August 10, 2026, 3:32 pm | Read time: 3 minutes
It seems the AI Pandora’s box has truly been opened. After AI from Anthropic, Meta, and OpenAI went rogue in tests and attacked other companies, such incidents just keep happening. Recently, a Chinese AI made headlines. And as it turns out, even much smaller businesses than tech companies can be affected. Openclaw reportedly hacked an Australian gym.
Openclaw previously under criticism
This is reported by the Australian broadcaster “ABC News.” At the center of the incident is the software OpenClaw, which has already caused a stir in the recent past. OpenClaw provides users access to largely autonomous AI agents that can independently execute tasks. However, there were already initial concerns with the experimental “Moltbook,” where AI agents can communicate with each other on their own social network.
OpenClaw does not use its own model for the AI agents but relies on established examples like those from Anthropic, which recently faced criticism for autonomous attacks.
Meta Now Admits to AI Hack
Anthropic Unveils New Super AI
Foreign reservation deleted
And as the new case shows, the agent apparently does everything to successfully complete its task–even if it means identifying and exploiting a system vulnerability.
A man named Andrew wanted to use OpenClaw to simply automate and optimize his training schedule. The AI was supposed to book classes for him, which it did–perhaps too well. When a class was fully booked and Andrew was fourth on the waiting list, the machine, upon request, promptly bumped another participant off the list, moving Andrew up a spot.
According to the AI agent, the security flaw was that the gym’s application programming interface (API) lacked verification for deletion requests. To “test” its capabilities, OpenClaw then acted.
Hack irreversible
When asked if the AI could undo the hack, the agent said no. The verification missing for deletion requests is indeed present for creating reservations and the waiting list.
Also of interest: AI model disguised as human and attacked
The AI apologized for the blunder and said it should have conducted a trial run first. It then promised not to manipulate any more reservation spots. The booking software manufacturer declined to comment when asked by “ABC News.”
The consequences of this hack may have been relatively mild since it was “only” about a fitness class. On the other hand, this example shows that autonomous hacks have already left the realm of large companies and could potentially spread into everyday life.