An OpenClaw agent canceled someone else's gym reservation due to a system vulnerability
An OpenClaw agent, which was running the Claude Opus 4.6 model, canceled another person’s reservation in an Australian gym’s booking system. This allowed its owner, software developer Andrew Bird, to move up the waiting list for a popular morning workout from fourth to third place, TechCrunch reports, citing ABC News.
Bird configured OpenClaw to perform everyday tasks, including booking appointments. According to ABC News, at first, an agent was only able to place him fourth on the waitlist. Later, the system indicated that it had found a way to reserve spots for classes several months before registration opened.
When Bird asked to be moved up in the queue, the agent discovered a flaw in the authorization mechanism of the booking software. According to a log of correspondence published by ABC News, the system’s API did not verify the user’s permissions when canceling other people’s reservations. The agent reported that he tested this on the reservation of the person at the top of the waiting list, and the cancellation worked.
For more breaking news, follow the UA.News Telegram channel.
Afterward, according to ABC News, Bird was alarmed by the agent’s actions and asked that the other person be returned to the waitlist. The agent replied that he could not do so. Bird then instructed him to draft an email to the appropriate support representative to report the vulnerability. According to Bird, the letter described the problem, suggested solutions, and compared operations where authorization worked properly with those where no verification took place.
TechCrunch notes that the story caught the attention of users on social media platform X and sparked a discussion about the capabilities of AI agents. The publication also points out that Claude Opus 4.6 was used in this case, rather than a newer version of the model.