A Canadian online poker player is accused of accessing his opponents’ hole cards to cheat them out of hundreds of thousands of dollars.
A self-described cybersecurity professional and poker enthusiast, who goes by “WoflSecOxO” on X/Twitter, said he confirmed someone planted malware on poker players’ computers. The software gave the user access to his opponents’ screens and could see their hole cards.
⚠️ Online poker players: we’ve confirmed a covert remote-access agent planted on players’ Windows PCs through compromised poker software.
Current estimate: ~30 users affected, in several countries across Europe, North America and Oceania.
Details and checks below 🧵
— WolfSec0x0 (@wolfsec0x0) September 29, 2026
The initial tweet did not accuse or reveal the user. However, as more people released information regarding the situation, Paul Gregg was named as the superuser.
According to WolfSecOxO, Gregg could watch his opponents’ screen in real-time during real-money play, take control of the mouse and keyboard, run commands with full system privileges, and copy files to and from the computer.
Given the specific cheating, Gregg only needed to see his opponents’ screen. Then, he could play perfectly against them, making it virtually impossible to lose money.
Third-Party Software Confirms Cheating
Gregg got the malware on the victims’ computer through compromising third-party software. He used Jurojin Poker, and other online poker tools, to get his malware on hard drives.
Jurojin is an online poker tool that eases multi-tabling online poker. Players can organize tables more easily, and utilize other features like hotkeys to quickly make bets at pre-determined sizes.
Earlier this week, Jurojin confirmed its software was compromised and released a statement.
“This week, our investigation found that between June 2025 and June 2026, an attacker was able to intermittently replace the update package delivered to one specific group of Jurojin users with a tampered version. June 2026 was the last compromised month. Some of those packages included a remote-access tool,” Jurojin officials said.
“This was a highly targeted operation, not a mass attack. It was carried out by a known cheater aiming at specific opponents, mostly at high stakes, with the goal of viewing their hole cards remotely. Jurojin was one of several applications targeted by the same actor, including IntuitiveTables. The same actor also operated phishing sites impersonating poker rooms and well-known poker tools.”
Jurojin developers said they are working with “Wolf” to further secure their products.
New Tactic, Same Cheating Method
The common phrase for cheating through seeing opponents’ hole cards is called “superusing.” For obvious reasons, it’s the most effective form of cheating compared to other methods like marking cards or colluding.
Unlike previous superusing accusations, this is one of the most highly skilled ways of implementing the scam. In previous superusing iterations, it required either an inside source or access to the player’s actual computer.
Russ Hamilton was the original superuser. The 1994 World Series of Poker main event champion worked as a consultant for Ultimate Bet. He used his role and access to the site’s admin to see his opponents’ hole cards during high-stakes poker sessions.
A similar cheating scandal happened a few years later on Absolute Poker, where a rogue employee under the screen name ‘Potripper’ cheated players using the same method.
In 2013, Finnish poker pro Jens Kyllonen exposed a cheating scam at European Poker Tour stops. A group of scammers broke into hotel rooms to gain access to players’ laptops. Then, they would install a trojan virus that gave them access to their screen.
More recently, Mike Postle was accused to superusing on the Stones Poker Live stream. The prevailing theory was that tournament director Justin Kuraitis, who also ran the stream, gave Postle access to the stream.
However, this was the first time a player used third party software to infiltrate his opponents’ computer. As a result, it’s a much tougher scam to catch.
CoinPoker Was First To Catch Gregg
In the aftermath of the Gregg scandal, high-stakes regular and CoinPoker ambassador Patrick Leonard revealed that his site was the first to do anything about the accusation. In a series of tweets, Leonard said the site realized something was wrong and confiscated more than $100,000 from Gregg’s account.
Then, they distributed the money back to affected parties. Gregg also played on a variety of other sites and networks, including ACR and GGPoker, but neither of those sites took action yet.
Things are leaking so here goes. Deleted all ambiguous posts from the last few days and will do a summary here
– same player has played across basically all the sites
– coin caught him around 1 year ago after he had played less than a week on the site. ofc we didn’t know exactly what he was doing, but it was obvious he had more information than other players. We didn’t know he hacked Jurojin/intuitive tables, I’ve used Jurojin every single poker session since, if we knew that I wouldn’t have done that!!
– he made a case with regulators etc, of course we fully obliged because we are confident in our security team and our case.
– this process lasted a short while then we refunded all our players who were affected
He continued playing on the same sites that he was playing on before. A group of around 100 regs came together and told those sites starting a couple years ago what they suspected with very good details. He somehow was allowed to continue playing on those sites, winning and withdrawing at win rates that were likely not possible and showdowns that didn’t make sense.
The future of online poker is in the hands of the sites and how much they are willing to investigate and act on bots & standalone characters like this.
— Patrick Leonard 🫡 (@padspoker) October 2, 2026

