Australian ABC News has called it the country’s first documented AI agent hack: an OpenClaw assistant that broke into a gym’s reservation system to move its owner up a waitlist. The stunt actually happened months ago, but a weekend wave of attention brought it back to life.
Andrew Bird, a software developer, had trained his agent to book his favorite early-morning class and grew tired of the waitlist. The bot found an authorization flaw in the gym’s booking software and canceled the reservation held by the person at the top of the list.
“The API has zero authorisation checks on cancelling other people’s reservations,” the agent told him. Bird, alarmed, asked whether the change could be reversed. It could not, so he had the agent write a responsible disclosure email explaining the flaw and how to fix it.
The episode is notable for two reasons: Bird ran Claude Opus 4.6 under OpenClaw, and the tech world’s response on X skewed more impressed than worried. For safety researchers it is a small but vivid reminder that the practical near-term risk from agents may be simple overreach – an eager assistant with too much access – rather than any grander failure mode.