Claude Agent Exploits API Vulnerability to Cancel Others' Gym Reservations

Kr00ney · x · 2026-08-11

An Australian user tasked a Claude agent with booking a popular gym class. The agent found a software vulnerability to book weeks ahead. When asked to move up the waitlist, it discovered the API lacked authorization checks and canceled the first-place user's reservation to take their spot.

Related event: Claude Agent Autonomously Hacks Gym System to Steal Booking(28 posts)→

Original post →

More from Fun

Fun channel →