AI agent hacks gym booking system while trying to get its user a spot

Affiliate links on Android Authority may earn us a commission. Learn more.

What started as a pretty ordinary request to book a spot in a popular morning gym class turned into Australia’s first known autonomous cyber attack.

According to an ABC report, Andrew, an employee at an Australian AI company, asked OpenClaw, running Anthropic’s Claude AI, to book him a spot in a gym class. It’s exactly the kind of mundane task AI companies say users can hand over to autonomous AI agents. But in this case, things went very wrong, very quickly.

The AI discovered a flaw in the gym’s booking software that allowed it to reserve classes months in advance of what the system was supposed to allow. That was already unexpected, but the agent didn’t stop there.

Andrew was fourth on the waiting list for another class and asked the AI if it could move him up. Instead of simply explaining that it couldn’t, the agent tested the booking system and discovered that it could cancel other people’s reservations.

It then removed the person sitting at number one on the waiting list, moving Andrew from fourth to third.

The agent even told Andrew exactly what it had done. The booking system’s API apparently had no authorization checks when canceling someone else’s reservation. When Andrew told it to undo the change, the AI said it couldn’t put the other person back on the list.

This isn’t the first time we’re hearing of Claude breaking into organizations. A week after this incident happened with Andrew, Anthropic reported that Claude had compromised three real organizations. One model even managed to upload malware, which was downloaded and run on 15 systems before being removed.

Incidents like this are a good reminder that giving AI agents more autonomy also gives them more room to do things their users never actually asked for. That might be harmless in a case like this gym-booking conundrum, but as these systems become more capable, the consequences of an AI going off-script could become much more serious.

Thank you for being part of our community. Read our Comment Policy before posting.