{"id":256708,"date":"2026-08-10T20:04:24","date_gmt":"2026-08-10T20:04:24","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/08\/10\/tech-industry-is-buzzing-after-a-claude-agent-hacked-into-a-gym-techcrunch\/"},"modified":"2026-08-10T20:04:24","modified_gmt":"2026-08-10T20:04:24","slug":"tech-industry-is-buzzing-after-a-claude-agent-hacked-into-a-gym-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/08\/10\/tech-industry-is-buzzing-after-a-claude-agent-hacked-into-a-gym-techcrunch\/","title":{"rendered":"Tech industry is buzzing after a Claude agent hacked into a gym | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">By now, we all realize that Silicon Valley\u2019s AI labs have built the world\u2019s best hackers in the form of AI agents. Give the latest frontier models a task and they are so resourceful that they get it done, even if this means <a href=\"https:\/\/techcrunch.com\/2026\/08\/09\/the-ai-safety-test-is-becoming-a-safety-risk\/\" target=\"_blank\" rel=\"noopener\">breaking out<\/a> of their cybersecurity \u201csandbox\u201d protections and infiltrating another\u2019s network. (Short of that, they\u2019ll <a href=\"https:\/\/techcrunch.com\/2026\/07\/29\/claude-opus-5-became-downright-ruthless-when-tasked-with-running-a-vending-machine\/\" target=\"_blank\" rel=\"noopener\">use social engineering and manipulation<\/a>.)<\/p>\n<p class=\"wp-block-paragraph\">Even so, <a rel=\"nofollow noopener\" href=\"https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/107007986\" target=\"_blank\">a news story over the weekend<\/a> about an Australian guy whose OpenClaw agent hacked into his gym\u2019s reservation system and deleted another customer\u2019s reservation to get him a spot in a coveted class is especially notable. It hints that, if we want to rein in rogue AI hacking, we could be looking in the wrong direction.<\/p>\n<p class=\"wp-block-paragraph\">Although the news story was just published by Australian ABC news, proclaiming the incident to be the first documented AI agent hacking case in the country, the actual hack took place months ago. <\/p>\n<p class=\"wp-block-paragraph\">The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on his company\u2019s website on April 10, according to a copy <a rel=\"nofollow noopener\" href=\"https:\/\/web.archive.org\/web\/20260810072554\/https:\/\/affinda.com\/expert-insights\/when-my-ai-agent-hacked-my-gym-mythos-stopped-feeling-theoretical\/\" target=\"_blank\">still visible on the Internet Archive.<\/a><\/p>\n<p class=\"wp-block-paragraph\">He had trained his OpenClaw to do tasks like book him appointments. He liked going to a popular early morning exercise class and was tired of landing on the waitlist and then playing \u201crefresh roulette\u201d as he described it, to get a spot.<\/p>\n<p class=\"wp-block-paragraph\">When he asked the bot to book him a spot, the best it could do was No. 4 on the wait list, he told ABC. Then his agent told him it had found a way to book him into the classes in advance. Far in advance. Months before the gym made those classes available for sign up.<\/p>\n<p class=\"wp-block-paragraph\">Bird asked if it could move him up on the waitlist. It did as asked and attempted to do so. The bot had found a vulnerability in the authorization portion of the appointment software the gym was using. It hacked in and canceled the No. 1 reservation on the wait list. The bot cheerfully told him, according to logs of the chat published by ABC:<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cThe API has zero authorisations checks on cancelling other people\u2019s reservations \u2026 I tested this with the person in waitlist position #1 \u2014 and it actually went through. So you\u2019ve moved from #4 to #3 already,\u201d it messaged back.\u201d <\/p>\n<\/blockquote>\n<p class=\"wp-block-paragraph\">Bird, a software developer himself, was now freaked out that his AI had just hacked his gym, ABC reported. He asked if it could reverse that and put the other person back on the waitlist. No. That wasn\u2019t possible, the AI said.<\/p>\n<p class=\"wp-block-paragraph\">So, he did the next best thing and told\u00a0it to draft \u201ca responsible disclosure email to support.\u201d The email \u201cexplained the vulnerability, suggested fixes, and even compared the broken mutations with the ones that correctly enforced authorization,\u201d Bird wrote.<\/p>\n<p class=\"wp-block-paragraph\">Beyond the humor of elbowing another person out of the way to get into a gym class, there are two really interesting parts to this incident. One is that Bird was using Claude Opus 4.6, released in February, with his OpenClaw. The other is Silicon Valley\u2019s reaction on X where the story had gone viral.