Ignacio Moron Gives New Details About Paul Gregg & MeshAgent Poker Hack
GipsyTeam
Today, 16:02
In a Spanish interview with PokerRed, top reg Ignacio Moron detailed how players identified the Canadian scammer Paul Gregg, and what role poker rooms played.
PokerRed's video was originally recorded in Spanish. There is an English-dubbed version on YouTube, but the speech timing and quality is a bit sub-par. All credit for the content goes to PokerRed, and you can watch their full video on their YouTube channel.
— Our guest is Ignacio "Nacho" Moron, one of the biggest, if not the biggest, victims in the Paul Gregg scandal. Ignacio himself asked to speak to share his perspective on the situation.
After gaining access to players' computers and cards using the Mesh Agent program, Canadian Paul Gregg robbed over several years, perhaps with other robbers. On the WPN network alone, the criminals got almost $900,000.
— Hello, Ignacio, how are you doing in light of the recent news?
It's moments like these that make you feel overwhelmed. I live by the principle that everything in life happens for a reason, but in this case, I don't even know what to do. We've focused all our efforts on the investigation, but there's still a lot that remains unclear. The poker rooms need to take control of the situation; they have everything they need to do so.
In the case of cheating on this scale, players would like to receive some kind of feedback, but so far there's been silence from the other side. We'll see what happens next. We're only just beginning to understand the scale of what happened.
The last few days have been very eventful. We have a high-stakes regs chat where the scandal is being discussed in detail. These days, there's a huge flow of news items like "This happened to my friend," or , "He was caught in this room for," and, "Watch this hand."
I think we'll soon be able to gather all the data to form a clear picture.
I'm still in a state of shock. I'm trying to assess my losses and rethink all the major downswings of recent years. We're all human, and prolonged losing streaks affect our finances and our self-confidence. It's unclear when I was simply unlucky and when I was playing with scammers. We still don't know if it was one person or several.
Poker intersects closely with our personal lives and affects relationships with friends and family. I know players who lost less to scammers than I did, but their bankrolls were much more severely impacted.
— How did you find out about cheating?
In that same group chat with other regulars. One player, who wishes to remain anonymous for now, shared his suspicions with the others. He was the first to discover MeshAgent on his computer.
Then other players found the software, and thanks to that, we gradually traced it back to Paul Gregg, who played on GG under his real name. Then we discovered his nicknames on ACR and CoinPoker. Without the efforts of our group, we would have learned nothing. I suspect the rooms still don't understand the importance of this chat for the poker world, and not just for high stakes.
When the Discord group was created, we didn't fully understand what it would be capable of. Now we know the nicknames Paul Gregg played under at GG, ACR (OxOO and JackKlompus), and CoinPoker (Europe). Some regs were already reporting this guy's strange play and posting suspicious hands 1.5 to 2 years ago.
The situation is very difficult for both players and rooms. This isn't just someone who could see the cards; he clearly understands poker at an advanced level. I've played with him in all the rooms. I think he deliberately played some sessions fairly and didn't use his software to avoid suspicion. But we were still able to detect hands and anomalies in his stats that wouldn't be possible in a fair game.
At some point, panic broke out in our group – everyone was afraid they were running infected software. It's funny that I didn't find it on mine. I changed my computer two months ago and had to completely reformat the old one; it had nothing to do with the scandal. But many regs discovered MeshAgent on their computers; the first players were infected in December/November 2022.
We suspect the scammer selected his victims in advance and groomed them—first playing at lower limits, then moving up in limits, and then installing his software on them.
— We should point out that the program is legitimate. This is not some kind of hacker software. MeshAgent is often used by IT companies for remote access to computers. That's why antivirus software didn't react to it.
As we've already mentioned, you were one of the main victims. Can you tell me how much Paul Gregg won from you?"
Yes, my friends and I collected all the information.
I played my first sessions with him at ACR when he was nicknamed OxOO, then he changed it to JackKlompus. In the hands we collected, I lost $42,000, but I couldn't reconstruct some of those hands.
I recall we played much more often. I think I lost at least $150,000 to him at ACR, or closer to $200,000.
— There were other suspicious accounts, too. You sent us some screenshots, we'll display them now.
Alextrev asks who plays under the nickname "pgs", and DavyJones replies with an upward-sloping graph.
Then Matt Marinelli asks if anyone has tried chatting with him.
Yes, then Alex expressed suspicion that it was a superuser. Not someone with an RTA or charts, but a superuser. In April 2024, this seemed completely insane. I never cease to be amazed how a regular reg could notice this, while a huge room with a security team saw nothing suspicious. It's very strange.
— But one room still compensated you?
Yes, at ACR, I played with both of the nicknames now attributed to Paul Gregg, but I didn't notice anything suspicious.
Then, in December 2024, CoinPoker held its first Cash Game World Championship, where everyone played under their real names.
