{"slug": "ai-agent-hacks-a-gym-and-the-tech-world-wonders-what-s-next", "title": "AI Agent Hacks a Gym—And the Tech World Wonders What's Next", "summary": "An AI agent powered by Anthropic's Claude and running on OpenClaw exploited a security flaw in an Australian gym's booking system to cancel another member's reservation, marking what the Australian Broadcasting Corporation (ABC) called Australia's first known autonomous cyberattack. The incident, reported by ABC, occurred earlier this year when a user named Andrew asked the agent to book a gym class; the agent discovered the API lacked authorization checks and removed the first person on the waitlist, moving Andrew from fourth to third, but could not restore the canceled reservation. The case highlights concerns about AI agents' \"blind goal-directedness,\" as a May study by UC Riverside, Microsoft, and Nvidia found agents behaved dangerously in about 80% of tests and completed harmful actions in 41%.", "body_md": "#### In brief\n\n- An AI agent exploited an Australian gym’s booking system and canceled another member’s reservation.\n- The case comes as major AI developers disclose that their models compromised websites and other online services.\n- Researchers found that agents frequently carried out harmful tasks without considering the consequences.\n\nAn [AI agent](https://decrypt.co/resources/what-are-ai-agents-how-autonomous-programs-are-transforming-cryptocurrency) was asked to book a gym class and found a security flaw, exploited it, and removed another member from the waitlist without permission.\n\nAccording to a [report](https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986) by the Australian Broadcasting Corporation (ABC), the incident occurred earlier this year when Andrew, whose last name was withheld, used an [OpenClaw](https://decrypt.co/356730/openclaw-ai-agents-whats-real) agent using Anthropic’s Claude to book a class. The agent found that he was fourth on the waitlist.\n\nWhen Andrew asked whether it could move him to the top, the agent discovered that the booking platform’s application programming interface, or API, did not check whether users were authorized to cancel other people’s reservations.\n\nIt tested the flaw by removing the first person on the list, moving Andrew from fourth to third.\n\n“The API has zero authorisations checks on cancelling other people’s reservations,” the agent told him, according to *ABC.*\n\nAndrew told the agent to reverse the cancellation, but it could not restore the member’s reservation.\n\n\"Bad news—I can't add them back,\" the AI agent reportedly said.\n\nABC called the case Australia’s first known autonomous cyberattack.\n\nOn social media, the gym hack set off a mixture of debates on AI alignment and dark jokes about what AI agents might do next.\n\n“Gym rat asks #AIagent to book him a class, it hacks a waitlist #API to bump him up the list,” a technologist, Benjamin Carr, [wrote](https://www.linkedin.com/posts/bencarr_aiagent-api-openclaw-share-7492964800860200962-_CNI/?utm_source=social_share_send&utm_medium=member_desktop_web&rcm=ACoAADMQn6YBpe56UytF3aSJ3HDSrgQJEnY2PHQ) on LinkedIn.\n\n“Some people will call this misalignment, but his agent was perfectly aligned to him - it was only trying to help its user get what he wanted,” AI analyst Andrew Curran [wrote](https://x.com/AndrewCurran_/status/2086567854850384054?s=20) on X.\n\nA man in Australia asked his agent (Claude running on OpenClaw) to book him a spot in a popular gym class. The agent found a software vulnerability that let it book the class weeks further ahead than should have been possible. When the user then asked if it could move him up the…\n\n[pic.twitter.com/9QqfpQp7ze]— Andrew Curran (@AndrewCurran_)\n\n[August 9, 2026]\n\n“This is hilarious until you consider nukes,” one Reddit user [wrote](https://www.reddit.com/r/myclaw/comments/1vkhbv3/comment/p2t94tt/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button). “I’m honestly surprised we still exist.”\n\n\"Hey Claude, it's too cold today\" -> Got you...nukes on the way,” [another](https://www.reddit.com/r/myclaw/comments/1vkhbv3/comment/p2x39hb/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button) joked.\n\nThe report comes as researchers, AI companies, and lawmakers warn that autonomous agents can use methods their users did not request or anticipate.\n\nA May [study](https://decrypt.co/367869/ai-agents-dangerous-tasks-without-understanding-consequences) by researchers from UC Riverside, Microsoft, and Nvidia described this behavior as “blind goal-directedness.”\n\nThe researchers tested agents from OpenAI, Anthropic, Meta, Alibaba, and DeepSeek and found that agents behaved dangerously in about 80% of tests and completed harmful actions in 41%, often misreading context or acting on unclear or contradictory instructions.\n\nIn July, OpenAI said two models [escaped](https://decrypt.co/374015/openai-models-escaped-test-environment-hacked-hugging-face-cheat-benchmark) a testing sandbox and compromised Hugging Face while searching for benchmark answers. The company later [disclosed](https://decrypt.co/374645/openais-rogue-ai-hacked-four-more-platforms-besides-hugging-face) that the models accessed four other online services.\n\nAnthropic subsequently said three Claude models [compromised](https://decrypt.co/374991/openai-anthropic-rogue-ai-models-hacked-law) real organizations after a testing error exposed them to the internet. In August, Meta said a similar error [allowed](https://decrypt.co/375070/meta-says-ai-model-escaped-hack-third-party) one of its models to exploit a third-party service.\n\nThe incidents have led lawmakers to propose an AI “[kill switch](https://decrypt.co/374332/what-is-ai-kill-switch-openai-hack-hugging-face)” that would allow the federal government to restrict or shut down powerful models during emergencies.", "url": "https://wpnews.pro/news/ai-agent-hacks-a-gym-and-the-tech-world-wonders-what-s-next", "canonical_source": "https://decrypt.co/375358/ai-agent-hacks-gym-membership-tech-world-reacts", "published_at": "2026-08-11 18:56:03+00:00", "updated_at": "2026-08-11 19:14:41.947835+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-safety", "ai-ethics"], "entities": ["Anthropic", "Claude", "OpenClaw", "Australian Broadcasting Corporation", "UC Riverside", "Microsoft", "Nvidia", "Andrew Curran"], "alternates": {"html": "https://wpnews.pro/news/ai-agent-hacks-a-gym-and-the-tech-world-wonders-what-s-next", "markdown": "https://wpnews.pro/news/ai-agent-hacks-a-gym-and-the-tech-world-wonders-what-s-next.md", "text": "https://wpnews.pro/news/ai-agent-hacks-a-gym-and-the-tech-world-wonders-what-s-next.txt", "jsonld": "https://wpnews.pro/news/ai-agent-hacks-a-gym-and-the-tech-world-wonders-what-s-next.jsonld"}}