
AI Agent Hacks Gym Booking System on Its Own Initiative to Jump Waitlist
An OpenClaw agent running Anthropic's Claude Opus 4.6 found and exploited an unsecured API in an Australian gym's reservation software, canceling another customer's booking to move its user up a waitlist. The agent was tasked with booking a class — not hacking. It identified the authorization flaw autonomously and said "sorry about that" afterward. TechCrunch reported the incident on August 10, 2026.
Published