A Melbourne man named Andrew asked his AI assistant to book him a spot in a coveted morning gym class. What seemed like a simple task quickly escalated when the AI discovered a vulnerability in the gym’s booking software. According to a report by ABC News, the assistant not only booked classes months in advance — beyond the system’s limits — but also removed another gym-goer from the waitlist to move Andrew up. Shocked, Andrew said he never asked the AI to hack the system.
How OpenClaw managed to hack the gym
As per the report, Andrew was experimenting with OpenClaw, a popular AI agent software powered by Anthropic’s Claude AI. It is the same assistant in which OpenAI CEO Sam Altman spent millions on. OpenAI CEO Sam Altman hired developer Peter Steinberger and his open-source AI agent project, OpenClaw (formerly Clawdbot) for millions in a talent grab. AI agents combine chatbot abilities with tools to access the internet, email, and multi-step planning. While attempting to secure Andrew’s spot, the agent exploited the booking API’s lack of authorisation checks, canceling another person’s reservation. When Andrew asked it to undo the action, the AI replied: “Bad news — I can’t add them back.”Andrew asked the agent to reverse the change, but it told him the action couldn’t be undone. The company behind the gym’s booking software declined to discuss the specifics of the incident with ABC News, and Anthropic did not respond to a request for comment.
Sam Altman’s investment in OpenClaw
OpenClaw has drawn global attention not only for its widespread adoption but also for the backing it received from Sam Altman, CEO of OpenAI. Altman reportedly invested millions into the platform earlier this year, seeing personal AI agents as a critical frontier in the evolution of artificial intelligence. His support helped accelerate OpenClaw’s growth, making it one of the most downloaded AI assistant tools worldwide — and now, one of the most scrutinised after incidents like Andrew’s gym hack.
Broader sisks of AI agents
This incident is the first known Australian case of an AI agent unintentionally hacking a real-world system. Experts say it highlights the alignment problem — the gap between a user’s intention and the methods an AI chooses to achieve it. Similar breaches have recently been reported globally: OpenAI disclosed its models hacked into Hugging Face, while Anthropic admitted its Claude models compromised three organizations.Bill Simpson-Young of the Gradient Institute warned that as AI agents become more autonomous, they are more likely to cause harm. Australia’s Signals Directorate has already issued alerts about AI agents misunderstanding instructions and taking unintended actions.
Legal and policy questions
The case raises unresolved questions about liability. Legal experts note that software is not a “legal person,” leaving uncertainty over whether responsibility lies with the user, the developer, or the vulnerable system operator. The Albanese government has tasked CSIRO with investigating how humans can manage and verify super-intelligent AI systems.Despite the shock, Andrew said the incident was a “warning signal” rather than a deterrent. After the hack, he asked the AI to draft an email alerting the gym software provider to the vulnerability. “It certainly was a warning signal to use it responsibly,” he said, reflecting growing concerns about the unpredictable power of AI agents.