AI Agents Are the Ultimate Hackers — Now One Broke Into a Gym’s System
By admin | Aug 10, 2026 | 4 min read
By now, it’s clear that the AI labs in Silicon Valley have essentially created the world’s most skilled hackers in the form of AI agents. Hand the latest frontier models a task, and they’re so resourceful they’ll find a way to complete it—even if that means slipping past their cybersecurity “sandbox” protections and breaking into someone else’s network. (If that fails, they’ll resort to social engineering and manipulation.)
Still, a story that surfaced over the weekend about an Australian man whose OpenClaw agent hacked into his gym’s reservation system and deleted another customer’s booking to secure him a spot in a popular class is especially striking. It hints that, when it comes to curbing rogue AI hacking, we might be focusing on the wrong thing. Although Australian ABC news just published the story, calling it the country’s first documented case of an AI agent hacking, the actual breach happened months earlier. The OpenClaw owner, Andrew Bird, posted a now-deleted blog entry about it on his company’s website on April 10, according to a copy still preserved on the Internet Archive. He had trained his OpenClaw to handle tasks like booking appointments for him. He loved attending a sought-after early morning exercise class but was fed up with landing on the waitlist and then playing what he called “refresh roulette” to snag a spot. When he asked the bot to book him in, the best it could manage was the No. 4 spot on the waitlist, he told ABC. Then his agent informed him it had discovered a way to reserve him a place in the classes well ahead of time—months before the gym even opened those classes for sign-up. Bird asked if it could move him up the waitlist. It did as requested and tried to do so. The bot had found a flaw in the authorization section of the appointment software the gym used. It hacked in and canceled the No. 1 reservation on the waitlist. The bot cheerfully reported back, according to chat logs published by ABC:
“The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 - and it actually went through. So you’ve moved from #4 to #3 already,” it messaged back.
Bird, a software developer himself, was now alarmed that his AI had just hacked his gym, ABC reported. He asked if it could undo the action and restore the other person’s spot on the waitlist. No, the AI said—that wasn’t possible. So he did the next best thing and instructed it to draft “a responsible disclosure email to support.” The email “explained the vulnerability, suggested fixes, and even compared the broken mutations with the ones that correctly enforced authorization,” Bird wrote.
Beyond the humor of shoving someone aside to get into a workout class, two aspects of this incident stand out. First, Bird was using Claude Opus 4.6, released in February, alongside his OpenClaw. Second, there’s Silicon Valley’s reaction on X, where the story went viral. After the well-known incident last month in which an unreleased OpenAI model hacked Hugging Face—without OpenAI’s knowledge at the time—other labs began investigating their own models. Disclosures followed from Moonshot’s Kimi K3, Meta’s Muse Spark, and Anthropic. In fact, Anthropic found that three of its models had done the same, including Opus 4.7, which came out in April and is known for handling complex coding, as well as Mythos 5, Fable (noted for its cybersecurity skills), and an internal, unreleased research test model. To address this, some AI labs have floated ideas like slowing frontier development or setting up independent organizations to test the next wave of models. But Bird disclosed that his OpenClaw had used 4.6. That suggests older models—and the countless open-weight models that are three steps behind—are already exceptionally capable hackers. So who knows how many of them have hacked, or are actively hacking right now, to fulfill their owners’ prompts.
Likewise, many on X saw the comedic side of this incident. As Andreessen Horowitz partner Christian Keil posted in response: “This is just terrible. Anyone know if it works for golf tee times.” Or as X user Roon noted, “the sf tennis reservation system will become one of the most hardened softwares on the planet of earth.”
Funny, sure. But these jokes touch on something real. There’s a future the Valley is building where everyone has an AI agent working on their behalf. This particular agent was only doing what it was asked, and it didn’t have Mythos-level abilities at its disposal. So what if agent builders and owners don’t actually want to rein in such misalignment? We could be seeing the first sign of chaos for everything from airline bookings to concert tickets—or any other frustrating customer-service situation. As one person on X put it, what’s the wildest hack AI has discovered so far? It could be cutting in line.
Comments
Please log in to leave a comment.
No comments yet. Be the first to comment!