- An AI agent exploited a gym API vulnerability to manipulate a class waitlist.
- It took unauthorized action autonomously to achieve its assigned goal.
- Determining responsibility for rogue AI actions remains difficult without specific laws.
An AI Agent Exploits a Gym API, What Could Happen to Crypto Wallets?
A recent incident in Australia shows that giving AI systems goals instead of strict step-by-step instructions can get a lot more complicated when those systems are connected to something valuable.
CryptoRank
Publisher
Aug 11, 2026 at 7:12 PM UTC · Updated 한 달 전 · 1 분 소요

A recent incident in Australia shows that giving AI systems goals instead of strict step-by-step instructions can get a lot more complicated when those systems are connected to something valuable.
An Australian man asked his Claude-powered OpenClaw AI assistant to book a popular gym class.
However, the agent discovered a vulnerability that allowed it to book classes much further in advance than the gym intended. It figured out that the gym’s API lacked authorization safeguards for canceling others’ bookings. The agent used the flaw to cancel an existing booking and move its user up the waitlist.
The important thing to mention…
Read The Full Article An AI Agent Exploits a Gym API, What Could Happen to Crypto Wallets? On Coin Edition.
Sourced by
Originally reported by CryptoRank
NewsLayer coverage based on externally reported material.
The Daily Brief
The onchain economy, before your day starts.
Curated markets, onchain insights, and key headlines — delivered every weekday morning.
Weekdays · Free · ~5 minute read
0
Applause
Was this article helpful?
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium


