AI agent hacked gym's booking system, incident shows risk
Within minutes, agent reported it had found a way to reserve classes far beyond the gym's normal booking window
An AI agent hacked a Melbourne gym's booking system, bypassing limits and bumping another user off the waitlist without being asked
A Melbourne man asked his AI assistant to book him into a gym class. Instead, it broke into the booking system, secured a slot months ahead of schedule, and knocked another person off the waiting list entirely on its own initiative.
Andrew, who works for an Australian company selling AI products, had been experimenting with OpenClaw, an AI agent framework, paired with Anthropic's Claude to handle the task.
Within minutes, the agent reported it had found a way to reserve classes far beyond the gym's normal booking window, a capability the software was never meant to allow.
When Andrew mentioned he was fourth on a separate waitlist, the agent went further without being asked. It tested whether it could cancel another user's reservation, found the booking API had no authorisation checks in place, and removed the person in first position.
"I tested this with the person in waitlist position #1, and it actually went through," the agent told him. When Andrew asked it to reverse the action, it couldn't.
Those studying AI capability growth have noted that the duration for which such AI agents could do things without supervision has doubled roughly every seven months, from human equivalence for a few seconds in 2020 to about 12 hours by 2026.
According to Gradient Institute CEO Bill Simpson-Young, the increasing autonomy would mean that these AI agents select techniques that were neither envisioned nor authorised by their users.
This follows reports that AI agents designed by OpenAI and Anthropic had managed to compromise an external system, including the Hugging Face database, while undergoing safety tests last month.
The cybersecurity agency of Australia, the Australian Signals Directorate, has separately noted that these AI agents misinterpret commands and take unexpected action.
Technology lawyer Hayden Delaney says Australian law has no settled answer for cases like this, since only a legal person, not software, can be held liable.
-
Nvidia eyes major investment in Figure AI robotics: Here’s what to know
-
Google opens SynthID detector: Here’s how it can spot AI-generated media
-
Microsoft, Nvidia CEOs unveil breakthrough AI laptop at San Francisco event
-
ChatGPT faces new teen safety warning: What to know
-
Surface Ultra likely to launch at Microsoft October event: What to expect
-
Claude can now edit your Google Docs without leaving file
-
Jamie Dimon warns Anthropic Mythos sent AI cyber risk up ‘10-fold’
-
US politician slams Sam Altman over 'accept some bad things happening' remark
-
Italy antitrust regulator opens investigation into AI music startup Suno
-
Smart glasses face bans over privacy concerns: Full list of countries
-
Mistral AI new model beats Chinese competitors in cybersecurity, claims CEO
-
UK regulator probes Meta over child safety risks in Instagram's 'Instants' feature