Paul Gregg Cheating Allegations Shake High-Stakes Poker
- online-poker
- cheating-scandal
- superuser
- high-stakes
- poker-security
- jurojin
Paul Gregg is at the center of cheating allegations involving alleged hole-card access, malware, and a compromised poker-tool supply chain.
High-stakes poker rocked by a new cheating scandal
High-stakes online poker has seen plenty of controversy over the years, but few stories cut as deeply as an allegation involving hole cards, remote access, and compromised poker software. Paul Gregg is now at the center of that storm, after the poker community began linking him to a cheating scheme that allegedly gave him a devastating informational edge.
This is not just another accusation about soft play or suspicious table dynamics. If the claims are accurate, the issue goes straight to the integrity of online poker itself. Once one player can see an opponent’s hidden cards, the game becomes fundamentally distorted, and every decision at the table changes shape.
For regulars battling at high stakes, the stakes are bigger than a single bankroll swing. The real question becomes whether the ecosystem can detect, contain, and reverse this kind of abuse quickly enough. That is why the reaction from poker rooms matters just as much as the accusation itself.
How the alleged superuser setup worked
The case gained traction after cybersecurity professional and poker fan WolfSec0x0 said he had confirmed a covert remote-access agent planted on players’ Windows PCs through compromised poker software. He estimated that around 30 users were affected across Europe, North America, and Oceania.
According to the claims, the attacker could:
- view the victim’s screen in real time;
- control the mouse and keyboard;
- run commands with full system privileges;
- copy files to and from the computer.
That kind of access is catastrophic in an online poker environment. If someone can simply watch an opponent’s screen, they do not need fancy exploits at the table. They can play near-perfect poker against that player because they already know what the opponent is holding.
In practical terms, that means a cheating operation can remain hidden for much longer than classic forms of fraud. The player still appears to be making normal decisions, but those decisions may be based on privileged information that no honest opponent could ever have.
Jurojin Poker, third-party tools, and the supply-chain risk
One of the most alarming parts of this story is that the alleged attack did not rely on direct access to a victim’s computer in the traditional sense. Instead, the malware reportedly entered through third-party poker software, including Jurojin Poker and other online poker tools.
Jurojin is widely used by online grinders because it makes multi-tabling easier. It helps players organize tables, use hotkeys, and automate simple workflow tasks that matter when you are playing many tables at once. For serious players, tools like this are part of the daily routine, much like studying with a poker school or reviewing hands away from the tables.
Jurojin later confirmed that its software had been compromised. The company said that between June 2025 and June 2026, an attacker was able to intermittently replace update packages delivered to one specific group of users with a tampered version. June 2026 was the last compromised month, and some of those packages included a remote-access tool.
The company also described the operation as highly targeted rather than mass-scale. According to its statement, the attacker was a known cheater targeting specific opponents, mostly at high stakes, with the goal of viewing hole cards remotely. Jurojin added that the same actor also targeted IntuitiveTables and ran phishing sites impersonating poker rooms and well-known poker tools.
That supply-chain element is what makes this case especially dangerous. Players often trust utility software because it is part of the broader poker workflow. When that trust is abused, the threat extends beyond one app and becomes an industry-wide security problem.
Why this is called superusing
In poker slang, seeing an opponent’s hole cards is often referred to as superusing. It is one of the most damaging forms of cheating because it removes the core uncertainty that makes poker a game of incomplete information.
Compared with collusion or marking cards, superusing is particularly toxic because it can make a single player look simply “better” rather than obviously dishonest. The cheater can avoid bad spots, extract extra value in profitable ones, and fold hands that would otherwise cost money. Over a long sample, that edge can be enormous.
Historically, superuser scandals often involved an inside source or direct access to a player’s machine. This case is different because the reported method used third-party software to infiltrate opponents’ computers. That makes detection much harder and gives the attacker a much cleaner cover story.
The history of superuser scandals in poker
The poker world has seen several famous cases that explain why this story hits so hard. Russ Hamilton is widely regarded as the original superuser. The 1994 WSOP Main Event champion worked as a consultant for Ultimate Bet and used his access to the site’s admin panel to view opponents’ hole cards in high-stakes games.
