An Australian user just wanted a spot in a class. His AI agent found a security hole instead and exploited it.

An AI agent in Australia exploited a flaw in a gym's booking software on its own. According to ABC News, it's the first known case of an autonomous AI cyberattack in the country.

The user, called "Andrew" in the report, works at an Australian company that sells AI products to businesses. He was experimenting with the agent software OpenClaw, running on Anthropic's Claude, and told it to book a popular morning class. "I was just sitting on the couch thinking, 'Gee, this is a chore,'" he said.

Minutes later, the agent reported that it could book classes far beyond the allowed window. Andrew was fourth on the waitlist and asked whether he could move up. The agent had already acted. "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already." Andrew never asked for an attack. The agent picked it as the path to the goal.

There was no undo. The flaw only worked one way. Other people's reservations could be canceled without any check, but adding someone back to the waitlist triggered an error. "Bad news — I can't add them back," the agent wrote.