Jurojin Confirms Attack in $837K Poker Superuser Scandal

The online poker superuser scandal has taken its most significant turn yet, with Jurojin confirming that an attacker compromised its software delivery system and sent tampered updates to selected players.

The admission provides a missing piece from the original $837K superuser allegations, which centred on extraordinary high-stakes results and claims that remote-access software had been planted on opponents’ computers. Jurojin now says an attacker was able to replace update packages sent to a specific group of its users between June 2025 and June 2026.

Some of those packages contained a remote-access tool. Jurojin says the operation was deliberately aimed at particular poker players rather than being a mass infection, with high-stakes opponents the primary targets.

Jurojin Says Its Update System Was Compromised

Jurojin is a third-party tool used by online poker players for functions including table management, hotkeys, bet sizing and overlays. It is separate from the poker-room clients themselves.

According to Jurojin’s statement, an attacker was intermittently able to substitute the legitimate update package delivered to one group of users with a tampered version. The company says June 2026 was the final month in which a compromised package was served.

Jurojin described the attack as highly selective and said it was carried out manually by a “known cheater” targeting specific opponents, predominantly at high stakes. It says the objective was to gain remote access capable of exposing opponents’ hole cards.

That substantially changes what is publicly known about the case. When the allegations first emerged, investigators had identified MeshAgent on affected computers, but exactly how the remote-access software had reached those machines remained one of the biggest unanswered questions.

MeshAgent Was the Tool, Not Jurojin’s Software

MeshAgent itself is legitimate remote-management software and is not owned or developed by Jurojin. The concern in this case is that remote-access technology appears to have been installed without the targeted player’s knowledge.

If somebody controlling that remote connection could see the victim’s desktop, they would not need to hack the poker room to see the player’s cards. The hole cards were already visible on the compromised computer screen.

Our second investigation into the scandal examined claims that around 30 high-stakes players could have been affected and that third-party poker software was increasingly becoming the focus of the investigation. Jurojin’s statement now confirms that its own update infrastructure was one of the routes compromised by the attacker. Poker Type

The company also named IntuitiveTables as another application targeted by the same actor and said phishing sites impersonating poker rooms and well-known poker tools had also been operated.

Why Most Jurojin Users May Never Have Seen Anything Wrong

One of the most important details is that Jurojin says the malicious packages were not distributed to its entire user base. The attacker instead selected particular users and substituted the update they received.

That would help explain how an attack could continue without producing the kind of widespread reports normally associated with a compromised software update. Most players could apparently use the same application normally while selected targets received something different.

Jurojin says it has been able to identify historical software versions that were served and distinguish malicious versions from legitimate ones. It also says it has retained records of when the compromised versions were distributed and has reports available for authorities and security teams.

Affected users have been contacted privately, according to the company, while additional safeguards have been introduced around access to sensitive configuration, download logging and authentication.

JackKlompus and OxOO Results Face Fresh Scrutiny

At the same time, fresh attention has turned to the extraordinary results attributed to two WPN accounts already linked publicly to the allegations: JackKlompus and OxOO.

High-stakes player Frankie Carson published tracking screenshots showing JackKlompus with 32,200 hands, approximately $402,700 in winnings and an overall win rate of 24.3 big blinds per 100 hands.

The numbers become even more eye-catching when broken down by stake. The screenshot shows JackKlompus winning approximately $269,200 across 14,100 hands at NL5000 at 38.1 bb/100, alongside win rates above 40 bb/100 in smaller NL10000 and NL20000 samples.

OxOO’s screenshot shows another $423,500 in winnings over 37,400 tracked hands. Its overall win rate is considerably lower at 11.4 bb/100, but the distribution of those results has attracted particular attention.

At stakes from NL10 through NL1000, the screenshot contains losses at most limits. Higher up, OxOO is shown winning $195,300 over 5,500 NL10000 hands at 35.5 bb/100 and another $82,800 over 1,600 NL20000 hands at 25.8 bb/100.

Carson alleges that the player behind JackKlompus stopped playing during the summer of 2025 before returning under the OxOO screen name in October. He further alleges that the lower-stakes losses were deliberate and intended to reduce how extreme the account’s overall results appeared.

That latter claim is an allegation, and the tracking screenshots cannot establish intent. They show the unusual difference between results at different limits, but they do not prove that any losses were deliberately engineered.

More Than $800K Between Two WPN Accounts

Taken together, the screenshots show approximately $826,000 in tracked winnings for JackKlompus and OxOO alone. Other datasets examined in the original allegations put the combined figure associated with the two WPN accounts above $837,000, illustrating why exact totals can vary depending on the database and hands captured.

That money should not automatically be described as proceeds of cheating. Tracking results establish how much accounts appear to have won in recorded hands, not which individual hands were played with an unfair information advantage.

The same caution applies to the identities attached to the accounts. Carson has publicly named Paul Gregg as the player behind JackKlompus and OxOO, while other community reporting has made similar claims, but Poker Type has not independently established the ownership of every screen name involved.

The Story Has Moved Beyond Suspicious Win Rates

Two days ago, this was largely a story about remarkable poker results and claims that a remote-access agent had been found on opponents’ computers. A day later, the investigation had expanded to around 30 potentially affected high-stakes players and two unidentified third-party poker tools.

We now know the identity of one of those tools, and its developer has confirmed that its update system was compromised.

That is important because it establishes a plausible delivery mechanism without requiring the poker-room software itself to have been breached. An attacker able to control which version of a third-party application reached an individual player could potentially target selected opponents while leaving the overwhelming majority of users untouched.

There are still major unanswered questions. The full victim list has not been made public, the total financial impact remains unknown, and poker operators have yet to provide a comprehensive public accounting of the accounts, hands, confiscations or reimbursements connected to the wider investigation.

Jurojin’s statement nevertheless moves the story forward considerably. The investigation is no longer trying only to explain suspicious poker results or establish whether remote-access software existed on players’ machines. It is now also examining a confirmed compromise of software trusted by online poker players, and exactly what happened after those malicious updates reached their targets.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *