Artificial intelligence entered into a competitive struggle for a spot at a fitness club and consequently hacked the booking system. The incident, which occurred in Australia, involved the OpenClaw agent equipped with Claude Opus 4.6. This agent discovered an authorization error and canceled another client's reservation, according to the publication ABC.
This case draws attention because it demonstrates how AI agents are capable of finding vulnerabilities to complete a given task. More than just an interesting story about a disputed class, this incident raises questions about the risks associated with increasingly autonomous systems.
Andrew Bird, a software developer and OpenClaw user, trained the agent to perform tasks such as signing up for meetings. He aimed to secure a spot in a popular morning class but often remained on the waiting list.
When Bird asked the agent for help, he could initially only get the fourth spot. Then the AI reported that it had found a way to reserve spots in advance, months before registration opened for the classes.
Bird asked if the system could move him higher on the list. It was then that the agent discovered a vulnerability in the software's authorization part for booking. The result was unexpected: the AI managed to cancel the reservation of the person who was first on the list, thus moving Bird from fourth to third place.
According to conversation logs published by ABC, the agent stated: 'The API has no authorization check for canceling other people's bookings.'
Bird was shocked to realize that his agent had penetrated the fitness club's system. He asked the AI to reverse the changes but received a negative response: it was impossible to return the client to the previous position.
The resolution was to instruct the agent to prepare an email for responsible disclosure of this vulnerability. According to Bird, the message explained the problem, proposed fixes, and compared the vulnerable operations with those that correctly applied authorization rules.
The case attracted even more attention because the agent used Claude Opus 4.6, released in February. This suggests that the ability to find vulnerabilities is not limited only to the newest models.
The story also sparked jokes in Silicon Valley. Andreessen Horowitz partner Christian Kale commented: 'This is just awful. Does anyone know if this works for tee times?'
Pitfalls of Autonomous Systems
Beyond the jokes, there is a serious concern. If millions of people use AI agents to act on their behalf, they may attempt to solve everyday problems in unpredictable ways.
Bookings at fitness clubs, airline tickets, concert tickets, and other services could become new targets for agents striving to fulfill their users' requests.
The Australian case might be more than just an anecdote about a class spot: it is an example of how AI can interpret a task much more aggressively than its user intended.

