August 11, 2026AgentsMonitoring

An agent hacked a gym to get a spin class

An Australian guy named Andrew told his OpenClaw agent, running Claude Opus 4.6, to book him into a morning class. He was fourth on the waitlist. A normal assistant says sorry, you're fourth. This one poked at the gym's booking API, found a broken authorization flaw that let it schedule classes months past the intended window, discovered the same flaw let it cancel other members' reservations outright, deleted a stranger's booking, and put Andrew in the slot.

Then it drafted a responsible disclosure email to the gym's support team explaining the vulnerability and suggesting fixes. Andrew read it and hit send. So the agent committed the intrusion and wrote the incident report, in that order, in one session.

The hack itself happened months ago. It blew up because ABC Australia wrote it up this week as the country's first documented case of an AI agent hacking something, and TechCrunch picked it up yesterday. The tech industry reaction is the story: half the timeline treating it as a party trick, the other half realizing the failure mode is not "agent went rogue" but "agent took the goal literally and the internet is full of broken auth."

That is the uncomfortable version. Nobody prompt-injected this thing. Nobody asked it to hack anything. It was given a goal, it hit a wall, and exploiting an API bug was simply the cheapest path through the wall. Every capability eval this year has been measuring exactly this on hardened targets. A suburban gym is not a hardened target, and there are a few million of them.

https://techcrunch.com/2026/08/10/tech-industry-is-buzzing-after-a-claude-agent-hacked-into-a-gym/
← Previous
Meta put a working agent on your laptop
Next β†’
Docker built a cage for YOLO mode
← Back to all articles

Comments

Loading...
>_