A similar scandal later hit Absolute Poker, where an employee using the screen name Potripper cheated players with the same method.
In 2013, Finnish pro Jens Kyllonen exposed a cheating ring during European Poker Tour stops. In that case, scammers broke into hotel rooms, accessed players’ laptops, and installed a trojan that gave them visibility into the screen.
More recently, Mike Postle was accused of superusing on the Stones Poker Live stream. The prevailing theory was that tournament director Justin Kuraitis, who also ran the stream, may have given Postle access to hidden information.
The common thread in all of these scandals is the same: once hidden information leaks, the game is no longer poker in the way players understand it. The difference here is the sophistication of the alleged delivery mechanism.
Industry response, frozen funds, and player trust
After the Gregg allegations spread, high-stakes regular and CoinPoker ambassador Patrick Leonard said his site was the first to act. In a series of posts, Leonard said CoinPoker realized something was wrong, confiscated more than $100,000 from Gregg’s account, and then redistributed the money to affected players.
Leonard also said Gregg had played on multiple sites and networks, including ACR and GGPoker, but that those operators had not yet taken similar action at the time of his comments.
For players, this is the part that matters most. When a cheating case breaks, speed is crucial. If a site can quickly identify suspicious behavior, freeze balances, cooperate with regulators, and return funds, it reinforces confidence in the platform. If it hesitates, players start wondering whether their own games are truly safe.
That concern goes beyond one account balance. It affects the willingness of serious players to deposit, multi-table, and grind long sessions across the ecosystem, whether they are using standard poker clubs or moving between different networks.
Expert analysis: what this means for poker strategy and security
This case is a reminder that modern poker security is now as important as preflop theory. A player can spend years mastering GTO, ICM, and exploitative adjustments, but all of that work is meaningless if the software layer is compromised.
There are several strategic and practical takeaways for players:
- Treat every poker utility as part of your security perimeter.
- Keep systems updated, but verify that updates come from legitimate channels.
- Use strong device security, unique passwords, and two-factor authentication.
- Be especially cautious if you play on multiple sites or run multiple tools at once.
For the industry, the lesson is even bigger. Operators and developers may need tighter verification of update packages, more aggressive anomaly detection, and better coordination when suspicious patterns appear across different platforms. A player who can move from one network to another without friction is one thing; a cheater who can do the same is a threat to the entire market.
This is also why people who work through a poker agent or manage action across multiple rooms should pay attention to security policies as closely as they do to rake and traffic. Trust is now a competitive advantage.
Final thoughts on the Paul Gregg case
Paul Gregg’s alleged involvement has become more than a single cheating accusation. It is a case study in how modern online poker threats evolve: from insider abuse to remote access, from direct hacks to supply-chain compromise, and from isolated incidents to platform-wide security concerns.
If the allegations hold up, this case will likely be remembered not only for the money involved but for the method used to gain an edge. For players, the message is clear: skill still matters, but so does the safety of the environment in which that skill is applied. For poker operators, the standard is even higher now — protect the software, protect the data, and protect the game.
FAQ
What is superusing in online poker?
Superusing is a cheating method where a player gains access to an opponent’s hole cards. It creates an enormous and unfair advantage because the cheater can make decisions with near-perfect information.
How was Paul Gregg allegedly able to see opponents’ hole cards?
The allegations say malware was planted through compromised third-party poker software, giving the attacker remote access to victims’ screens and computers. That would allow real-time viewing of hidden cards.
Why is Jurojin Poker mentioned in the scandal?
Jurojin said its update packages were compromised for a targeted group of users between June 2025 and June 2026. The company said some tampered packages included a remote-access tool.
What did CoinPoker reportedly do?
According to Patrick Leonard, CoinPoker froze more than $100,000 from Gregg’s account after spotting suspicious activity and then returned the money to affected players.
How can online poker players protect themselves from similar attacks?
Players should use trusted software, enable two-factor authentication, keep systems clean, and be cautious about installing third-party tools. Security hygiene is essential, especially at high stakes.