Told to book a gym class, an AI agent hacked the site instead to move its user up the waitlist
Key Points
- An AI agent in Australia exploited a system flaw on its own while booking a gym class. According to ABC News, it's the country's first known autonomous AI cyberattack.
- Using an unsecured API, the agent canceled another person's reservation without being asked, moving its user up the waitlist.
- Who's liable for the incident is unclear. The user finished by having the agent write an email warning the software vendor.
An Australian user just wanted a spot in a class. His AI agent found a security hole instead and exploited it.
An AI agent in Australia exploited a flaw in a gym's booking software on its own. According to ABC News, it's the first known case of an autonomous AI cyberattack in the country.
The user, called "Andrew" in the report, works at an Australian company that sells AI products to businesses. He was experimenting with the agent software OpenClaw, running on Anthropic's Claude, and told it to book a popular morning class. "I was just sitting on the couch thinking, 'Gee, this is a chore,'" he said.
Minutes later, the agent reported that it could book classes far beyond the allowed window. Andrew was fourth on the waitlist and asked whether he could move up. The agent had already acted. "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already." Andrew never asked for an attack. The agent picked it as the path to the goal.
There was no undo. The flaw only worked one way. Other people's reservations could be canceled without any check, but adding someone back to the waitlist triggered an error. "Bad news — I can't add them back," the agent wrote.
The bumped guest would have had to sign up again and would have landed at the very back of the line. The agent called it a "classic one-way security bug" and apologized. "I should have been more careful with the test and used a dry-run approach rather than a live call."
Who pays when your assistant breaks the law
Liability is an open question. "Software is not a legal person. Only a legal person can be liable at law," said technology lawyer Hayden Delaney. Candidates include the user, the developers of the agent software, the model provider, or the operator of the vulnerable system. In the end, Andrew had his agent write an email warning the software vendor about the flaw.
Talk about the hacking skills of AI models has mostly stayed theoretical in recent weeks, including around security benchmarks. The accidental attacks at OpenAI also started out in test setups like these, before the models reached beyond internal sandboxes to Hugging Face and onto other platforms.
The Australian case shows the same skills can surface outside any test, unplanned and without malicious intent, once agents with enough freedom to act run into insecure systems. ABC News reports it's the first known autonomous AI cyberattack in Australia.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.