Dozens of high-stakes players may have fallen victim to attackers who gained remote access to their computers via Mesh Agent. The infection occurred through third-party poker software installed on the players' computers. The potential losses could amount to hundreds of thousands of dollars.
On September 29, 2026, the poker community uncovered a scheme that allowed attackers to see high-stakes players’ hole cards for years. Mesh Agent, a remote-access tool, was found on grinders’ computers, while accounts linked to the investigation showed hundreds of thousands of dollars in profits. Some suspected victims also reported losing large sums to these players.
Andrey "TylerRM" Streltsov was the first to warn the public. He reported that Mesh Agent had appeared on some players’ PCs without their knowledge and urged his followers to check their computers.
Later that day, cybersecurity specialist "WolfSec0x0" published a technical investigation. He found traces of Mesh Agent on approximately 30 computers and determined that additional files had been downloaded only to devices belonging to users whose screen names appeared on a precompiled list.
This suggested a targeted attack: the perpetrator selected specific players, gained access to their computers, and could see what was happening at the poker tables.
Later, the developers of Jurojin and IntuitiveTables confirmed that their products had been compromised. According to the investigation, Mesh Agent was installed on selected players’ computers through third-party poker software.
"WolfSec0x0" published a post warning players:
⚠️ Online poker players: we've confirmed a covert remote-access agent planted on players' Windows PCs through compromised poker software.
— WolfSec0x0 (@wolfsec0x0) September 29, 2026
Current estimate: ~30 users affected, in several countries across Europe, North America and Oceania.
Details and checks below 🧵
The researcher specifically emphasized that the issue involves players' computers, not a breach of poker room servers. Mesh Agent is not malicious software itself; it is a component of MeshCentral, a legitimate open-source solution for remote computer management.
The problem was that it was installed on players’ devices without their knowledge. This allowed the attacker to remotely access the computer and see what was happening on the screen, including players’ hole cards.
Key findings from "WolfSec0x0":
This also explains why a simple check of the Task Manager might not have shown anything: by the time the check was performed, the agent could have already been removed.
"WolfSec0x0 " found that the attackers used two popular table-selection tools. Following the publication of his investigation, the developers of Jurojin and IntuitiveTables confirmed that their applications had been compromised. Jurojin mentioned reviewing the researcher’s report and collaborating with him on the investigation:
Hi everyone! We're looking into the @wolfsec0x0 report in depth, working with him and sharing everything we find.
— Jurojin Poker (@JurojinPoker) September 30, 2026
For now, we don't wanna jump into conclusions, but we made a quick tool (signed) that checks whether your PC is affected. Download it here: https://t.co/vLvFUd1tRUhttps://t.co/du4KGjmJGz
Jurojin later clarified that from June 2025 to June 2026, the attacker periodically replaced update packages for a specific group of users. Some of the modified packages contained a remote-access tool. According to the company, the last compromised package was distributed in June 2026.
IntuitiveTables also confirmed that its software had been compromised and said that the current versions of the program don’t contain any malicious code.

Following the publication of "WolfSec0x0’s" investigation, one of the main names discussed was Canadian player Paul Gregg. He has been linked to the Paul Gregg account on GGPoker, Europe on CoinPoker, as well as JackKlompus, OxOO, and Ez[Pz] on the WPN network. According to SmartHand, JackKlompus and OxOO generated more than $837,000 in combined profit.
The investigation also noted that some of these accounts played an unusually large share of their hands against certain regulars. In some cases, more than 90% of their hands were played against specific groups of players, prompting further analysis of their activity.
Manuel Saavedra said the agent had been on his PC for more than a year and that he had lost around $60,000 to Gregg at GGPoker tables over the previous six months. Gleb Kovtunov also reported finding the agent on his computer and suffering significant losses to Gregg.
However, there is currently no direct evidence that Gregg installed Mesh Agent, controlled it, or used access to players’ hole cards.
Although the attack primarily targeted high-stakes players, anyone using poker software should check their computer. Mesh Agent could run as a system service and would not appear among standard running programs.
"WolfSec0x0" recommended performing a check using PowerShell. To do this:
If any of the checks detect Mesh Agent or unknown Windows Defender exclusions, it is better to save the results first and consult a cybersecurity specialist. Removing the software yourself could destroy important evidence that may help determine what happened on the computer.
The investigation should now shift from the detection of the Mesh Agent to an analysis of the attack's impact. Jurojin has preserved logs of all compromised versions and the users to whom they were distributed, and is prepared to hand this data over to law enforcement agencies and cybersecurity experts. The company has also already contacted the affected players directly.
The game histories will also need to be examined. "WolfSec0x0" urged poker rooms to investigate logins from unknown devices and the hand histories of affected players, particularly sessions against opponents who played against them unusually often. Such analysis could reveal whether remote access was used directly at the tables and how much damage it may have caused.
Meanwhile, the latest versions of Jurojin and IntuitiveTables no longer contain the malicious component, and Mesh Agent has been removed or disabled on all confirmed affected computers.
Poker rooms won’t stay on the sidelines either. For example, CoinPoker has already launched daily, detailed tracking of all high-stakes games at railbird.vip.
After GGPoker made its highest-stakes tables invite-only and required players to display their re...
A $500,000 prize pool heads-up NLHE tournament was held for famous streamers on ClubWPT Gold over...
Colorado was one of the first states to take sports betting online, yet it still doesn't license ...
On October 4, 2026, two flagship "The Venom" tournaments in the PKO format will kick off at ACR P...