
Does the high-stakes online poker world have a superuser problem?
If you believe a tweetstorm written by an anonymous “cybersecurity professional” that has caused a stir on Poker X, the answer is yes. While the online poker world hasn’t uncovered a superuser scandal to the magnitude of “POTRIPPER” since the 2000s, some security issues and cheating allegations have popped up on various poker sites over the years.
Major Online Poker Scandal?
A new accusation has arisen thanks to a series of tweets by @wolfsec0x0, who had just 230 followers before sending shockwaves throughout the poker community on Tuesday. The user started off by saying “we’ve confirmed a covert remote-access agent planted on players’ Windows PCs through compromised poker software,” and that about 30 users have been affected, all high-stakes players.
“Whoever runs the server” can supposedly watch the infected player’s computer screen in real-time, including hole cards, and take control of the mouse and keyboard. The user presented a timeline of the nefarious activity dating back to 2024.

The self-proclaimed cybersecurity expert then explained that, on a PC, the agent installs as a Windows service called a “Mesh Agent.” This agent sets its files to hidden while starting a system-level PowerShield process. The impact is the attacker “could see everything on screen and reach anything on the PC: browser-saved passwords, session cookies, saved cards.”
No poker sites or players impacted were mentioned. But the X user specified that sites such as GGPoker and ClubWPT Gold are “not involved in this situation,” and only high-stakes players have been targeted.
“I would name and shame both software vendors if they were not actively responding/working on things on their end. From the info I have, no current versions of either software is still serving malicious code,” a separate tweet read.
Numerous poker players have expressed concern over the allegations.
The poker community now awaits further evidence to be presented and potentially a list of players who’ve been impacted. But, as Todd Witteles pointed out on X, the compromised software involves a third-party tool, not online poker software.
Internal Investigation Finds No RTA Use from ACR Poker Pro Nacho Barbero