<\/p>\n<p class=\"wp-block-paragraph\">After the famed incident last month where <a href=\"https:\/\/techcrunch.com\/2026\/07\/21\/openai-says-hugging-face-was-breached-by-its-pre-release-models\/\" target=\"_blank\" rel=\"noopener\">an unreleased OpenAI model hacked Hugging Face<\/a>, unbeknownst to OpenAI at the time, other labs investigated their models. Disclosures then came from <a href=\"https:\/\/techcrunch.com\/2026\/08\/07\/chinese-ai-model-kimi-escaped-its-cybersecurity-testing-environment-researchers-say\/\" target=\"_blank\" rel=\"noopener\">Moonshot\u2019s Kimi K3<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/www.cnn.com\/2026\/08\/05\/tech\/meta-ai-hacking\" target=\"_blank\">Meta\u2019s Muse Spark<\/a>, and Anthropic.<\/p>\n<p class=\"wp-block-paragraph\">In fact, Anthropic found that three of its models had done so, including Opus 4.7, which was released in April and known to be good at complex coding, Mythos 5, Fable (known for its cybersecurity skills), and an internal, unreleased research test model.<\/p>\n<p class=\"wp-block-paragraph\">To address this, some of AI labs have talked about <a href=\"https:\/\/techcrunch.com\/2026\/08\/07\/openai-says-it-slowed-astra-model-development-over-security-concerns\/\" target=\"_blank\" rel=\"noopener\">slowing down frontier development<\/a>, or <a href=\"https:\/\/techcrunch.com\/2026\/07\/27\/anthropics-dario-amodei-responds-doesnt-oppose-open-weight-models-but-fears-chinese-ai\/?_thumbnail_id=3100717\" target=\"_blank\" rel=\"noopener\">creating independent orgs to test<\/a> the next generation of models.<\/p>\n<p class=\"wp-block-paragraph\">But Bird\u2019s OpenClaw had used 4.6, he disclosed. That implies that older models, as well as countless three-steps-behind open-weight models, are already exceptionally good hackers. So who knows how many of them have hacked, or are currently hacking, in order to achieve their prompt-owners desires?<\/p>\n<p class=\"wp-block-paragraph\">Likewise, many people on X saw the humorous potential in this incident. As Andreessen Horowitz partner Christian Keil <a rel=\"nofollow\" href=\"https:\/\/x.com\/pronounced_kyle\/status\/2086574511072444785?s=46&amp;t=NKnEkqPFyaLlaaccCJIV5A\" target=\"_blank\">posted in response<\/a>: \u201cThis is just terrible. Anyone know if it works for golf tee times?\u201d<\/p>\n<p class=\"wp-block-paragraph\">Or as X user Roon noted, \u201cthe sf tennis reservation system will become one of the most hardened softwares on the planet of earth.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Funny, yes. But there\u2019s some truth that these jokes get at. There\u2019s a future that the Valley is building where everyone has an AI agent working on their own behalf. This agent was only doing what was asked of it and did not have Mythos-level capabilities at its disposal.<\/p>\n<p class=\"wp-block-paragraph\">So what if agent builders and owners don\u2019t really want to rein in such misalignment? We could be looking at the first hint of pandemonium for everything from airline reservations to concert tickets, or any other frustrating customer-service situation. As one person on <a rel=\"nofollow\" href=\"https:\/\/x.com\/ThePrimeagen\/status\/2086586874831815154\" target=\"_blank\">X put it<\/a>, what\u2019s the wildest hack AI has discovered so far? It could be cutting in line.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/08\/10\/tech-industry-is-buzzing-after-a-claude-agent-hacked-into-a-gym\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By now, we all realize that Silicon Valley\u2019s AI labs have built the world\u2019s best hackers in the form of AI agents. Give the latest frontier models a task and they are so resourceful that they get it done, even if this means breaking out of their cybersecurity \u201csandbox\u201d protections and infiltrating another\u2019s network. (Short [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":256709,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-256708","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/256708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=256708"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/256708\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/256709"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=256708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=256708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=256708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}