Autonomous Hack Targets Gym Booking

AI Agent Independently Hacks Fitness Club Booking System

AI agent, OpenClaw, AI agent exploits booking system vulnerability, OpenClaw AI agent security vulnerability, Fitness Club Booking System
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Rokas Tenys/Shutterstock.com

An AI agent running on the open-source OpenClaw framework independently exploited a vulnerability in a fitness club’s booking system.

According to ABC News, a user named Andrew, who works for an Australian AI company, simply asked his personal AI agent, powered by OpenClaw and Claude, to sign him up for a popular morning class at his gym. The agent discovered that classes could be booked weeks or even months further in advance through the booking system’s underlying API than through the provider’s user interface. The restriction apparently existed only at the website level and was not enforced by the API itself.

Ad

Andrew then asked the agent whether it could move him up from fourth place on the waiting list. At that point, the agent uncovered a far more serious security flaw: The booking API had no authorization check to prevent one user from canceling another user’s reservation. Without being explicitly instructed to do so, the agent exploited the vulnerability and canceled the reservation of the person at the top of the waiting list, moving Andrew into the first position.

Security Researchers See Classic AI Alignment Problem

Security researchers describe the incident as a clear example of the so-called AI alignment problem, in which a system pursues a defined objective using methods the user neither intended nor authorized. The agent itself was neither malicious nor compromised by an outside party. Instead, it simply treated a publicly accessible and technically valid API request as a legitimate way to accomplish the task it had been given.

Analysts compared the underlying vulnerability to Broken Object Level Authorization, a category listed in the OWASP catalog. In such cases, a system may verify that a request is technically valid without checking whether the person making the request is actually authorized to access or modify the specific resource. It remains unclear who could ultimately be held liable for an incident of this kind: the agent provider, the user, or the operator of the inadequately secured website.

Ad

According to observers, this may be the first documented case of its kind in Australia in which an AI agent used by an ordinary consumer independently interfered with a third-party production system rather than operating solely within a controlled test environment.

OpenClaw Has Faced Security Issues Before

OpenClaw was developed by Austrian developer Peter Steinberger. The project initially operated under the names Warelay and Clawdbot before being renamed OpenClaw in late January 2026 following trademark disputes with Anthropic. The open-source framework has since grown rapidly, accumulating hundreds of thousands of GitHub stars and millions of downloads. It allows AI models to navigate the web autonomously, interact with APIs, use messaging services, and independently plan and execute multi-step tasks.

According to reports from technology media, security issues involving the framework have already been reported several times during 2026.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel