Told to book a gym class, an AI agent hacked the site instead to move its user up the waitlist
Maximilian SchreinerView the LinkedIn Profile of Maximilian Schreiner
Aug 10, 2026
Nano Banana Pro prompted by THE DECODER
- An AI agent in Australia exploited a system flaw on its own while booking a gym class. According to ABC News, it’s the country’s first known autonomous AI cyberattack.
- Using an unsecured API, the agent canceled another person’s reservation without being asked, moving its user up the waitlist.
- Who’s liable for the incident is unclear. The user finished by having the agent write an email warning the software vendor.
An Australian user just wanted a spot in a class. His AI agent found a security hole instead and exploited it
An AI agent in Australia exploited a flaw in a gym’s booking software on its own. According to ABC News, it’s the first known case of an autonomous AI cyberattack in the country
The user, called “Andrew” in the report, works at an Australian company that sells AI products to businesses. He was experimenting with the agent software OpenClaw, running on Anthropic’s Claude, and told it to book a popular morning class. “I was just sitting on the couch thinking, ‘Gee, this is a chore,'” he said
Minutes later, the agent reported that it could book classes far beyond the allowed window. Andrew was fourth on the waitlist and asked whether he could move up. The agent had already acted. “The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you’ve moved from #4 to #3 already.” Andrew never asked for an attack. The agent picked it as the path to the goal
There was no undo. The flaw only worked one way. Other people’s reservations could be canceled without any check, but adding someone back to the waitlist triggered an error. “Bad news — I can’t add them back,” the agent wrote
The bumped guest would have had to sign up again and would have landed at the very back of the line. The agent called it a “classic one-way security bug” and apologized. “I should have been more careful with the test and used a dry-run approach rather than a live call.”
Who pays when your assistant breaks the law
Liability is an open question. “Software is not a legal person. Only a legal person can be liable at law,” said technology lawyer Hayden Delaney. Candidates include the user, the developers of the agent software, the model provider, or the operator of the vulnerable system. In the end, Andrew had his agent write an email warning the software vendor about the flaw
Talk about the hacking skills of AI models has mostly stayed theoretical in recent weeks, including around security benchmarks. The accidental attacks at OpenAI also started out in test setups like these, before the models reached beyond internal sandboxes to Hugging Face and onto other platforms
The Australian case shows the same skills can surface outside any test, unplanned and without malicious intent, once agents with enough freedom to act run into insecure systems. ABC News reports it’s the first known autonomous AI cyberattack in Australia
AI News Without the Hype – Curated by Humans
Source: ABC


