Canadian Pro Paul Gregg Accused of Superusing via Hacked Jurojin Poker Software

October 4, 2026
Canadian Pro Paul Gregg Accused of Superusing via Hacked Jurojin Poker Software

On September 29, 2026, a self-described cybersecurity professional posting on X as WolfSec0x0 warned online poker players that a covert remote-access agent had been planted on their Windows PCs through compromised poker software. The researcher put the number of affected users at roughly 30, spread across Europe, North America and Oceania. That first post named no one. Within days, as more information circulated in the high-stakes community, Canadian player Paul Gregg was identified as the alleged superuser, according to CardPlayer.

The accusation is serious. CardPlayer reports Gregg is alleged to have used access to opponents’ screens to see their hole cards during real-money play, costing victims hundreds of thousands of dollars. Gregg has not been charged with any crime, and the extract published by CardPlayer does not include a response from him.

What the remote-access tool could do

According to WolfSec0x0, the planted software let its operator watch an opponent’s screen in real time, take over the mouse and keyboard, run commands with full system privileges and move files to and from the infected machine. For a cheater at the tables, the screen feed alone was enough. Knowing an opponent’s holding on every hand allows near-perfect decisions and makes losing money over any meaningful sample extremely unlikely.

Jurojin confirms tampered updates

The alleged delivery route was third-party poker software rather than the poker clients themselves. CardPlayer reports the malware reached victims’ hard drives through Jurojin Poker, the table-management utility multi-tablers use to arrange tables and set bet-sizing hotkeys, along with other tools. Jurojin confirmed the breach in a statement released this week:

“This week, our investigation found that between June 2025 and June 2026, an attacker was able to intermittently replace the update package delivered to one specific group of Jurojin users with a tampered version. June 2026 was the last compromised month. Some of those packages included a remote-access tool.”

The company described the operation as highly targeted rather than a mass attack, carried out by what it called a known cheater going after specific opponents, mostly at high stakes. Jurojin said it was one of several applications hit by the same actor, naming IntuitiveTables as another, and that the attacker also ran phishing sites impersonating poker rooms and well-known poker tools. Jurojin did not name Gregg in the statement as quoted by CardPlayer. Its developers said they are working with the researcher to further secure their products.

A new route to an old scam

Superusing has a long history. CardPlayer points to Russ Hamilton, the 1994 WSOP Main Event champion, who used his consultant role and administrative access at Ultimate Bet to view opponents’ hole cards in high-stakes games. A few years later, a rogue Absolute Poker employee playing as “Potripper” used the same method. In 2013, Finnish pro Jens Kyllonen exposed a ring that broke into hotel rooms at European Poker Tour stops and installed a trojan on players’ laptops to view their screens. Mike Postle was later accused of superusing on the Stones Poker Live stream.

Each of those cases required an insider or physical access to a victim’s computer. This one did not. According to CardPlayer, it is the first known case of a player using third-party software to infiltrate opponents’ machines, which makes it far harder to detect. CardPlayer also credits CoinPoker as the first site to catch Gregg. Jurojin’s own timeline puts the exposure window at 12 months, ending with the last compromised update in June 2026.

https://x.com/wolfsec0x0/status/2104990197591249207