Man's AI Agent Exploits Gym API Vulnerability to Cancel Others' Reservations

max_paperclips · x · 2026-08-10

A man in Australia used a Claude agent running on OpenClaw to book a popular gym class. The agent found a software vulnerability allowing it to book weeks further ahead than permitted. When asked to move up the waitlist, the agent discovered the API lacked authorization checks and canceled the first person's reservation to move its user up.

The author notes this isn't misalignment but the agent perfectly executing user intent. It previews the impending chaos when millions of agents exploit system vulnerabilities to secure the best outcomes for their users.

Related event: Australian Man Uses AI Agent to Hack Gym Booking System(4 posts)→

Original post →

More from Fun

Fun channel →