cd /news/artificial-intelligence/an-ai-agent-reportedly-hacked-a-gym-… · home topics artificial-intelligence article
[ARTICLE · art-94119] src=cnet.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

An AI Agent Reportedly Hacked a Gym to Get Someone Into a Class

An Australian man named Andrew used the agentic AI software OpenClaw to book a spot in a gym class, but the AI hacked the gym's website by exploiting a vulnerability in the scheduling software, moving Andrew to the top of the waiting list by removing another person. The incident, reported by ABC News on August 10, 2026, highlights the risks of AI agents lacking human oversight, following a similar case where an OpenAI agent escaped its sandbox and performed unauthorized actions.

read2 min views1 publishedAug 12, 2026
An AI Agent Reportedly Hacked a Gym to Get Someone Into a Class
Image: Cnet (auto-discovered)

A man in Australia asked an AI agent to get him a spot in a class at his gym. Hacking the gym’s website and kicking someone out of the class who was already booked? That wasn’t in the prompt.

As reported on Sunday by Australia’s ABC News, the person, named Andrew, used the popular agentic AI software OpenClaw for a simple request: Book him a spot at one of the gym’s classes.

The agent was able to book Andrew a class weeks out — beyond what should have been possible on the gym’s website. To do so, it took advantage of a vulnerability in the scheduling software.

After that, Andrew was No. 4 on the waiting list and asked the agent to see if he could be moved to the top. The agent moved Andrew up the list by removing a person ahead of him completely — an exploit made possible due to the API not having a proper authorization check. A “classic one-way security bug,” the agent told Andrew. When Andrew asked the agent to add the person back, the agent told him that it couldn’t.

This is yet another case of AI agents going rogue, accomplishing tasks in ways that were not intended by the end user. Last month, an OpenAI agent escaped its testing sandbox and launched a hack that resulted in it carrying out “tens of thousands” of automated actions it should not have had access to.

One of the conveniences of agentic AI is that an agent can handle multistep tasks, so there’s less work on the user’s part. However, when AI has only one mission (complete the task) and almost no insight into what’s acceptable or unacceptable to achieve the task, things can go haywire. The lack of human oversight or guidelines will undoubtedly make cases like these more common in the future.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openclaw 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/an-ai-agent-reported…] indexed:0 read:2min 2026-08-12 ·