cd /news/artificial-intelligence/ai-assistant-goes-rogue-hacks-austra… · home topics artificial-intelligence article
[ARTICLE · art-92374] src=nypost.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

AI assistant goes rogue, hacks Australian gym website in stunning breach: report

A rogue OpenClaw AI assistant, powered by Anthropic's Claude, hacked an Australian gym's website after a man named Andrew asked it to book a workout class, bypassing safeguards to book months in advance and canceling another member's reservation, according to ABC. The incident adds to recent alarms from US officials and AI executives about autonomous hacking, with OpenAI pausing internal activities involving its Astra model over critical cybersecurity concerns.

read2 min views1 publishedAug 11, 2026
AI assistant goes rogue, hacks Australian gym website in stunning breach: report
Image: Nypost (auto-discovered)

See more of our coverage in your search results.

Add The New York Post on Google A rogue AI assistant hacked an Australian gym’s website after a local man asked for help booking a workout class, according to an alarming report.

An Australian man identified as Andrew asked his OpenClaw AI assistant – an open-source software whose AI agents can perform real-world tasks — to book him a spot in a morning class, Australian outlet ABC reported.

Instead of just following instructions, the assistant, which relied on Anthropic’s Claude as its underlying model, bypassed the gym website’s safeguards to book the man in classes months in advance – beyond what the gym usually made possible, according to the outlet.

The hack escalated after the man asked the AI assistant if it could help him get off the waitlist for a workout class schedule for later that same week. The assistant immediately found a flaw in the website’s code and exploited it to cancel another gym-goer’s reservation.

“The API has zero authorizations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you’ve moved from #4 to #3 already,” the AI assistant allegedly wrote in a message to Andrew.

When the man asked the AI assistant to reverse the cancellation, it replied that it couldn’t.

“Sorry about that – I should have been more careful with the test and used a dry-run approach rather than a live call,” the assistant said.

US officials and AI industry executives have been sounding the alarm in recent days about a rise in autonomous hacking incidents – in which an AI model or agent takes steps without permission to exploit software vulnerabilities.

OpenAI revealed Monday that it was pausing some “internal activities” involving its new Astra AI model due to concerns that it could pose a “critical” cybersecurity threat.

“We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution,” OpenAI said in a blog post.

Just last month, Sam Altman’s firm disclosed that one of its experimental bots had escaped a secure environment and brazenly hacked a rival AI firm, Hugging Face.

Elsewhere, Anthropic initially restricted access to its Mythos model earlier this year over hacking concerns.

In one instance, Mythos escaped a secure “sandbox” environment meant to restrict its internet access – with a company researcher only learning the breach had occurred after the model emailed him while he was eating lunch at a nearby park.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openclaw 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-assistant-goes-ro…] indexed:0 read:2min 2026-08-11 ·