A poker software hack has become one of the most serious integrity stories online poker has seen in years. According to a statement from Jurojin Poker, a third-party tool used by serious grinders had its update package intermittently swapped out by an attacker, and that attacker was then able to see the hole cards of roughly 30 high-stakes players. The poker sites themselves do not appear to have been breached. The weak link was the software players install on their own PCs to make multi-tabling easier.
For anyone who plays real-money poker online, this is a story worth reading closely, because the lessons apply far beyond the small group of high-stakes regulars who were targeted.
What Jurojin Has Confirmed
Jurojin's software combines table management, hotkey controls, bet sizing tools and real-time overlays. It is the kind of utility that sits next to your poker client all day, which is precisely why it is such an attractive target. In its public statement, the company said that between June 2025 and June 2026, with June 2026 the last compromised month, "an attacker was able to intermittently replace the update package delivered to one specific group of Jurojin users."
That wording matters. This was not a mass infection that hit every user of the tool. It was a selective operation aimed at a defined group, and the company says roughly 30 high-stakes players were targeted. Jurojin privately emailed the affected users rather than publishing a list.
The company also says a second tool, IntuitionTables, was compromised by the same actor, and that the same person ran phishing sites impersonating poker rooms and poker tools. In response, Jurojin says it has restricted configuration access, begun logging all downloads, required multi-factor authentication, and rotated its encryption keys. It also credited the security researcher who exposed the problem, who posts as @wolfsec0x0, as a partner in the clean-up.
How the Alleged Attack Worked
Separate reporting describes the payload as Mesh Agent, a legitimate remote-management tool that was reportedly installed as a Windows service without the victim's knowledge. In that configuration it can show a live view of the screen, which means a hand's hole cards, along with remote mouse and keyboard control and access to saved browser passwords, cookies and payment information.
Some of the figures in circulation are allegations rather than confirmed findings, and it is worth separating them. The researcher who raised the alarm estimated about 30 affected users in Europe, North America and Oceania. One outlet reported the first detected activity dating to March 16, 2024, which is earlier than the June 2025 window in Jurojin's own statement. Those two timelines have not been reconciled publicly, and readers should treat the longer one as unconfirmed.
The same report said profits on flagged accounts exceeded $837,000, that more than 90% of the hands played by suspicious accounts were concentrated against specific opponents, and that CoinPoker reportedly blocked one account and confiscated roughly $100,000, which was later redistributed to affected players. These details come from journalism and community investigation rather than a regulator's findings, so they may change as evidence is released.
No individual has been convicted of anything, and this article deliberately does not name anyone accused. The allegations have circulated widely in the poker community, but an accusation is not an adjudication, and the platforms involved have not published final conclusions.
Why This Is Different From a Typical Poker Scandal
Poker has a long history of cheating controversies: superuser accounts, collusion rings, real-time assistance software and ghosting. Most of them involve either an insider abusing access or players breaking rules at the table. This one is different in two important ways.
First, the cheating alleged here did not require beating any poker site's security. The attacker went after the client side, the player's own computer. Security specialist Todd Witteles noted that the compromised software involved third-party tools rather than the poker platforms' own software. Even a flawless site cannot protect a player whose operating system is quietly streaming their screen to someone else.
Second, the victims were chosen. A tool that reveals hole cards is only profitable if the cheater is in the same games as the victims, and the reported concentration of hands against specific opponents fits that pattern. It is a reminder that high-stakes regulars carry a different threat model from recreational players. They are known, they are findable, and the games they play are small enough that unusual results stand out.
How Platforms Detect This Kind of Cheating
If the reports are accurate, the way the problem surfaced is instructive. It was not a single suspicious hand. It was a statistical pattern: an account winning an outsized share of its money from a narrow set of opponents, in situations where its decisions looked improbably well-informed. Several affected opponents then discovered Mesh Agent on their own systems, which tied the pattern to a mechanism.
That is the kind of problem that modern integrity teams, solver-based analysis and hand-history review are built to find. We have covered the broader arms race in our pieces on AI cheating detection tools and bot detection, but the practical point is simple: pattern analysis catches behavior that no single-hand review would, and it works best when players report anything that feels off.
What This Means for Players
You do not have to be a high-stakes regular to take the following seriously.
Treat poker tools like any other software supply chain
HUDs, table managers, hotkey tools, solvers and overlays all run with a level of trust on your machine. Download them only from the developer's official site, avoid links in direct messages or forum posts, and be suspicious of "updated" installers sent to you. The reported phishing sites imitating poker rooms and poker tools are the other half of this attack and are far easier for an attacker to run at scale.
Check for remote-access tools you did not install
Reporting from the community advises Windows users to look for Mesh Agent using PowerShell and to inspect registry keys. If you find it and did not install it, the recommended steps are to disconnect the machine from the network, preserve evidence, change passwords from a different, clean device, and then reinstall the operating system. A cleanup that stops at deleting one file is unlikely to be enough.
Use a dedicated machine or account where you can
Serious players increasingly separate their poker computer from the one they use for email, banking and browsing. If a tool on your poker PC is compromised, saved passwords and payment details are then not sitting in the same browser profile. Turn on multi-factor authentication for your poker accounts, and keep your cashier credentials out of the browser.
Choose operators that take integrity seriously
How an operator responds to reports of cheating tells you a lot about it. Our safe poker sites page explains what to look for in licensing, security and account protection, and our poker networks guide shows which networks run which rooms. If you play with crypto, our crypto poker page covers the added considerations around withdrawals and account security.
What to Watch Next
Several questions remain open. The poker community is waiting for a fuller list of affected players and for evidence that would let platforms and the affected victims settle who is owed what. The gap between the 2024 and 2025 timelines needs to be explained. And the two tool vendors will be judged by whether their new controls, from logged downloads to multi-factor authentication, are enough to stop a repeat.
For the wider industry, the episode is a case study in a risk that will not go away: as sites harden their own systems, attackers move to the soft edges, and those edges are the tools players choose to install. The next few weeks will show whether the response is a one-off clean-up or a change in how poker software is built and distributed.
Whatever the outcome, the practical takeaway is unchanged. If you are making a living, or even a serious side income, from real money poker, the security of your own computer is part of your bankroll management. Protect it with the same care you give your stakes.