Jaroslav,
Thank you. I understand the distinction you are making, and I agree that evidence of a compromised Google account or unknown sessions does not, by itself, prove that another person performed the specific disputed gameplay.
That is not what I am asking Casino Guru to assume.
What I am asking is whether the evidence can be reconsidered as a complete timeline, because there is an important fact that existed before the disputed gameplay and before I had any reason to anticipate Shuffle's later allegations:
On July 14 at 11:44 PM UTC, I contacted Shuffle and stated, "my acct was compromised."
Shuffle's own exported support record documents that report and directed me into its account recovery process.
The disputed Zeus's Thunderbolt activity occurred afterward, on approximately July 16.
That chronology matters because my compromised account explanation was not created after Shuffle accused me of exploitation, after my account was closed, or after approximately $48,000 was withheld. I reported the security problem before the activity Shuffle later characterized as deliberate exploitation occurred.
There is also additional evidence consistent with that report, including Google's security warnings concerning unfamiliar access, changes involving my account security and 2FA, and unfamiliar sessions/devices. I normally accessed Shuffle from my MacBook or iPhone, primarily through Safari, while an unfamiliar Windows/Firefox session appeared in the account information.
Again, none of those facts standing alone establishes who performed a particular game request. I understand that.
But Shuffle's allegation is itself highly technical. They claim specially generated requests were sent directly to a game backend through an authenticated session and that the activity could not have resulted from normal gameplay.
If that is the allegation, then the authentication and session evidence becomes extremely important.
The question should not simply be whether prohibited requests originated from an authenticated session associated with my account. The relevant question is whether the evidence establishes that I personally controlled the session responsible for those requests, particularly when I had already reported the account compromised before the disputed activity.
That is why I have asked for the relevant timestamps, session records, IP addresses, device/browser information, game round IDs and other technical information connecting the alleged exploit to me. Those records could potentially confirm or contradict my explanation.
There is another point I believe deserves consideration. Shuffle's Terms place responsibility on users for account activity, but their account security provision also specifically addresses circumstances where Shuffle has previously been notified that an account is no longer secure. My July 14 report therefore appears directly relevant to how responsibility for subsequent authenticated activity should be evaluated.
I am not asking Casino Guru to disregard the evidence it previously reviewed or to automatically rule in my favor.
I am asking the complaint team to compare Shuffle's technical evidence against the security evidence and chronology now presented and answer a much narrower question:
Does Shuffle's evidence actually establish that I performed or authorized the prohibited activity, or does it establish only that the activity occurred through an authenticated session associated with an account I had already reported as compromised?
Those are materially different conclusions.
Regarding the $10,000 deposit, I also understand Casino Guru cannot simply declare that Shuffle is legally required to return it. My point is narrower there as well. If Shuffle invalidated winnings because certain gameplay was allegedly illegitimate, I believe there should be a clear accounting showing which transactions and game rounds were invalidated, how the confiscated amount was calculated, and the contractual basis for retaining my original deposited funds in addition to invalidating the disputed winnings.
I recognize that reopening the complaint is not guaranteed. I am simply asking that the reconsideration be based on the entire chronology and the underlying technical connection between the alleged exploit and the person who actually controlled the relevant session, rather than treating the existence of activity on my authenticated account as automatically establishing that I personally performed it.
That is the issue I am asking Casino Guru to reconsider.


