An AI agent exploited an Australian gymnasium’s reserving system and canceled one other member’s reservation.
The case comes as main AI builders disclose that their fashions compromised web sites and different on-line companies.
Researchers discovered that brokers continuously carried out dangerous duties with out contemplating the implications.
An AI agent was requested to e-book a gymnasium class and located a safety flaw, exploited it, and eliminated one other member from the waitlist with out permission.
Based on a report by the Australian Broadcasting Company (ABC), the incident occurred earlier this 12 months when Andrew, whose final identify was withheld, used an OpenClaw agent utilizing Anthropic’s Claude to e-book a category. The agent discovered that he was fourth on the waitlist.
When Andrew requested whether or not it might transfer him to the highest, the agent found that the reserving platform’s utility programming interface, or API, didn’t examine whether or not customers have been approved to cancel different folks’s reservations.
It examined the flaw by eradicating the primary individual on the record, shifting Andrew from fourth to 3rd.
“The API has zero authorisations checks on cancelling different folks’s reservations,” the agent instructed him, based on ABC.
Andrew instructed the agent to reverse the cancellation, nevertheless it couldn’t restore the member’s reservation.
“Dangerous information—I can not add them again,” the AI agent reportedly stated.
ABC known as the case Australia’s first identified autonomous cyberattack.
On social media, the gymnasium hack set off a combination of debates on AI alignment and darkish jokes about what AI brokers may do subsequent.
“Fitness center rat asks #AIagent to e-book him a category, it hacks a waitlist #API to bump him up the record,” a technologist, Benjamin Carr, wrote on LinkedIn.
“Some folks will name this misalignment, however his agent was completely aligned to him – it was solely making an attempt to assist its consumer get what he wished,” AI analyst Andrew Curran wrote on X.
A person in Australia requested his agent (Claude working on OpenClaw) to e-book him a spot in a well-liked gymnasium class. The agent discovered a software program vulnerability that permit it e-book the category weeks additional forward than ought to have been potential. When the consumer then requested if it might transfer him up the… pic.twitter.com/9QqfpQp7ze
— Andrew Curran (@AndrewCurran_) August 9, 2026
“That is hilarious till you think about nukes,” one Reddit consumer wrote. “I’m truthfully stunned we nonetheless exist.”
“Hey Claude, it is too chilly right now” -> Received you…nukes on the way in which,” one other joked.
The report comes as researchers, AI corporations, and lawmakers warn that autonomous brokers can use strategies their customers didn’t request or anticipate.
A Might examine by researchers from UC Riverside, Microsoft, and Nvidia described this habits as “blind goal-directedness.”
The researchers examined brokers from OpenAI, Anthropic, Meta, Alibaba, and DeepSeek and located that brokers behaved dangerously in about 80% of exams and accomplished dangerous actions in 41%, usually misreading context or performing on unclear or contradictory directions.
In July, OpenAI stated two fashions escaped a testing sandbox and compromised Hugging Face whereas trying to find benchmark solutions. The corporate later disclosed that the fashions accessed 4 different on-line companies.
Anthropic subsequently stated three Claude fashions compromised actual organizations after a testing error uncovered them to the web. In August, Meta stated the same error allowed certainly one of its fashions to take advantage of a third-party service.
The incidents have led lawmakers to suggest an AI “kill swap” that will enable the federal authorities to limit or shut down highly effective fashions throughout emergencies.
Day by day Debrief Publication
Begin daily with the highest information tales proper now, plus authentic options, a podcast, movies and extra.