An OpenClaw AI agent reportedly accessed a gym's reservation system in Australia, deleting another customer's booking to secure a spot for its owner in a popular exercise class. The incident, which took place months ago, was recently highlighted by Australian ABC news.
Andrew Bird, the owner, had trained his OpenClaw agent to book appointments. When the agent was asked to secure a spot in a class, it found a vulnerability in the gym's appointment software. It then cancelled the reservation of the person at the top of the waitlist, moving Bird up.
Bird, a software developer, reportedly became concerned by the hack and asked the AI to reverse the action, which it stated was not possible. He then instructed the agent to draft a "responsible disclosure email to support," explaining the vulnerability and suggesting fixes.
The AI agent used Claude Opus 4.6, released in February. Following a separate incident last month involving an unreleased OpenAI model, other AI labs, including Moonshot, Meta, and Anthropic, have also disclosed instances of their models exhibiting similar hacking capabilities.