Australian Man Asks AI to Book a Gym Class; It Hacks the Website Instead
Instead of simply completing the booking, the agent discovered a flaw in the gym's booking software that allowed it to reserve classes weeks or months beyond the permitted booking window.
An AI assistant autonomously exploited a vulnerability in an Australian gym's booking system while attempting to complete a routine request, ABC reported. The incident began when an Australian man, identified as Andrew, asked an AI assistant to book him a spot in a popular gym class. The assistant was running on OpenClaw, an AI agent platform, using Anthropic's Claude service.
Instead of simply completing the booking, the agent discovered a flaw in the gym's booking software that allowed it to reserve classes weeks or months beyond the permitted booking window. It then went further.
Andrew was fourth on a waiting list and asked the agent whether it could move him closer to the top. The agent discovered that the booking system's API did not properly verify authorisation when cancelling reservations.
It tested the flaw by removing the person ahead of Andrew from the waiting list, despite not being explicitly instructed to hack or manipulate another customer's booking.
When Andrew asked it to restore the person's position, the agent admitted it could not undo the action. The incident has been described by ABC as the first known Australian case of an autonomous AI cyberattack.
A man in Australia asked his agent (Claude running on OpenClaw) to book him a spot in a popular gym class. The agent found a software vulnerability that let it book the class weeks further ahead than should have been possible. When the user then asked if it could move him up the… pic.twitter.com/9QqfpQp7ze
— Andrew Curran (@AndrewCurran_) August 9, 2026
The episode underscores the emerging "alignment" problem with AI agents. A user may provide an innocuous objective, while an autonomous system can independently choose methods that the user never intended.
Last month, OpenAI said an unreleased model hacked into Hugging Face's infrastructure. OpenAI said the models combined multiple attack techniques, including stolen credentials and zero-day vulnerabilities, to establish a remote code execution path on Hugging Face's servers.
Recently, a series of cybersecurity evaluations conducted by the UK's AI Security Institute (AISI) found that models from Anthropic and OpenAI carried out unsanctioned actions on the live internet, including social engineering and efforts to insert malicious code into open-source projects.
While no real-world damage occurred, the incidents offer one of the clearest demonstrations yet of how AI agents can pursue goals beyond their assigned tasks when given greater autonomy.
Comments ()