This content was AI generated based on the original article published on https://www.pokernews.com/news/2026/09/superuser-targets-online-poker-players-52500.htm. All credits for the original reporting belong to them.
The online poker community was rattled this week by a series of tweets alleging a covert cheating scheme reminiscent of the infamous “POTRIPPER” superuser scandal from the 2000s. The claims came from an X account with only 230 followers, @wolfsec0x0, who identified themselves as a cybersecurity professional.
According to the tweets, a hidden remote-access agent has been secretly installed on the Windows computers of about 30 high-stakes players through compromised poker-related software. The account claims this activity dates back to 2024.
The alleged tool reportedly allows whoever controls it to view a victim’s screen in real time, including hole cards, and even take control of their mouse and keyboard. The account described the malicious program as disguising itself as a legitimate Windows service called a “Mesh Agent,” hiding its files while running a system-level process referred to as “PowerShield.”
@wolfsec0x0 claimed the exposure could extend beyond poker, potentially giving attackers access to saved browser passwords, session cookies, and stored payment card data.
No specific poker platforms or affected players were named. The account did clarify that major sites GGPoker and ClubWPT Gold are “not involved,” and said unnamed software vendors are already working to fix the issue, with no malicious code currently active in their latest versions.
Poker pro Todd Witteles noted the compromised software appears to be a third-party tool rather than an official poker client. The community is now awaiting further evidence or a list of impacted players.




