Online poker players have been urged to check their computers after news of an alleged cheating scandal broke online.
A cybersecurity professional known as 'WolfSec0x0' reported that remote-access software was covertly installed on Windows PCs, giving an unknown attacker the ability to view their screens – and potentially their hole cards in real time.
They estimate that 10 to 30 players may have been affected, with confirmed activity dating back to March 2024.
'WolfSec0x0' also stated that no poker clients are known to be malicious or infected, and made it clear that the attacks were "extremely targeted" and that only specific high-stakes players have been affected.
The news is being taken extremely seriously in the online poker community.
Poker coach Mobius Poker posted: “Looks very, very bad. This will change online poker forever.”
Patrick Leonard wrote, “This is one of the biggest things that has happened in online poker, how we react to it as a community and individuals is very important.”
Leonard also urged players to follow instructions in an X thread posted by 'WolfSec0x0'.
The thread, shared below, details the technical specifics of the attack and how players can check whether their PCs may have been affected.
How to check your PC and what to do if you're affected
'WolfSec0x0' begins by saying that “the agent belongs to MeshCentral, legitimate open-source remote-management software” and states that the attacker can:
- Watch the affected players’ screens live, including hole cards during real-money play
- Take control of the mouse and keyboard
- Run commands with full system privileges
- Copy files to and from the PC
They also list seven steps that you should take if you find that your devices have been affected:
- Disconnect from the internet. Don't delete anything yet – the evidence matters to police and poker sites.
- From a different, clean device, change your email password first, then poker, crypto and other accounts.
- Sign out of all sessions everywhere and turn on 2FA.
- Ask your card issuer to replace any card saved in your browser.
- Move funds out of any software crypto wallet that was on the PC.
- Report it to the security team of each poker site you play on, and to your local police or fraud-reporting service.
- Wipe and reinstall Windows once the evidence is collected. Removing the agent alone isn't enough.
What happened?
The investigation by 'WolfSec0x0' found that poker players' Windows PCs had been secretly running Mesh Agent, part of the legitimate open-source remote-management software MeshCentral.
In the affected cases, it had been installed without the players' knowledge and meant that their screens could be viewed. It also potentially gave the attacker access to passwords, files, payment information and crypto wallets.
The thread states that the remote-access software was delivered via compromised versions of two legitimate poker utilities, but stops short of naming them.
'WolfSec0x0' said this was because the vendors were responding to and investigating the issue. They also clarified that none of the known compromises were recent and that, “from the info I have, no current versions of either software is still serving malicious code.”
Jurojin Poker has since publicly responded to the report, saying: “We're looking into the @wolfsec0x0 report in depth, working with him and sharing everything we find.”
While 'WolfSec0x0' does not name any suspected cheaters in their report, a separate thread on the 2+2 poker forum appears to be linked to the investigation.
Several poker accounts are named in the thread, with allegations about their results and playing patterns.
PokerOrg has not independently verified the allegations made in the 2+2 thread and has not seen any corroborating evidence confirming that any of the accounts named were involved in the alleged cheating.
PokerOrg has reached out to two operators for comment. This is a developing story and we will bring you more news as we get it.