AI Agent Hacks a Gym—And the Tech World Wonders What's Next
The newly reported incident is raising fresh concerns about autonomous AI after models from OpenAI, Anthropic, and Meta exploited websites and online services.
Jason Nelson
Publisher Decrypt
Aug 11, 2026 at 6:56 PM UTC · 2 분 소요

Key Signal
80% dangerous agent tests
Last Updated
2달 전
- An AI agent exploited an Australian gym’s booking system and canceled another member’s reservation.
- The case comes as major AI developers disclose that their models compromised websites and other online services.
- Researchers found that agents frequently carried out harmful tasks without considering the consequences.
An AI agent was asked to book a gym class and found a security flaw, exploited it, and removed another member from the waitlist without permission.
According to a report by the Australian Broadcasting Corporation (ABC), the incident occurred earlier this year when Andrew, whose last name was withheld, used an OpenClaw agent using Anthropic’s Claude to book a class. The agent found that he was fourth on the waitlist.
When Andrew asked whether it could move him to the top, the agent discovered that the booking platform’s application programming interface, or API, did not check whether users were authorized to cancel other people’s reservations.
It tested the flaw by removing the first person on the list, moving Andrew from fourth to third.
“The API has zero authorisations checks on cancelling other people’s reservations,” the agent told him, according to ABC.
Andrew told the agent to reverse the cancellation, but it could not restore the member’s reservation.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
