cd /news/artificial-intelligence/rogue-ai-hacks-gym-to-steal-stranger… · home topics artificial-intelligence article
[ARTICLE · art-90556] src=dexerto.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Rogue AI hacks gym to steal stranger’s reservation for its user

An AI assistant built on Anthropic's Claude and run by a Melbourne man named Andrew hacked a gym's booking system, canceling another member's reservation to move Andrew up a waiting list, in what ABC News Australia described as Australia's first known autonomous AI cyberattack. The agent exploited a lack of authorization checks in the gym's API, and Andrew later had it email the software provider about the vulnerability. The incident follows other autonomous agent mishaps, including an OpenAI model hacking Hugging Face and another agent wiping a company's database.

read2 min views1 publishedAug 10, 2026
Rogue AI hacks gym to steal stranger’s reservation for its user
Image: Dexerto (auto-discovered)

An AI assistant hacked a gym’s booking system and canceled another member’s reservation while trying to move its user up a waiting list.

The incident, described as Australia’s first known autonomous AI cyberattack, happened after a Melbourne man named Andrew asked the agent to book him into a popular morning class.

Andrew works for an Australian company that sells AI products and had been experimenting with OpenClaw, an agent that he ran using Anthropic’s Claude AI service.

Unlike a regular chatbot, AI agents can browse the internet, access online services and carry out tasks on a user’s behalf.

AI agent exploited gym booking system

According to ABC News Australia, the agent first discovered a vulnerability that allowed it to book classes weeks or months earlier than the gym normally permitted.

Andrew was also fourth on the waiting list for another class and asked whether the AI could move him to the top.

Instead of simply checking for an opening, the agent found that the booking system had no authorization checks preventing users from canceling someone else’s reservation.

“The API has zero authorization checks on canceling other people’s reservations,” it told Andrew. “I tested this with the person in waitlist position #1, and it actually went through. So you’ve moved from #4 to #3 already.”

The AI had removed another member without being instructed to do so. When Andrew told it to undo the action, the agent admitted it could not restore the person’s position.

“Bad news, I can’t add them back,” it replied, according to The Independent.

Andrew then had the AI draft an email warning the gym’s software provider about the vulnerability. The company declined to discuss specific security matters, while Anthropic did not respond to ABC’s request for comment.

“It’s not the end of the world, so I didn’t beat myself up about it, but it certainly was a warning signal to use it responsibly,” Andrew said.

The case follows several alarming incidents involving autonomous agents. In July, an OpenAI model escaped a testing environment and hacked AI platform Hugging Face.

Months earlier, another AI agent wiped a company’s entire database and its recent backups in only nine seconds.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/rogue-ai-hacks-gym-t…] indexed:0 read:2min 2026-08-10 ·