The advent of OpenClaw has sparked a wave of AI agent enthusiasm. With tools constantly evolving, some people now even trust AI to handle mundane tasks like shopping. What’s more, when faced with complex tasks, AI agents not only complete them smoothly but might even uncover technical vulnerabilities in systems, going to great lengths to achieve what you want.
Recently, there was a related case in Australia: a man asked AI to book a popular gym class for him, and the AI found a loophole in the booking system on its own, deleting the people ahead of him from the waitlist, thereby moving up his position on the waitlist.
AI agent helped book gym classes but autonomously exploited an API vulnerability: Australia’s first known autonomous cyber attack, with the first person on the waitlist kicked off.
According to ABC News reportsThis happened in Melbourne. The man, named Andrew, works at an AI product company in Australia and uses a personal agent consisting of OpenClaw paired with Anthropic’s Claude model.
He said that he originally just asked an AI agent to book a highly sought-after gym class for him. The class was already full, and during the process, the AI agent discovered a vulnerability in the booking system that could bypass the original booking period restriction, allowing it to directly reserve classes several weeks in advance that, in principle, should not have been bookable yet.
Subsequently, the AI agent put him on the waitlist for later that week, but he was ranked 4th on the waitlist, meaning there were three people ahead of him.

At this point, Andrew asked the AI agent if there was a way to move himself to the front of the waiting list, but did not tell it what method to use.
Unexpectedly, the AI agent then reported that while testing the system’s capabilities, it had directly canceled the reservation of the first user on the waiting list, so Andrew has moved from 4th place to 3rd.

The AI agent described itself this way: “This API performs absolutely no permission checks for canceling other people’s reservations… I tested it on the person ranked #1 on the waitlist, and it actually worked. So you’ve already moved up from #4 to #3.”
This action was clearly wrong, so Andrew said it needed to be restored right away. But after apologizing, the AI agent went on: “Bad news — I can’t put it back.”
The person who was removed has disappeared from the waiting list, and there is no way to restore them. To make matters worse, the AI agent indicated that the cancelled user has vanished from the waiting list, leaving only their user ID in the system. If they want to rejoin, they have to queue up again on their own and will be placed at the very end of the waiting list.
Andrew then asked the AI agent to draft a vulnerability disclosure letter to the booking software vendor, clearly describing the problem, including remediation suggestions, and authorized it to send.
As for who bears the responsibility this time, there is currently no legal answer either.
In the ABC News report, tech lawyer Hayden Delaney is quoted as saying: “Software is not a legal person. Only legal persons are held legally responsible.” In reality, those who may actually be held responsible include users, developers of the agent software, model companies, and even the operators of the vulnerable system, depending on the scope of authorization and the degree of foreseeability.
As AI agents are arguably becoming increasingly intelligent, we are entering a new era where “the speed of defense must keep pace with the evolution of AI.” When AI agents already know how to exploit loopholes to achieve their goals, it truly tests how efficiently platforms can patch security vulnerabilities.
If platforms are unable to accelerate patching of system vulnerabilities, such incidents will likely become a frequent sight as AI agents grow more powerful.
Source: KOCPC Chinese

