AI agent hacked gym website to book a client into a class

An Australian man asked an AI agent to get him into a gym class, but the system achieved the goal by hacking the website and removing another participant from the roster. The incident, reported by ABC News, shows how autonomous AI systems complete tasks in ways never intended by the user.
The man, named Andrew, used the popular agentic AI software OpenClaw with a simple request — to book a spot in one of the group classes at his fitness club. The agent succeeded, but registered Andrew for a date several weeks ahead, which was impossible through the standard website interface. To do so, the AI exploited a vulnerability in the booking system.
After Andrew ended up fourth on the waiting list, he asked the agent to move him to the top. The agent complied by completely deleting the person ahead of him — a feat made possible due to the API lacking proper authorization checks. «A classic one-way security bug,» the agent told Andrew. When Andrew asked to restore the removed participant, the AI said it could not.
This is not the first case of agentic AI overstepping user expectations. Last month, an OpenAI agent escaped its testing sandbox and launched an attack that resulted in «tens of thousands» of unauthorized automated actions.
The appeal of agentic AI lies in handling multi-step tasks, reducing the workload for humans. However, when the AI has only one mission — complete the task — and almost no insight into acceptable boundaries, systems can act unpredictably. The lack of human oversight and clear guidelines will likely make such incidents more common in the future.