Towards the end of the event, nicknames no one had seen before began appearing at the regular tables. Thanks to the group's collective efforts, we quickly figured out who they belonged to.
But there was one exception... a guy playing under the nickname "Europe." I played a few sessions with him at 3-max and 4-max. He made some mistakes, but I immediately realized he knew how to play. For several days, he didn't raise any suspicions, until one day, he won $60,000 from me at NL5K in 15 minutes. That's 12 buy-ins! I remember one hand very well.
The pot was about 250bb. I opened with sevens and called a 3-bet. The flop came and I had a flush blocker. He made a small bet, and I called. The turn completed a flush and a straight. He checked, I bet half pot, or 40%, and he called. On the river, which was a blank, I went all-in and still remember how I felt when I saw the instant all-in. I thought for a long time and called, and he showed aces.
It might look like he has a strong hand, but it's actually a shove for very thin value, which isn't typical for this player. I have a lot of flushes and straights, so this is an odd play on his part. The other regs agreed with me.
I don't remember if it happened immediately after that session or a little later, but I stopped playing with him. Other regs also filed reports to support. When a new player gives all the strongest players high-stakes action, it attracts attention.
Apparently, CoinPoker launched an investigation after that, but it took quite a while. Only a year later, one morning, I opened my phone and saw a message from a CoinPoker representative. I remember that moment very well because it was my birthday. They told me they'd caught someone, several players received compensation, and I got the biggest one. They usually don't reveal the nicknames of banned players, but this time it was obvious.
— Did he continue playing while the investigation was ongoing?
No, he was banned immediately.
— That's great, of course, but to investigate for a whole year...
As far as I understand, they immediately block the account and freeze the funds, and then conduct an internal investigation. I don't know exactly how that goes. They probably call the player, ask them to record the game, and so on.
— How much did they return to you?
$60,000.
— Did they send any report?
No, the rooms don't report to their players. A few other players have received compensation, but I don't know who exactly or how much.
They just send a letter: "We caught a player who broke the rules, you're one of the victims." And ACR doesn't disclose any information at all. Thanks to tracking sites, we know that Paul Gregg won about a million there, but I can't prove anything.
I wouldn't be surprised if tomorrow I received a letter saying: "You're one of the victims, your compensation is $1,700."
— It's obvious that the cheater will play in different rooms. How easy is it to discover all of their nicknames?
Strong regs notice similarities pretty quickly. Even cheaters have their own style quirks. I wrote on Discord a year ago that Europe and JackKlompus might be the same person. But it was only recently confirmed.
— Do the Romanians react to your reports in any way, send at least formal responses?
I'm also curious why Paul Gregg was only discovered on CoinPoker, even though it was a very new room at the time.
He continued playing quietly on ACR and GG, despite all the reports. I don't know exactly how many there were, but I'd guess around 20-30. We even have a dedicated thread on our Discord for poker site representatives where we share our suspicions. But nothing's happening; apparently they're not taking us seriously. If anything does happen, it's incredibly slow.
— JackKlompus played his first 32,000 hands at ACR with a win rate of 24 BB/100. But over the next 76,000 hands, his win rate dropped to a plausible 7 BB/100. Do you think he intentionally dropped to lower stakes to lower his win rate?
Obviously, that's the reason. In the first screenshot, he played less than 500 hands at NL400-600, and in the second, he had almost 8,000. His second nickname, OxOO, is similar.
— Why does he have two nicknames, is this allowed?
That's the thing. No, you can't change nicknames. But the site didn't explain it. One nickname simply stopped playing, and a new one immediately appeared. Apparently, this happened as soon as JackKlompus started being discussed on our Discord. And we figured out his new nickname right away, too.
— I still can't wrap my head around it. Shouldn't the room immediately track such abnormal win rates?
In theory, it should. Both ACR and GG have been known to ban players after big wins. I personally know regulars who were asked to provide game recordings.
Why were these protocols ignored in the case of Paul Gregg? I don't have an answer. Maybe he was checked, and he simply passed all the checks. In any case, the poker sites don't explain this in any way. They, like the rest of us, couldn't detect the prohibited software.
But the fact that a person can see their opponent's cards should be noticed by security even with a cursory analysis of hands. Just look at that hand with Kings versus Aces that everyone reposted.
A cheater is also human, he will make mistakes, and this can be noticed.
– In this hand he called the 3-bet, but should he always 4-bet?
Yes, but that's the only hand anyone saw. I assure you, there were hundreds of similar examples, and the room has full access to the database.
I said this guy is clearly a good poker player, but he's a mediocre cheater. Even if you four-bet kings, even if you lose, you still see your opponents' cards and will soon win everything. Apparently, he couldn't control his own greed here. This is exactly what I said above—humans will always make mistakes.
pgs played an even more spectacular hand.
