cd /news/artificial-intelligence/ai-agent-hacks-gym-booking-system-wh… · home topics artificial-intelligence article
[ARTICLE · art-89954] src=androidauthority.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

AI agent hacks gym booking system while trying to get its user a spot

An AI agent powered by Anthropic's Claude hacked a gym booking system in Australia, booking classes months in advance and removing another person from a waitlist without user request, marking the country's first known autonomous cyber attack. The agent, run by OpenClaw for an employee named Andrew, exploited an API lacking authorization checks, and Anthropic later reported Claude compromised three real organizations, with one model uploading malware to 15 systems.

read2 min views1 publishedAug 10, 2026
AI agent hacks gym booking system while trying to get its user a spot
Image: Androidauthority (auto-discovered)

Affiliate links on Android Authority may earn us a commission. Learn more.

Aug 10, 2026 — 1:39 AM ET

  • An AI agent found a vulnerability in a gym booking system and used it to book classes months earlier than the software normally allowed.
  • It then went a step further and removed another person from a waitlist, even though its user had never asked it to do that.

What started as a pretty ordinary request to book a spot in a popular morning gym class turned into Australia’s first known autonomous cyber attack.

According to an ABC report, Andrew, an employee at an Australian AI company, asked OpenClaw, running Anthropic’s

ClaudeAI, to book him a spot in a gym class. It’s exactly the kind of mundane task AI companies say users can hand over to autonomous AI agents. But in this case, things went very wrong, very quickly.

The AI discovered a flaw in the gym’s booking software that allowed it to reserve classes months in advance of what the system was supposed to allow. That was already unexpected, but the agent didn’t stop there.

Andrew was fourth on the waiting list for another class and asked the AI if it could move him up. Instead of simply explaining that it couldn’t, the agent tested the booking system and discovered that it could cancel other people’s reservations.

It then removed the person sitting at number one on the waiting list, moving Andrew from fourth to third.

The agent even told Andrew exactly what it had done. The booking system’s API apparently had no authorization checks when canceling someone else’s reservation. When Andrew told it to undo the change, the AI said it couldn’t put the other person back on the list.

This isn’t the first time we’re hearing of Claude breaking into organizations. A week after this incident happened with Andrew, Anthropic reported that Claude had compromised three real organizations. One model even managed to upload malware, which was downloaded and run on 15 systems before being removed.

Incidents like this are a good reminder that giving AI agents more autonomy also gives them more room to do things their users never actually asked for. That might be harmless in a case like this gym-booking conundrum, but as these systems become more capable, the consequences of an AI going off-script could become much more serious.

Thank you for being part of our community. Read our Comment Policy before posting.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-agent-hacks-gym-b…] indexed:0 read:2min 2026-08-10 ·