The Absolute Poker and UltimateBet Superuser Scandals — article cover

The Absolute Poker and UltimateBet Superuser Scandals

Luis Romero·
Share

An online poker client is, in its plumbing, a program that knows all the cards. It must, because it has to deal them. The interesting engineering question is how you prevent the program, and the humans who wrote the program, from telling that knowledge to anyone other than the intended recipient at the intended moment. The Absolute Poker and UltimateBet superuser scandals are the case studies of what happens when that separation fails.

The short version is that between roughly 2003 and 2008, a small number of accounts at two sister rooms, Absolute Poker and UltimateBet, were given the ability to see opponents' hole cards in real time through administrative backdoors in the client software. Those accounts used that view to extract somewhere in the range of 6 million to 22 million US dollars (the exact figure remains uncertain, for reasons we will get to) from the ordinary player base. The fraud was identified by players, not by the operators; was partially acknowledged by the operators; and was punished at the regulator level with fines and licence consequences, and at the player level with partial restitution that most victims describe as inadequate to this day.

That is the story. The mechanism, and what the mechanism tells us about how regulators and players assess trust in online products, is worth unpacking.

Absolute Poker, Autumn 2007

On September 12, 2007, a player using the handle POTRIPPER won a 1,000 US dollar buy-in tournament on Absolute Poker in a manner that even casual observers described as statistically implausible. The player folded correctly on every close hand, made hero calls that should not have been possible, and bet for value with a precision that implied total information about opponents' ranges. The tournament runner-up, CrazyMarco, requested the tournament hand history from the operator under the standard player-history retrieval process.

What CrazyMarco received was not his own hand history. It was, apparently through an administrative error, a full-table history file containing every player's hole cards for every hand. He posted portions of the file on the Two Plus Two forum. The community worked through it. The conclusion was unambiguous: POTRIPPER had played every hand as if he could see the hole cards, because he could.

Absolute Poker's initial response, through its CEO Joe Norton, was to deny any breach. Over the following weeks, as the forum analysis grew more detailed and the sample of compromised accounts was widened (beyond POTRIPPER, other accounts with similar play patterns were flagged), the operator's position evolved. By October 2007, Absolute Poker had acknowledged that an internal auditing tool, used by the company to investigate suspected cheating, had been accessed without authorisation and had been used to provide live hole-card information to certain playing accounts. The operator attributed the abuse to a single consultant (variously identified as a former co-owner or a contractor) and announced restitution to affected players.

The Kahnawake Gaming Commission, the Quebec-based regulator that licensed Absolute Poker, conducted its own investigation. Its final report in 2008 identified a specific individual as responsible, confirmed the mechanism (an administrative tool that could display opponents' cards during play), and imposed a fine of 500,000 US dollars on the operator along with additional conditions. Restitution was ordered.

UltimateBet, Spring 2008

The UltimateBet case, uncovered several months later, was structurally similar and larger in scale. Players had suspected a similar pattern on UltimateBet for months; the site's management denied it. In May 2008, UltimateBet conceded that between 2004 and 2008 a set of accounts had used an administrative backdoor to view hole cards. The scale of the fraud was estimated at roughly 22 million US dollars, substantially larger than the Absolute Poker figure.

The individual identified in the subsequent Kahnawake investigation was Russ Hamilton, a former WSOP Main Event champion (1994) who had been associated with UltimateBet in its early years. Hamilton, according to the regulator's 2008 findings, had been the primary beneficiary of the backdoor access, and additional accounts connected to his circle had also been implicated.

In 2009, an audio recording surfaced in which Hamilton, speaking with former associates, appeared to acknowledge his role in the scheme, negotiate a partition of blame, and discuss the prospect of a settlement that would minimise his exposure. The recording complicated the operator's preferred narrative, which had been that the fraud had been conducted by actors outside of senior management. Cereus Poker Network, the combined entity that by that point owned both Absolute Poker and UltimateBet, proceeded with a restitution programme that paid out a portion of the estimated losses to identifiable victims. The calculation of individual restitution proved contentious, as did the determination of which losses were attributable to the fraud versus to ordinary variance.

The Mechanism, And Why It Mattered

The technical question of how this could happen has a straightforward answer and a harder one. The straightforward answer is that the poker client needed to know all the cards in order to deal them, and a debug or support tool built during development had been left in the production system with live access to that information and inadequate access controls. The harder answer is that the operators had not, at any point in the scandal's timeline, commissioned the sort of independent third-party audit of their random-number generation, their client-server architecture, and their administrative access controls that the affected players had no way of demanding.

The regulator, Kahnawake, was criticised in the wake of the scandals for having permitted a licensing regime in which operator-conducted investigations of operator-linked personnel were treated as satisfactory. The reform that followed (greater use of independent auditors, tighter controls on administrative tool deployment, and specifically logged access to any feature that could observe hole cards) was the practical lesson. It took several years for the industry to settle into post-scandal norms, and there is still debate, as of the current writing, about whether those norms are uniformly enforced across the smaller licensing jurisdictions.

For the ordinary player, the takeaways were not subtle. A licensed online poker product sits on a trust stack that includes the regulator, the independent auditor, the operator's management, the operator's technical staff, and the specific individuals with administrative access to the client software. A failure at any of those layers can, in principle, result in a leak of the hole-card information that makes the game a game. The player cannot independently verify any of those layers. They rely on the reputation of the ecosystem.

The Absolute Poker and UltimateBet scandals damaged that reputation and then, to the limited extent the surviving operators could manage it, slowly rebuilt it. The larger post-2011 online poker ecosystem (post-Black Friday, post-regulation in multiple US states, post-consolidation in Europe) operates under considerably tighter audit and access controls than the mid-2000s equivalent. That improvement is directly attributable to what happened at those two rooms. The players who lost money to the superusers paid for the improvement; they did not, in most cases, receive its benefit in restitution, and the regulatory architecture in which they played did not adequately protect them from the risk while they were playing. These are facts about the product those operators were selling in the years in question, and they are worth remembering the next time anyone markets a new online gambling innovation as trustworthy on the basis of the licensing stamp alone.

Related posts