ez[Pz]WPN (ACR)$25K in August 2026
EuropeCoinPokerBanned; about $100K confiscated and refunded

Combined, JackKlompus and OxOO show more than $837,000 in tracked profit. Those are recorded winnings, not a confirmed amount gained by cheating.

GGPoker is investigating but had not published a public statement on the case at the time of writing.

What is the superuser scandal?

In poker, a “superuser” is a player who can see information others cannot, usually their opponents’ hole cards. This case did not involve a rogue site insider. Instead, attackers allegedly broke into third-party poker software that players run alongside their tables.

The story went public after cybersecurity researcher @wolfsec0x0 posted findings on X. According to that research:

•           The operation may have run for about two years.

•           Roughly 30 high-stakes players were reportedly targeted.

•           The attacker gained remote access to victims’ screens, which exposed their hole cards in real time.

With that view, an opponent knows exactly when to bet, bluff or fold. Over hundreds of hands, the edge becomes enormous.

Who is “Paul Gregg”?

Paul Gregg is the screen name at the centre of the allegations. Nobody has officially confirmed who is behind it. What is known comes from the players who faced it.

Spanish outlet Poker Red spoke with Spanish pro Ignacio Moron, one of the alleged victims. Moron believes his total losses to the account sit somewhere between $100,000 and $200,000. In one session alone, he says, about $60,000 disappeared in roughly 15 minutes.

Moron’s numbers show the scale of the problem. If one player lost that much, the combined damage across dozens of targets could be far larger.

Two sites, two very different responses

The report sent to GGPoker

Poker coach Patrick Howard of Mobius Poker reportedly filed a report with GGPoker in September flagging odd behaviour from the Paul Gregg account. Howard was careful not to call it cheating outright. He simply asked the site to look closer.

Howard has since said publicly that this scandal could permanently change online poker. He also shared on X that GGPoker has now contacted him about its investigation.

The site that acted early

A second site, the unregulated room CoinPoker, spotted the account much sooner. High-stakes pro Mario Mosböck, an ambassador for that site, confirmed its security team flagged the account, seized $100,000 and banned it. Affected players were refunded.

Fellow ambassador Patrick Leonard added detail on X. He said the account was caught after less than a week of play. The team did not know the exact method, but the account clearly had information other players lacked.

Leonard also claimed that around 100 players had raised concerns about the account with various sites years earlier. Despite this, he said, it kept playing and cashing out at win rates that looked impossible. In his view, the future of online poker depends on how seriously sites chase down bots and accounts like this one.

Note: reports differ on timing. Some coverage says the early detection happened more than two years ago, while Leonard put it at about one year ago.

The software behind the breach

Two poker tools have been named as compromised: Jurojin and IntuitiveTables. Jurojin released a statement explaining what happened and the steps it is taking to stop a repeat.

According to Jurojin, this was not a broad hack of its user base. It describes a focused campaign by a known cheater who went after specific opponents, mostly at high stakes, to view their cards remotely. Jurojin says it was one of several apps the same person targeted.

The statement adds another warning. The same actor allegedly ran phishing sites that copied the look of real poker rooms and popular poker tools. Any player who downloaded software from an unofficial link should treat their device as potentially at risk.

Poker has been here before

Superuser cheating is not new. The most infamous case belongs to Russ Hamilton, a former World Series of Poker Main Event champion. In the late 2000s, his “POTRIPPER” account was used to see opponents’ cards on Ultimate Bet and Absolute Poker, costing players millions of dollars.

The key difference is the route in. Hamilton’s scandal came from inside the poker rooms’ own systems. The Paul Gregg case allegedly came through outside tools on players’ own computers. That means even a perfectly secure poker site can be exposed if the software around it is weak.

How to protect yourself at the online tables

You cannot control what a site does, but you can reduce your own risk:

1.         Download tools only from official sources. Type the developer’s address yourself rather than clicking links in emails, ads or chat messages.

2.         Keep every poker tool updated. Security fixes usually arrive in updates, especially after a breach like this one.

3.         Review remote-access permissions. Check which apps can view or share your screen, and remove any you do not recognise.

4.         Turn on two-factor authentication for your poker accounts and the email linked to them.

5.         Check Task Manager for a process called MeshAgent and run a trusted security scan if you use Jurojin, IntuitiveTables or any tool from an unofficial link.

6.         Report odd play with evidence. Hand histories, timestamps and specific hands make a report much harder to ignore.

7.         Watch for impossible results. An opponent who folds strong hands at the perfect moment, again and again, deserves a closer look.

What this means for online poker

The Paul Gregg case shows that warnings alone are not enough. One site reacted within days, recovered funds and refunded players. Elsewhere, reports suggest complaints sat for far longer while the account kept winning.

It is still unclear how many sites the account played on or how much was taken in total. Investigations are ongoing, and more details are likely to emerge.

Trust is the real currency in online poker. Players need to know that when they spot something wrong, someone will act. How sites respond in the coming weeks may decide how much of that trust survives.

Sources

•           PokerNews: Poker Sites Were Warned About Suspicious Account

•           PokerNews: Superuser Targets Online Poker Players

•           PokerNews: Online Poker Scandal Statement Released

•           Poker Red: Nacho Moron on Paul Gregg

•           Poker Red: GGPoker and Patrick Howard’s report

•           PokerListings: Paul Gregg screen names and results

•           PokerScout: CoinPoker banned the cheater early

•           PokerExclusive: MeshAgent trojan fraud

•           GipsyTeam: Malware used against high rollers

•           Funfarm: Scammers earned about $2 million

FAQs

1. What is the Paul Gregg poker scandal?

The Paul Gregg scandal involves allegations that an online poker account used compromised third-party software to view opponents’ hole cards and gain an unfair advantage in high-stakes games.

2. How did the Paul Gregg superuser allegedly see opponents’ cards?

Reports say attackers used malware, reportedly identified as MeshAgent, to gain remote access to players’ computers through compromised poker software, including Jurojin and IntuitiveTables.

3. Which poker sites were linked to the Paul Gregg scandal?

The reported accounts were associated with GGPoker, WPN (ACR) and CoinPoker. CoinPoker banned the account named Europe, while GGPoker’s investigation was ongoing as of October 3, 2026.

4. How much money was allegedly stolen in the Paul Gregg scandal?

Reports estimate that the alleged operation generated around $1 million, with some outlets suggesting up to $2 million over approximately two years. These figures have not been officially confirmed.

5. How can online poker players protect themselves from superuser attacks?

Players should download poker tools only from official websites, install security updates, enable two-factor authentication, review remote-access permissions and report suspicious activity with hand histories and timestamps.

Leave a Reply

Your email address will not be published. Required fields are marked *

Poker Platform

Suprema Poker review covering its app features, games, ratings, updates, club-agent model, security, real-money risks, and India availability.

 
 

Bravo Poker Live review 2026: explore live poker games, waitlists, tournament clocks, features, ratings, and room coverage.

 
 
1Win Poker review 2026 covering bonuses, games, payments, mobile apps, licensing, and withdrawals.
Explore RedStar Poker’s $2,000 welcome bonus, up to 35% rakeback, iPoker games, traffic, software, and payment options in 2026.

Explore BetRivers Poker’s $1,000 bonus, low rake, multi-state games, app features, and payment options in 2026.

Explore BetMGM Poker’s $1,000 bonus, soft games, MGM Rewards, mobile app, tournaments, and payment options in 2026.