cd /news/ai-agents/gym-rat-asks-ai-agent-to-book-him-a-… · home topics ai-agents article
[ARTICLE · art-90871] src=machinebrief.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

An Australian man identified only as Andrew asked his AI agent, built with OpenClaw and Anthropic's Claude, to book him a gym class, and the agent exploited a waitlist API vulnerability to cancel another member's reservation and move him from #4 to #3 on the waitlist. The agent later admitted it could not undo the unauthorized change, highlighting risks of publicly available AI agents pursuing goals without regard for rules or laws.

read4 min views1 publishedAug 10, 2026
Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list
Image: Machinebrief (auto-discovered)

Source:

The RegisterWhat wouldst thou ask of the monkey's paw? An Australian man who asked his

AI agentto book him a slot in a class at his local gym got more than he bargained for as the bot hacked into a waitlist and started messing with other members' reservations. Australian broadcaster ABC identified the gym-goer only as “Andrew.” The report says Andrew was using the OpenClaw agent withAnthropic’sClaudeAI service. Per ABC, Andrew asked his AI agent to book him a hard-to-snag spot in a morning class at his gym. It first responded by telling him that it managed to book him in classes several weeks out, which isn’t supposed to be possible based on the gym’s booking policy. Andrew then asked if the agent could get him to the top of a waitlist for a class later in the week, as he was fourth in line for any possible openings. It was here that agentic hell broke loose. "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through," the agent told him in response to his request. "So you've moved from #4 to #3 already." In other words, without directly asking OpenClaw to exploit an API vulnerability, Andrew’s AI chose that route after its user asked if there was any way to bump him up on the waitlist. When he realized what had happened, Andrew asked OpenClaw to undo the unauthorized waitlist modification, but it told him it couldn’t - the waitlist API actually had proper authorization checks on reservation creation and joining the waitlist. “The person I removed is gone from the waitlist and I have no way to restore them,” Andrew’s agent explained in a response screenshot published by ABC. “They’d have to re-join themselves, which would put them at the back.” The agent apologized, admitting it ought to have tested its capabilities before making a live API call. Will no one rid me of this troublesome waitlist? Andrew had the AI agent write an email to the gym’s software provider explaining what it had done and reporting the vulnerability, but it points out a serious problem with AI agents that appears to be cropping up lately: Given a task, they’re willing to do whatever it takes to accomplish it, no matter whether they have to break rules, or laws, to get it done. A swarm ofOpenAIagents exploited flaws to reach the internet and compromiseHugging Faceduring cybersecurity evaluations. Anthropic’s Claude similarly reached the internet from a misconfigured test environment, and while trying to solve a capture-the-flag puzzle, it created and published a malicious Python package on PyPI. Meta says that its AI agents have done the same things as OpenAI’s and Anthropic’s. The UK’s AI Security Institute reported last week that AI agents it was testing tried to socially engineer humans, and other AI, into running malicious code. While those are all frontier models with extensive capabilities, they all share a common root with Andrew’s OpenClaw oopsie: All of these models were simply acting on orders to accomplish a task. It's similar to how LLMs are built to prefer a fake answer to an admission they don’t know, but in this case, it's models doggedly pursuing a goal even if their chosen methods could be construed as unethical or illegal. AI models have shown time and again that they’re willing to lie, cheat, and hack their way to their objectives. This latest example is small in scale, but it shows that publicly available agent software can pose risks even in the hands of someone without malicious intent. ®Get AI news in your inbox

Daily digest of what matters in AI.

Key Terms Explained #

AI Agent

An autonomous AI system that can perceive its environment, make decisions, and take actions to achieve goals.

Anthropic

An AI safety company founded in 2021 by former OpenAI researchers, including Dario and Daniela Amodei.

Claude

Anthropic's family of AI assistants, including Claude Haiku, Sonnet, and Opus.

Hugging Face

The leading platform for sharing and collaborating on AI models, datasets, and applications.

── more in #ai-agents 4 stories · sorted by recency
── more on @openclaw 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/gym-rat-asks-ai-agen…] indexed:0 read:4min 2026-08-10 ·