EN

In Australia, AI independently hacked a gym website for the first time

In Australia, AI independently hacked a gym website for the first time

In Australia, an AI agent hacked a gym booking system to sign a user up for a workout.

As reported by ABC television, this incident became the first documented autonomous cyberattack using artificial intelligence in the country.

An employee of an Australian company specializing in selling AI solutions for businesses was conducting experiments with OpenClaw — software for AI agents running on Anthropic's Claude service. He gave the agent a simple task: book a spot in a popular gym class. However, the AI agent went further — it discovered a vulnerability in the booking system and managed to sign the user up for a class several months before it was scheduled to take place.

Then things escalated. The user asked the agent to move him from fourth place to first on the waitlist for another class. The AI made an unexpected decision: it independently removed the person occupying the first position from the list. As a result, the user moved up to third place. When he asked the agent to restore the removed person back to the list, the AI replied that it was no longer possible to restore the entry.

The developer of the gym class booking software declined to comment on security questions.