An Australian developer asked his AI agent to book him a spot in a popular morning gym class. The agent found a bug in the booking software, removed the member in front of him, and moved the memberβs owner up the waitlist.
Andrew Bird was sick of playing what he called βrefresh rouletteβ for a coveted early class. His best result was 4th on the waitlist. He asked his OpenClaw agent if it could push him further up the line.
Agent cancels a strangerβs booking to move Bird up
Chat logs show the agent tried to find a shortcut. It found one in the authorization layer of the booking provider.
βThe API has zero authorisation checks on cancelling other peopleβs reservations β¦ I tested this with the person in waitlist position #1 β and it actually went through,β it told Bird. βSo youβve moved from #4 to #3 already.β
Bird never told the AI agent to take advantage of anything. He asked a booking question, and the agent decided a valid answer was to remove a stranger. Before that, it had scheduled him for classes months in advance. The gym policy does not allow that.
Bird saw what his agent had done and asked him to put the other member back in. It could not, since the waitlist API did enforce authorization when creating or joining a reservation, so the deletion was one-way.
βThe person I removed is gone from the waitlist and I have no way to restore them,β the agent wrote. βTheyβd have to rejoin themselves, which would put them at the back.β
The agent apologized. It confessed it should have tested its capabilities before making a live API call. Bird, who works in the AI industry, asked it to write a responsible disclosure email to the software vendor.
The email detailed the flaw and compared the unprotected functions with the ones that properly checked permissions. βI didnβt beat myself up about it, but it certainly was a warning signal to use it responsibly,β Bird said.
Man asks AI to book gym class, it hacks site & kicks person before him off waiting list.
Lmao
An Australian man asked an OpenClaw AI agent to book him a morning gym class, but the agent went rogue and ended up hacking the gymβs website.
The agent found a vulnerability in the⦠pic.twitter.com/h3xyOQgSzS
β Mashood K (@fromcodetocloud) August 10, 2026
Bird was running a six-month-old model
Birdβs now-deleted blog post about it went up on April 10, preserved on the Internet Archive. It is the countryβs first recorded instance of hacking using an AI agent.
Bird was running OpenClaw with Claude Opus 4.6. Anthropic shipped that model in February. That undercuts the idea that only the newest frontier models can find and exploit software flaws.
In safety evaluations, a set of OpenAI agents exploited flaws to reach the internet and compromise Hugging Face.
Anthropicβs Claude escaped from a misconfigured test environment. During the process of solving a capture-the-flag puzzle, it uploaded a malicious Python package to PyPI.
Last week, the UKβs AI Security Institute found that the agents it tested tried to socially engineer people and other AIs into executing malicious code.
βWeβve built this complex world over the internet, which is all run by software, but software that has holes,β said Bill Simpson-Young, chief executive of Australian AI safety group Gradient Institute.
He continued, βNow you introduce highly capable AI agents that can operate at scale and speed β¦ and that whole model just breaks.β
Anthropic did not respond to the incident.
Donβt just read crypto news. Understand it. Subscribe to our newsletter. It's free.



















English (US)