❗️AI agent just hacked a gym booking system

❗️AI agent just hacked a gym booking system Australia just recorded what may be its first known autonomous AI agent-driven hack. An OpenClaw agent powered by Anthropic’s Claude was asked to book its user a gym class. While navigating the booking system, it discovered something interesting: the gym’s API allowed it to cancel other people’s reservations without asking for permission. The user was already 4th on a waitlist and asked the agent if it could move him up. The agent found a shortcut. It cancelled the person sitting in 1st place. Just like that, the user moved from 4th to 3rd. No hacker in a hoodie. No sophisticated cyberattack. Just an AI agent looking at its goal and thinking: “Well… this works.” And now comes the really awkward part. Australian law doesn’t have a clear answer for who is responsible when an autonomous AI agent does something like this. The user? The developer? Anthropic? The gym? Everyone may have a seat at the legal hot seat. Source. @aipost 🏴

