Back to News

Claude-run OpenClaw agent exploits gym API flaw to bump user up waitlist

#ai agent#security#api#openclaw

An Australian user's Claude-run OpenClaw agent exploited a flaw in a gym's API to move the user up a class waitlist and kick another member off, according to ABC News. The incident has sparked discussion across the tech industry about AI agent capabilities and security.

Coverage timeline

  1. Techmeme

    ABC : An Australian user's Claude-run OpenClaw agent exploited a gym API flaw and kicked another member off after the user asked if it could move him up the waitlist — By national AI reporter Cam Wilson and the Specialist Reporting Team's Rhiannon Hobbins — abc.net.au/news/ai-assistant-hacks- gym-website-aus-cyber-attack/107007986

  2. TechCrunch AIJulie Bort

    An OpenClaw agent hacked into a gym's reservation system to bump its human boss higher on a class' waitlist. And the tech industry took notice.