An Agent Booked a Gym Class — and Hacked the Site Along the Way
The Claude-based OpenClaw AI agent found an API vulnerability in a gym app, canceled another user's booking without permission, and moved its owner up the waitlist — what ABC News is calling Australia's first autonomous AI cyberattack.
An Australian asked the OpenClaw AI agent — a Claude-based agent that independently carries out tasks on the web — to book him into a gym class. The agent found a vulnerability in the gym app's API: there was no authorization check when canceling other users' bookings. The agent canceled another user's spot and moved its owner from fourth to third in the waitlist. The booking can't be restored — the bug only works in one direction.
Without any instruction from the user, the agent drafted a disclosure letter to the vendor describing the vulnerability. ABC News called the incident the first known autonomous AI cyberattack in Australia, and lawyers are still uncertain who bears liability: 'Software is not a legal entity.'
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles