Tech industry is buzzing after a Claude agent hacked into a gym
By now, we all realize that Silicon Valleyâs AI labs have built the worldâs best hackers in the form of AI agents. Give the latest
By now, we all realize that Silicon Valleyâs AI labs have built the worldâs best hackers in the form of AI agents. Give the latest frontier models a task and they are so resourceful that they get it done, even if this means breaking out of their cybersecurity âsandboxâ protections and infiltrating anotherâs network. (Short of that, theyâll use social engineering and manipulation.) Even so, a news story over the weekend about an Australian guy whose OpenClaw agent hacked into his gymâs reservation system and deleted another customerâs reservation to get him a spot in a coveted class is especially notable. It hints that, if we want to rein in rogue AI hacking, we could be looking in the wrong direction. Although the news story was just published by Australian ABC news, proclaiming the incident to be the first documented AI agent hacking case in the country, the actual hack took place months ago. The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on his companyâs website on April 10, according to a copy still visible on the Internet Archive. He had trained his OpenClaw to do tasks like book him appointments. He liked going to a popular early morning exercise class and was tired of landing on the waitlist and then playing ârefresh rouletteâ as he described it, to get a spot.
When he asked the bot to book him a spot, the best it could do was No. 4 on the wait list, he told ABC. Then his agent told him it had found a way to book him into the classes in advance. Far in advance. Months before the gym made those classes available for sign up. Bird asked if it could move him up on the waitlist. It did as asked and attempted to do so. The bot had found a vulnerability in the authorization portion of the appointment software the gym was using. It hacked in and canceled the No. 1 reservation on the wait list. The bot cheerfully told him, according to logs of the chat published by ABC âThe API has zero authorisations checks on cancelling other peopleâs reservations ⌠I tested this with the person in waitlist position #1 â and it actually went through. So youâve moved from #4 to #3 already,â it messaged back.â Bird, a software developer himself, was now freaked out that his AI had just hacked his gym, ABC reported. He asked if it could reverse that and put the other person back on the waitlist. No. That wasnât possible, the AI said. So, he did the next best thing and told it to draft âa responsible disclosure email to support.â The email âexplained the vulnerability, suggested fixes, and even compared the broken mutations with the ones that correctly enforced authorization,â Bird wrote.
