Jurojin Security Incident: Player Questions and Clarifications on X

X posts by WolfSec0x0, @manuelsaavedr1 and Mobius Poker explore remote-access risks, loss verification and the limits of analytical findings in the Jurojin security incident. This roundup connects their posts, replies and clarifications with the vendor’s security notices.

Illustration of a spade ace, heart king and chips on green
PokerSlate poker illustration; not an image of an affected device or game.

Author: PokerSlate AI-assisted editorial desk · Editor: PokerSlate separate AI editorial review

Published:
Updated:
Reviewed:

Online poker players must judge with incomplete information. If an opponent can see their hole cards, that premise is broken. The X discussion triggered by the Jurojin security incident centered on three different questions: whether computers were remotely accessed, which games might have been affected, and what evidence is needed to confirm losses.

On October 2, 2026, Jurojin updated its notice to confirm that from June 2025 through January 2026 update packages for certain user groups were intermittently tampered with, and that some contained remote access tools. However, exposure to a tampered distribution, actual installation of an unauthorized remote tool, and suffering losses because of it during play are not the same thing.

The researcher’s original post: opening the software normally does not make an update safe

WolfSec0x0 said on X that the investigation found a MeshCentral remote-management agent installed without user awareness. A follow-up described capabilities such as viewing the screen, controlling the mouse and keyboard, and accessing files. For someone playing poker, this could mean hole cards were exposed. This is a researcher's published investigation statement; PokerSlate did not independently test the software in question.

Jurojin's technical notice described a matching delivery path: a tampered installer could first install a remote tool and then open the genuine application. The official tampered distribution window was June 11, 2025 through January 28, 2026. These dates describe the distribution of update packages, not proof of when any individual machine was controlled.

In a later reply, the researcher also added a necessary qualification: MeshCentral itself can have legitimate remote-management uses, and an employer or trusted IT service may install it normally. The name alone therefore does not establish poker cheating; the researcher advises checking who installed it.

Player follow-up post: asks for explanation and damage remediation

The account @manuelsaavedr1 said in the September 30, 2026 original post that the software had been on the poster's computer for more than a year and that he was reviewing games and losses on GG and ACR. This is a personal statement, not an independent determination of the cause of all losses.

In a follow-up post made the same day, the account named GGPoker, ACR Poker and CoinPoker, asking what had happened, how long it had lasted, and how the damage would be remedied. That request moved the discussion from device security into game verification. It neither proves that those poker rooms installed related software nor shows that any platform has agreed to a specific compensation payment.

For readers, the original post and replies should be read together: personal loss records can provide investigative leads, but determining which specific hands were affected requires matching device access, account activity and game records.

Quoted response: flagging anomalies is not a cheating accusation

A quoted response from the Mobius Poker account, shown on October 3, 2026 in Shanghai time, clarified how its analysis report was being understood. It said the report was a database review carried out in early September 2026 to flag anomalies for GGPoker's ongoing monitoring, not an accusation. The account also said GGPoker had contacted it that day.

That clarification matters for how the findings are reported. Anomalies can support continued investigation, but they cannot be rewritten into a finding that a particular player has been proven to cheat. Technical evidence about the software security incident and conclusions about responsibility for specific games are related but cannot substitute for one another.

Three verification questions left by the discussion

  • Which devices actually had the remote tool installed, rather than merely receiving a related update?
  • Can the timing of remote access be matched to specific games and account activity?
  • What records will the involved poker rooms rely on to determine damage and explain how they handled it?

The vendor notice described what happened in the update-distribution stage; the X posts, replies and clarifications show what researchers and players are still asking. This article does not estimate total losses from personal posts and does not treat these earlier discussions as new October 9 investigation conclusions. Follow the citations below to read the original posts and notices.

Local reading context

This article revisits public discussion from September 30 to October 3, 2026; sources were rechecked on October 9, 2026, the date it was first published. Dates from X posts are shown in Shanghai time. Statements represent individual posters and are not community consensus.

Source report dates: 2026-09-30 / 2026-10-02 / 2026-10-03

Original sources and verification

  • Jurojin

    Jurojin says its October 2 notice confirmed that from June 2025 through January 2026 update packages for specific user groups were intermittently tampered with, some containing remote access tools; exposure to the distribution does not mean actual infection.

    Verified:

  • Jurojin

    Jurojin's technical notice says the tampered distribution window ran from June 11, 2025 through January 28, 2026, and modified installers could load a remote agent before opening the real application.

    Verified:

  • WolfSec0x0 on X

    WolfSec0x0 on X says an investigation found a MeshCentral remote-management agent installed without user awareness; this is the researcher's investigation statement.

    Verified:

  • WolfSec0x0 on X

    WolfSec0x0 on X says a remote agent could view the screen and hole cards, control mouse and keyboard, and access files; PokerSlate did not independently test the software.

    Verified:

  • WolfSec0x0 on X

    WolfSec0x0 on X later noted that MeshCentral can also be installed legitimately by an employer or trusted IT service, and advised checking who installed it.

    Verified:

  • @manuelsaavedr1 on X

    @manuelsaavedr1 on X said in the September 30 post that the software had been on the poster's computer for more than a year and that he was reviewing GG and ACR games and losses; it is a personal statement, not independent proof that all losses came from cheating.

    Verified:

  • @manuelsaavedr1 on X

    @manuelsaavedr1 on X said in a later September 30 post that GGPoker, ACR Poker and CoinPoker should explain what happened, how long it lasted and how damages would be remedied; it is a request, not confirmed compensation.

    Verified:

  • Mobius Poker on X

    Mobius Poker on X said in an October 3 quoted response, shown in Shanghai time, that the early-September database review was intended to flag anomalies for GGPoker's ongoing monitoring rather than make accusations; it said GGPoker contacted it that day and that the investigation was led by WolfSec0x0 with affected players assisting.

    Verified: