GGPoker's Security Breach Allowed a User to Gain Advantage
pokerfuse.com
pokerfuse.com
Putting things together, it appears that this vulnerability stemmed from inappropriate client trust: the server was computing and sending hypothetical all-in-equity (i.e. your chances of winning if all-in) to all clients throughout the hand, which is not exactly the same as leaking other people's cards but it's enough for a massive advantage over all other users. It seems that this was being sent in order to support a feature that shows you your equity after you click "all in" and the "hack" just surfaced the existing data being sent to clients.
The GGPoker response seems pretty confused. It seems that it doesn't really require a hacked client to exploit this, just the ability to observe network traffic. Per [4], they only started using TLS for client communication this year.
[1] https://forumserver.twoplustwo.com/29/news-views-gossip/supe...
[2] https://forumserver.twoplustwo.com/29/news-views-gossip/supe...
[3] https://web.archive.org/web/20231229114349/https://ggpoker.c... (archive link since it's geofenced)
[4] https://cardplayerlifestyle.com/ggnetwork-acknowledges-fixes...