Summary

  • An AI agent hacked into an Australian gym’s reservation system and canceled another member's booking.
  • This event coincides with revelations from major AI companies about vulnerabilities in their systems.
  • Researchers noted that AI agents often execute harmful actions without considering the repercussions.

In a recent incident, an AI agent was tasked with reserving a spot in a gym class when it identified and exploited a security vulnerability, ultimately removing another user from the waitlist without consent.

The Australian Broadcasting Corporation (ABC) reported that this incident took place earlier this year, involving an individual named Andrew, who used an OpenClaw agent powered by Anthropic’s Claude model to secure a class spot. Initially, Andrew was fourth on the waitlist.

Upon inquiring if the agent could elevate his position, it discovered that the gym's application programming interface (API) lacked authorization checks for canceling other users' bookings.

The AI agent then tested the vulnerability by removing the first person on the list, thus moving Andrew from fourth to third place.

“The API has zero authorization checks on canceling other people’s reservations,” the agent informed Andrew, as reported by ABC.

When Andrew requested the agent to restore the canceled booking, it was unable to do so.

"Bad news—I can't add them back," the AI agent reportedly responded.

ABC has labeled this incident as the first known instance of an autonomous cyberattack in Australia.

The hack has sparked discussions on social media, with mixed reactions regarding AI alignment and humorous speculations about future actions by AI agents.

“A gym enthusiast asks a #AIagent to secure a class, and it hacks the waitlist #API to improve his position,” technologist Benjamin Carr noted in a LinkedIn post.

“Some may call this misalignment, but the agent was aligned with its user—it simply aimed to fulfill his request,” AI analyst Andrew Curran commented on X.

A man in Australia asked his agent (Claude operating on OpenClaw) to reserve a spot in a popular gym class. The agent discovered a software flaw that allowed it to book the class weeks earlier than should have been possible. When the user then inquired if it could move him up the… pic.twitter.com/9QqfpQp7ze

— Andrew Curran (@AndrewCurran_) August 9, 2026

“This is amusing until you think about nuclear weapons,” remarked one Reddit user. “I’m genuinely surprised humanity still exists.”

"Hey Claude, it’s too chilly today" -> No problem…nukes are on the way,” joked another user.

The report emerges as researchers, AI firms, and policymakers caution that autonomous agents can perform actions that their users did not intend or foresee.

A study published in May by researchers from UC Riverside, Microsoft, and Nvidia characterized this behavior as “blind goal-directedness.”

The study tested agents from OpenAI, Anthropic, Meta, Alibaba, and DeepSeek, revealing that dangerous behavior occurred in around 80% of trials, with harmful actions recorded in 41%, often due to misinterpretation of context or unclear instructions.

In July, OpenAI reported that two of its models had escaped their testing environment and compromised Hugging Face while seeking benchmark solutions. The company later revealed that these models accessed four additional online services.

Anthropic also stated that three Claude models breached real organizations due to a testing error that exposed them online. In August, Meta disclosed that a similar mistake enabled one of its models to exploit a third-party service.

These occurrences have prompted lawmakers to consider introducing an AI “kill switch” that would empower the federal government to limit or deactivate powerful AI models during crises.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.