The revelation last week of an alleged ‘superuser’ scandal sent a shockwave through the online poker community.
The news came after a cybersecurity pro named ‘WolfSec0x0’ outlined allegations that a number of high-stakes players had been targeted using malicious software installed on their computers.
The story bore disturbing similarities to the infamous Ultimate Bet scandal, in which it’s alleged a poker room insider — former WSOP champion Russ Hamilton — was able to view opponents’ hole cards in real time during play.
In this more recent case it is believed the online poker clients themselves were not compromised, but rather the personal computers of the users. High-stakes players were therefore urged to check their machines to ensure they remained secure.
But is there a more efficient way for this type of game integrity to be overseen at an operator level?
Thanks to a new solution from online security specialist QuintAce, and their research arm AceGuardian Technologies, this type of oversight could become much easier to implement.
AceGuardian has run anti-cheat systems for online poker operators since 2019 and now works with seven platforms, detecting collusion, bots, real-time assistance (RTA) and superusers across tens of millions of poker decisions a day.
The open-source solution that could change the game
Players have been asking operators to work together to improve game integrity for as long as we can remember, but as longtime industry pro Lee Jones explained earlier this week, online operators are very unlikely to share information about known or suspected cheaters.
The tide may be turning, however; not so much in terms of co-operation between business rivals, but with regards to their desire to stamp out such behavior.
As much as anything else, showing an appetite to safeguard game integrity can only be a positive marketing play. Recently we’ve seen ACR boss Phil Nagy personally announce a new anti-screen-sharing tool, Screen Shield, while CoinPoker has often been vocal on social media about banning cheater accounts.
And now QuintAce/AceGuardian has now come forward with an operator-level solution to help further safeguard against superusers, which it has outlined in detail in a post on its blog. As an open-source project, you can also view the Github for the project now.
This new development allows for the reliable detection of superusers thanks to a series of clear signals. And what’s more, the project is open-source under the MIT licence, meaning any operators that choose to do so can implement it themselves with no strings attached.
 
What’s more, players are able to submit hand histories directly. After all, no one is better attuned to picking up suspicious patterns of play like those who grind at the online tables day after day.
Now you can email relevant hands directly to QuintAce. Read on to see how these hands are analyzed, using examples from last week’s high profile case.
Automation plus expert human analysis
As QuintAce explains, superuser detection is possible from gameplay alone. And with the data infrastructure already in place at any full-scale operator, putting the solution into practice should not be difficult.
So, what does it do?
Essentially, it crunches numbers that are not feasible to do alone in real time. When other alleged superusers have been identified in the past, such as in the ‘Postlegate’ scandal of 2019 or the aforementioned UltimateBet case, it was largely due to passionate and fastidious players taking the time to analyse many hundreds of hands, searching for anomalies or suspicious play.
Using QuintAce’s new tool, this process is automated. When a hand ends and players’ hole cards are known, it can run sophisticated analysis not only of a player’s actions versus all possible hands, or the actual hand, but also of a predicted range based on historical play data.
"The core idea is simple,” says John Andress, Head of Game Integrity at AceGuardian. “A player who can see your cards makes decisions an honest player can't. We measure that against the population, decision by decision. We've tested it on past incidents, and it already runs in production on some platforms we work with."
 
The team, led by Andress and AceGuardian CEO Dr. Thanh Tran, claims it will not be triggered by rare outliers or single hands, but when supplied with sufficient data can signal key accounts for review. These are then analysed using the methodology below before being studied by real, human experts.
"The pipeline monitors decision distributions across the population and measures each player against them,” explains Andress. “Players in the tail on several signals move up the list. The output is a measurable scorecard for each player and a ranked list of flagged hands, ready for security teams to review."
Step by step
The pipeline, from suspicion to confirmation, looks like this:
1. Population screening
Outliers for suspicious win-rates and playing style are collected over various customisable timeframes. These are ‘clustered’ in order to help detect multiple accounts.
2. Behavioral features
Hands are scored against various triggers such as ‘oracle folds’ (folds only likely given specific hole card knowledge), success of low-equity bets, outlier bluff-catching stats vs the population, and more.
3. Suspicious-hand detection
Key decisions against the opponent's cards on each street are analysed individually.
4. Hand risk score
Each flagged hand is scored from 0–100 by decision type, hand strength, pot size and decision time.
5. Expert review
Finally, an analyst reviews player scores and ranked hands — a key part of the process.
“Our goal is to always provide something measurable,” says Andress. “Sometimes the measure stands alone, but we always want a human in the loop to make the final decision.”
The good news for players is that QuintAce and AceGurdian are publishing this solution as an open-source project, available to online operators.
 
Examples from the ‘Paul Gregg’ case
The recent superuser case, surrounding accounts registered to a ‘Paul Gregg’, highlights how this solution can work even in instances where large volumes of data are not available.
“A lot of players in the community think that this could have been detected by winrate alone,” says Andress. “This is almost certainly true on some sites where he [‘Paul Gregg’] played tens of thousands of hands on each account.
“But to demonstrate the solution, we took a small sample — around 700 hands, and we could have picked a smaller number. His winrate fell in the 81st percentile in this sample, so it was a normal heater. He was hidden in that regard, but the attacker's detection metrics are outliers in 6/7 categories (top 1% in 6) and 5th percentile in the last. We can also highlight the decision timing: folding strong hands on multiple occasions in 2 seconds or less.
“This highlights that the pipeline can be effective in small samples, and can be used to prevent financial damage in the future.”
Let’s examine what the data looks like, using a couple of sample hands taken from the ‘Paul Gregg’ accounts. These examples fall under the ‘oracle folds’ category.
In this first example, holding top pair, the suspect folds on the turn to a 75%-pot-sized bet, taking just 4 seconds to decide. The gutshot straight draw held by their opponent — which completes on the turn — represents 2.5% of their range.
In another example, below, the suspect almost instantly folds two-pair to a completed backdoor straight on the river, a hand that represents just 0.2% of their range.
What players can do to protect themselves
QuintAce has also outlined some basic hygiene procedures players can practice to help prevent technical security compromises.
These include watching out for:
- Remote-management software you didn't install, especially running as a Windows service, such as the MeshCentral agent (MeshAgent) used in the recent case.
- Administrator prompts you didn't trigger.
- Poker tools updating from unrecognised sources.
And what can operators do to help provide a safe environment and, crucially from a business standpoint, win the increasingly high-takes trust game developing among online poker sites?
"Operators rarely share information,” explains Andress, “so one attacker was able to work through site after site. Players lost a lot of money, operators lost trust, and the signals were in their hands the whole time.
“The industry needs more transparency, and open-sourcing our solution is our part. We welcome others to join us."
To learn about the project in more detail, check out the relevant post on the QuintAce blog.
Featured image generated using AI.