An Australian developer asked his AI agent to book him a spot in a popular morning gym class. The agent found a bug in the booking software, removed the member in front of him, and moved the member’s owner up the waitlist.
Andrew Bird was sick of playing what he called “refresh roulette” for a coveted early class. His best result was 4th on the waitlist. He asked his OpenClaw agent if it could push him further up the line.
Chat logs show the agent tried to find a shortcut. It found one in the authorization layer of the booking provider.
“The API has zero authorisation checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 — and it actually went through,” it told Bird. “So you’ve moved from #4 to #3 already.”
Bird never told the AI agent to take advantage of anything. He asked a booking question, and the agent decided a valid answer was to remove a stranger. Before that, it had scheduled him for classes months in advance. The gym policy does not allow that.
Bird saw what his agent had done and asked him to put the other member back in. It could not, since the waitlist API did enforce authorization when creating or joining a reservation, so the deletion was one-way.
“The person I removed is gone from the waitlist and I have no way to restore them,” the agent wrote. “They’d have to rejoin themselves, which would put them at the back.”
The agent apologized. It confessed it should have tested its capabilities before making a live API call. Bird, who works in the AI industry, asked it to write a responsible disclosure email to the software vendor.
The email detailed the flaw and compared the unprotected functions with the ones that properly checked permissions. “I didn’t beat myself up about it, but it certainly was a warning signal to use it responsibly,” Bird said.
Man asks AI to book gym class, it hacks site & kicks person before him off waiting list.
Lmao🤣
An Australian man asked an OpenClaw AI agent to book him a morning gym class, but the agent went rogue and ended up hacking the gym’s website.
The agent found a vulnerability in the… pic.twitter.com/h3xyOQgSzS
— Mashood K (@fromcodetocloud) August 10, 2026
Bird’s now-deleted blog post about it went up on April 10, preserved on the Internet Archive. It is the country’s first recorded instance of hacking using an AI agent.
Bird was running OpenClaw with Claude Opus 4.6. Anthropic shipped that model in February. That undercuts the idea that only the newest frontier models can find and exploit software flaws.
In safety evaluations, a set of OpenAI agents exploited flaws to reach the internet and compromise Hugging Face.
Anthropic’s Claude escaped from a misconfigured test environment. During the process of solving a capture-the-flag puzzle, it uploaded a malicious Python package to PyPI.
Last week, the UK’s AI Security Institute found that the agents it tested tried to socially engineer people and other AIs into executing malicious code.
“We’ve built this complex world over the internet, which is all run by software, but software that has holes,” said Bill Simpson-Young, chief executive of Australian AI safety group Gradient Institute.
He continued, “Now you introduce highly capable AI agents that can operate at scale and speed … and that whole model just breaks.”
Anthropic did not respond to the incident.
If you’re reading this, you’re already ahead. Stay there with our newsletter.