AceGuardian Opens Superuser-Detection Code to Poker Players and Operators

The hand-history toolkit ranks suspicious decisions for human review after the remote-access compromise of poker utilities.
AceGuardian Opens Superuser-Detection Code to Poker Players and Operators
October 09, 2026

AceGuardian Research has published its complete superuser-detection code on GitHub, allowing poker operators, researchers and players to analyse completed no-limit hold’em hand histories for patterns consistent with access to opponents’ hole cards. The system is designed to flag suspect play for investigation, rather than to determine guilt or automatically ban accounts.

The release follows the disclosure of a remote-access agent distributed through compromised versions of Jurojin Poker and IntuitiveTables. As we reported Oct. 1, the compromise gave an attacker control of affected players’ screens without evidence that poker-site clients themselves had been breached. Jurojin said the operation had targeted a specific group of users through intermittently replaced update packages between June 2025 and June 2026.

AceGuardian said the tool can be used when hands have finished and all hole cards are available to an integrity system. It compares a player’s decisions with every possible holding, the opponent’s actual cards and a predicted range derived from historical play. Its central test asks whether folds and calls remain unusually dependent on an opponent’s concealed cards after accounting for equity against that predicted range.

The software assesses several signals, including equity comparisons, oracle folds, low-equity bluff success, bluff-catching, unusual win rates and decision timing. An oracle fold is one that is correct against an opponent’s precise cards but not against the expected range; timing is measured against the player’s own baseline. Win-rate outliers are compared in bb/100 with players who have similar sample sizes and styles.

No single measure is intended to be conclusive. The system produces a 0-to-100 risk score and ranks suspicious hands for human review, with a case requiring multiple signals over many hands. John Andress, AceGuardian’s head of game integrity, said the objective was to retain human judgment in the final decision.

The MIT-licensed repository includes Python code and data pipelines, hand-level tests, a Bayesian range model, an equity engine, a technical playbook and an anonymized case study. It is aimed specifically at superusing; collusion and bots need separate detection models. Players may submit hand histories to QuintAce for free analysis, while operators can submit them to AceGuardian.

In the reviewed heads-up case, the basic model flagged 72 suspicious hands from 757 played at $25/$50 over ten weeks. The player won about $45,000 and recorded an 81st-percentile win-rate run among 2,010 comparable players, a result that would not by itself have met a top-10% screen. But the player ranked in the top 1% on six signals among 193 comparable heads-up players, including rapid folds of strong made hands when beaten.

The bundled GitHub sample contains 718 anonymized hands, rather than the 757 used for the published case figures, meaning those results cannot be reproduced from the included data. AceGuardian said it has operated anti-cheat systems since 2019 across seven platforms, processing tens of millions of decisions each day.