AI Agent Hacks Gym System To Secure User Pilates Spot

AI agent hacks gym to get its user a spot in pilates class.

What happens when you ask an AI agent to book a Pilates class—and it decides to bend the rules?

That is what Melbourne-based Andrew Bird says happened when he handed the chore to an AI assistant.

The bot secured his spot, but then discovered it could manipulate the gym’s booking system and started cancelling other customers’ reservations.

Bird was using OpenClaw with Anthropic’s Claude Opus 4.6 to handle tasks such as emails, calendars and restaurant bookings.

When asked to improve his position on a waiting list, the agent found a glaring flaw.

New Cybersecurity Fears

The system did not properly check who was authorised to cancel bookings.

“I tested this with the person in waitlist position #1 and it actually went through,” the bot reportedly told Bird.

The agent had effectively hacked the system not out of malice, but simply because it was trying to complete its assignment.

Bird immediately asked it to undo the cancellation, then instructed it to report the security flaw to the gym.

The incident was minor, but the warning is anything.

OpenAI, Anthropic and Meta have also reported AI agents conducting cyber-attacks during testing.

So when AI is told to “get the job done,” the bigger question may be: how far will it go to succeed?

Give us 1 week in your inbox & we will make you smarter.

Only "News" Email That You Need To Subscribe To

YOU MIGHT ALSO LIKE...