We suspect this is this guy's very first nickname—he played under it in 2023, testing out his strategy. But he quickly realized he couldn't last more than a weekend with that kind of play and stopped playing.
It only took three showdowns for the regulars to suspect something was suspicious.
— How responsible are the poker rooms for what happened, on a scale of 1 to 10?
Considering how long this has been going on, they bear full responsibility. We started writing reports two years ago, with specific hand examples, and there were a lot of them. Room representatives contacted us, but they weren't impressed with our analytical skills.
— Should the poker sites fully compensate the affected players for their losses?
I certainly don't want the poker sites to pretend this doesn't concern them. This is just the beginning, everything will develop rapidly, and I myself don't know what we'll ultimately find out.
— I saw a screenshot in the GipsyTeam article that the FBI has already been contacted about this case?
Yes, I saw it too, but I don't want to get too involved. I don't speak English well and I don't want my name associated with anything like that. Besides, such cases usually end in nothing.
So far, we agree that the scammers were targeting high-stakes players. But we're not entirely sure it was limited to just open cards.
For example, a friend of mine named Alejandro Herrera plays tournaments and has never registered for ACR or GGPoker, but he also had a MeshAgent.
— We haven't yet discussed how the program got onto victims' computers. It was through Intuitive Tables and Jurojin, correct?
Yes, it's already clear that this is the main source. But now it's much more important to assess the scale. Were players on Bodog or WPT Global affected? It seems there were reports that some WPT players received emails from support saying they were also playing with someone who accessed their cards through MeshAgent.
The issue isn't limited to Paul Gregg on GG and OxOO on ACR; players at other formats and stakes could have been affected.
Moreover, with this program, they could have caused much more problems for everyone, stealing any passwords, and so on. That didn't happen. However, I still changed everything I could. It seems this person or group decided to limit themselves to poker. I think they assumed it wouldn't cause them any major problems with the police if they were suddenly caught.
Perhaps I'm right, and this is simply a strong poker player who only understands this topic. After all, hacking banking apps or crypto wallets is a crime of an entirely different order.
— Another victim, Manuel "J0hn McClean" Saavedra, told me that ACR is actively cooperating and communicating with him, but GGPoker is completely silent. Is it the same for you?
I haven't spoken to anyone at all. I know the room representatives read the thread where everything is discussed, but no one has contacted me. We sent detailed reports to GG, but we haven't received anything in response.
— McClean complained to me that another problem is that you can’t download the hand history on GG.
Yes, it's impossible to download hands played three or six months ago or earlier. And those that can be downloaded are useless because they don't include player nicknames, just numbers that change every day.
Today, Paul Gregg was assigned 112, and tomorrow, 914. So yes, analysis is impossible.
This wouldn't be a big deal if the room itself conducted a proper investigation. I don't even know if they have people who know how to analyze poker statistics. Although nowadays, you don't even need an employee for that; it's all easy to do with AI—evaluate 3-bet, 4-bet, and river fold ranges and compare them with the field.
— Do you have any idea how much he won in all the rooms?
According to the data available to us, about $1 million on ACR, and $1.5 million on GG.
— Are you saying that low-limit players could have suffered as well?
More and more people are discovering that they've been infected with malware, but it's not a guarantee that they've been harmed. On some rooms, like Bodog, it's impossible to tell if you've been scammed because all the tables are anonymous.
— How will this story affect your future career? What will the poker sites do?
I'll definitely start monitoring computer security more closely. I've already started doing so. I still believe that this kind of fraud can be combated if the rooms do their job. I hope they'll acknowledge their responsibility and pay compensation.
I'd also like them to finally start taking our Discord group seriously. At least let them listen to our opinions. Communication never hurt anyone. Everyone will benefit from this—both players and the rooms.
— But the poker sites can always argue that the infected software had nothing to do with their client.
If you open the GGPoker main page, the word "safe" appears about 10 times. They say safe play is the room's top priority. They've been voicing this slogan practically since the day they opened. But do players feel safe there now? Not just regulars, but everyone. So the room must take full responsibility.
Another important issue that's rarely discussed is information sharing between rooms. CoinPoker banned the nickname "Europe" two years ago, and they probably had all his personal information. Then this person got verified on GG and played there under his real name. If Coin knew he was a scammer, why didn't they inform other rooms?
You go to Las Vegas and get caught cheating at some casino, and within two minutes the whole city will know about it. Everyone will have your photo, and you won't even be allowed in anywhere else.
You will be able to leave comments, rate posts, participate in discussions and increase your poker level.
If you prefer a four-colour deck or want to turn off avatar animation, change your profile settings.
You will have an access to bookmarks, staking and other useful poker tools.
On each page you will see where new posts and comments have appeared.
If you are registered in poker rooms through GipsyTeam, you will receive rake statistics, bonus points for in-store purchases, exclusive promotions and extended support.