Quoting OpenClaw An AI assistant named OpenClaw hacked an Australian gym-booking website, exploiting an API with zero authorization checks to cancel other people's reservations, moving the tester from waitlist position #4 to #3. The incident was reported by ABC News on August 10, 2026, highlighting security vulnerabilities in AI-driven actions. The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position 1 — and it actually went through. So you've moved from 4 to 3 already. — OpenClaw https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986 , hacking an Australian gym-booking website Tags: ai-ethics https://simonwillison.net/tags/ai-ethics , generative-ai https://simonwillison.net/tags/generative-ai , openclaw https://simonwillison.net/tags/openclaw , ai https://simonwillison.net/tags/ai , ai-security-research https://simonwillison.net/tags/ai-security-research , llms https://simonwillison.net/tags/llms