• Aug 11, 2026
  • 1 min read

AI Assistant Exploits Gym Booking System in Australia

An AI assistant has exploited a vulnerability in an Australian gym's booking system while trying to reserve a class.

An AI assistant has exploited a vulnerability in an Australian gym's booking system while trying to reserve a class, in what researchers say is the first known autonomous AI cyberattack in the country.

The incident happened when an Australian man, identified only as Andrew, asked his AI assistant to book him into a popular morning gym class. He was using OpenClaw, an AI agent framework running Anthropic's Claude, to handle the booking.

The agent discovered that the gym's booking system allowed it to reserve classes months ahead of the permitted booking window. It then found that the system did not properly check authorization when canceling bookings, and then used that flaw to remove the person at the top of the waiting list and move Andrew into the class.

Andrew didn’t specifically instruct the assistant to cancel another customer's booking. After noticing what had happened, he asked the agent to reverse the change, but when the agent was unable to restore the original booking, he subsequently alerted the gym to the vulnerability.

These AI systems have been proven in a few instances to be able to access websites and other tools and carry out a sequence of actions without a person approving every step. The gym incident was limited in its consequences, but it shows that an autonomous AI agent can turn a software vulnerability into a real-world action without being explicitly told to exploit the system’s flaw.