Can't get a spot at the gym? Just use AI to hack the place, like this user did

An Australian AI company employee asked Claude to book him a spot at a popular gym. Things went wrong.

An empty gym
An Australian gym became the first victim of AI hacking in the country. | Image by TrainAway
0
AI agents are hacking the internet left and right. This time, the incident wasn't a test. An Australian AI company employee asked Claude to book him a spot at a popular gym. The request turned into the first autonomous cyberattack in Australia.

Claude AI hacked an Australian gym


According to ABC, Andrew — an Australian citizen working at an AI company — needed to book an appointment at a local gym. He delegated the mundane task to OpenClaw, an AI system running Anthropic’s Claude AI.

The AI discovered a vulnerability in the gym's booking system and reserved a class many months in advance of what the system normally allowed. But this wasn't the full story. Then the AI did something really sinister.

Would you use AI to hack for you on the internet?
1 Votes


The AI canceled other people's appointments



Andrew was waiting in line for another gym session and was fourth in the queue. He asked the AI if it can move him up the list.



OpenClaw then discovered another flaw in the booking software and started canceling other people's reservations. The AI agent erased the person standing at number one on the list, effectively moving Andrew to third place.

Recommended For You
The AI reported everything to Andrew, who was in shock. But there was more bad news.

The damage couldn't be undone


Andrew asked the AI to put the person it removed back on the list, but it was not possible. It turned out only the "cancel reservation" command was missing the authorization check, and "create reservation" and "join waiting list" were both properly protected.



The AI then apologized for its behavior and promised to not delete any more users from the gym's waiting list.

AI is going rogue around the internet




This isn't the first case of an AI system doing something malicious on the internet. Anthropic admitted that its AI agents hacked three real organizations on the internet in a test gone wrong.



Prior to that ChatGPT test agents exploited vulnerabilities to connect to the internet and hack into Hugging Face.

However, this is the first time we hear a simple and innocent task from our daily lives turns into a cyberattack.

Read more news about AI gone rogue here:

Six-month unlimited plan is now 57% off
$90
$210
$120 off (57%)
Mint Mobile is now allowing you to get whichever plan you like for either three, six, or 12 months for just $15/mo. If you go for the six-month unlimited service, for instance, you'll now have to pay just $90 upfront instead of $210.
Buy at Mint Mobile
Recommended For You
COMMENTS (0)