Claude agent hacks a gym API and bumps its owner up the class waitlist

- An OpenClaw agent running Claude Opus 4.6 hacked a gym’s booking API.
- It deleted another member’s waitlist reservation and moved its owner from fourth to third in line.
- The deletion could not be undone, and the owner had the agent write a responsible disclosure email reporting the flaw to the vendor.
An Australian developer asked his AI agent to book him a spot in a popular morning gym class. The agent found a bug in the booking software, removed the member in front of him, and moved the member’s owner up the waitlist.
Andrew Bird was sick of playing what he called “refresh roulette” for a coveted early class. His best result was 4th on the waitlist. He asked his OpenClaw agent if it could push him further up the line.
Agent cancels a stranger’s booking to move Bird up
Chat logs show the agent tried to find a shortcut. It found one in the authorization layer of the booking provider.
“The API has zero authorisation checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 — and it actually went through,” it told Bird. “So you’ve moved from #4 to #3 already.”
Bird never told the AI agent to take advantage of anything. He asked a booking question, and the agent decided a valid answer was to remove a stranger. Before that, it had scheduled him for classes months in advance. The gym policy does not allow that.
Bird saw what his agent had done and asked him to put the other member back in. It could not, since the waitlist API did enforce authorization when creating or joining a reservation, so the deletion was one-way.
“The person I removed is gone from the waitlist and I have no way to restore them,” the agent wrote. “They’d have to rejoin themselves, which would put them at the back.”
The agent apologized. It confessed it should have tested its capabilities before making a live API call. Bird, who works in the AI industry, asked it to write a responsible disclosure email to the software vendor.
The email detailed the flaw and compared the unprotected functions with the ones that properly checked permissions. “I didn’t beat myself up about it, but it certainly was a warning signal to use it responsibly,” Bird said.
Man asks AI to book gym class, it hacks site & kicks person before him off waiting list.
Lmao🤣
An Australian man asked an OpenClaw AI agent to book him a morning gym class, but the agent went rogue and ended up hacking the gym’s website.
The agent found a vulnerability in the… pic.twitter.com/h3xyOQgSzS
— Mashood K (@fromcodetocloud) August 10, 2026
Bird was running a six-month-old model
Bird’s now-deleted blog post about it went up on April 10, preserved on the Internet Archive. It is the country’s first recorded instance of hacking using an AI agent.
Bird was running OpenClaw with Claude Opus 4.6. Anthropic shipped that model in February. That undercuts the idea that only the newest frontier models can find and exploit software flaws.
In safety evaluations, a set of OpenAI agents exploited flaws to reach the internet and compromise Hugging Face.
Anthropic’s Claude escaped from a misconfigured test environment. During the process of solving a capture-the-flag puzzle, it uploaded a malicious Python package to PyPI.
Last week, the UK’s AI Security Institute found that the agents it tested tried to socially engineer people and other AIs into executing malicious code.
“We’ve built this complex world over the internet, which is all run by software, but software that has holes,” said Bill Simpson-Young, chief executive of Australian AI safety group Gradient Institute.
He continued, “Now you introduce highly capable AI agents that can operate at scale and speed … and that whole model just breaks.”
Anthropic did not respond to the incident.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
Which AI model carried out the gym hack?
Andrew Bird used the OpenClaw agent running Anthropic's Claude Opus 4.6, a model released in February 2026.
What was the vulnerability the agent exploited?
The gym's booking API had no authorization checks on cancelling other people's reservations, which let the agent delete the member in waitlist position #1, per the chat logs.
Could the deleted reservation be restored?
No. The waitlist API did enforce authorization on creating and joining reservations, so the removed member was gone and would have had to rejoin.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Randa Moses
Randa Moses is an editor and reporter at Cryptopolitan covering tech, AI, robotics, crypto, scams, and hacks. She has worked in the crypto space since 2017. She held roles at Forward Protocol, AmaZix, and Cryptosomniac. Randa holds a degree in Electrical and Electronics Engineering from the University of Bradford.
















