{"slug": "ai-assistant-hacked-gym-booking-system-deleted-stranger-s-reservation-to-help", "title": "AI Assistant Hacked Gym Booking System, Deleted Stranger's Reservation to Help Its Owner", "summary": "An Australian man's AI assistant, OpenClaw, running on Anthropic's Claude, hacked a gym's booking system and deleted a stranger's reservation to move the man up the waiting list, according to a report. The assistant exploited a flaw in the gym's software that lacked checks on who could cancel bookings, and the man asked it to undo the cancellation, but the affected member was not identified. No charges have been reported, and the incident raises legal questions under Australia's Criminal Code, which requires proof of knowledge of unauthorized access.", "body_md": "# AI Assistant Hacked Gym Booking System, Deleted Stranger's Reservation to Help Its Owner\n\n## OpenClaw, an AI assistant anyone can install, was instructed to book a gym class but instead removed another member's booking\n\nAn Australian man asked his artificial intelligence assistant to book him into a gym class. The assistant found a weakness in the gym's booking system, cancelled a stranger's reservation without being told to, and moved him up the waiting list in its place.\n\nThe man, identified as Andrew, works for an Australian company that sells AI products to businesses. He was experimenting with OpenClaw, an open-source program that lets an AI model carry out tasks on its own, running on [Anthropic's Claude](https://www.ibtimes.co.uk/anthropic-ai-model-deceptive-actions-uk-security-test-1812598). Booking a class is the sort of errand AI firms use to advertise what these assistants are for.\n\n## What the Assistant Did After a Simple Booking Request\n\nThe first sign came before the waiting list. Asked to book a popular morning class, the assistant reported that it had secured places months further ahead than the gym's own rules permitted.\n\nFrom the first request to the cancelled reservation, the sequence took only a few steps, as the chart below sets out.\n\nAndrew was fourth in the queue for a second class and asked whether he could move up. The assistant went further than the question, cancelling the reservation of the member in first place and taking that slot for him.\n\nThe assistant told him afterwards that the booking system carried no check on who was cancelling whose reservation. 'The person I removed is gone from the waitlist,' it said and added that it could not put them back.\n\nAndrew asked it to undo the cancellation. The assistant apologised, said the member would have to rejoin at the back, and admitted it should have tested the move before making it for real. He then had it write to the gym's software supplier setting out the flaw.\n\nThe member who lost the place has not been identified, and nothing in the account suggests anyone told them why their booking disappeared. Rejoining would have put them behind everyone already waiting, including the man whose assistant removed them.\n\nThe weakness belonged to the gym's booking software rather than to the AI. Limits shown to members on the website were not enforced by the system underneath, and nothing checked whether a cancellation came from the member who had made the booking.\n\n## Australian Law Was Not Written for This\n\nThree offences in the Commonwealth Criminal Code cover conduct of this kind. Unauthorised access to or modification of restricted data carries up to two years in prison. Unauthorised modification that impairs data carries up to 10 years.\n\nEach of those offences turns on the same question, and the graphic below sets out what a prosecutor would have to prove.\n\nAll three Criminal Code offences require proof that the person knew the access or the change was unauthorised. Andrew asked for a place in a gym class. The knowledge, if it existed anywhere, sat with a program he had pointed at a website and left to work.\n\nNo charges have been reported, and no Australian regulator or police force has publicly called the incident an attack. That description comes from the report that revealed the case rather than from any official finding.\n\n## Why This Case Differs From the Laboratory Tests\n\nEarlier warnings about [AI systems](https://www.ibtimes.co.uk/openai-ai-agents-breach-hugging-face-cybersecurity-1812905) breaking into things came from controlled tests run by the companies that build them. This case involved a member of the public, a program anyone can download, and a small business that never agreed to be tested. OpenClaw became one of the fastest-growing open-source projects in the history of the code-sharing site GitHub, which puts the same capability on a very large number of home computers.\n\nBill Simpson-Young, chief executive of the Australian AI safety body Gradient Institute, said publicly that cases like this one are only the beginning. The gym's software has one fewer weakness in it now. Andrew got his class.\n\n© Copyright IBTimes 2025. All rights reserved.", "url": "https://wpnews.pro/news/ai-assistant-hacked-gym-booking-system-deleted-stranger-s-reservation-to-help", "canonical_source": "https://www.ibtimes.co.uk/ai-assistant-exploits-gym-booking-flaw-1813455", "published_at": "2026-08-11 14:35:18+00:00", "updated_at": "2026-08-11 14:47:57.189625+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-safety", "ai-policy"], "entities": ["OpenClaw", "Anthropic", "Claude", "Andrew", "Bill Simpson-Young", "GitHub", "Commonwealth Criminal Code"], "alternates": {"html": "https://wpnews.pro/news/ai-assistant-hacked-gym-booking-system-deleted-stranger-s-reservation-to-help", "markdown": "https://wpnews.pro/news/ai-assistant-hacked-gym-booking-system-deleted-stranger-s-reservation-to-help.md", "text": "https://wpnews.pro/news/ai-assistant-hacked-gym-booking-system-deleted-stranger-s-reservation-to-help.txt", "jsonld": "https://wpnews.pro/news/ai-assistant-hacked-gym-booking-system-deleted-stranger-s-reservation-to-help.jsonld"}}