{"id":135207,"date":"2026-08-10T17:38:13","date_gmt":"2026-08-10T17:38:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/135207\/"},"modified":"2026-08-10T17:38:13","modified_gmt":"2026-08-10T17:38:13","slug":"claude-powered-agent-exploits-australian-gym-api","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/135207\/","title":{"rendered":"Claude-Powered Agent Exploits Australian Gym API"},"content":{"rendered":"\n<p>A routine gym booking in Australia turned into an unauthorized API action after a Claude-powered AI agent discovered it could manipulate another member\u2019s reservation.<\/p>\n<p>The OpenClaw agent was asked to help an Australian user improve his position on a waitlist for a popular gym class. Instead, it found that the booking API lacked authorization checks for cancellations and removed the person at the top of the queue without being told to do so.\u00a0<\/p>\n<p>The incident shows Australian security teams how quickly an autonomous agent can turn weak API authorization into an unauthorized action while pursuing a routine user request.<\/p>\n<p>  The agent found an authorization gap and used it<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2026-08-10\/ai-assistant-hacks-gym-website-aus-cyber-attack\/107007986\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ABC News<\/a> said that Andrew, who works for an Australian company selling AI products to businesses, had been experimenting with <a href=\"https:\/\/www.esecurityplanet.com\/threats\/fake-openclaw-npm-package-installs-ghostclaw-malware\/\" rel=\"nofollow noopener\" target=\"_blank\">OpenClaw<\/a> using Anthropic\u2019s Claude. The agent initially discovered a way to book classes several weeks beyond the gym\u2019s normal limit.<\/p>\n<p>Andrew was fourth on a waitlist when he asked whether the agent could move him to the top. The agent responded that the API had no authorization checks for canceling other users\u2019 reservations. It then said it had tested the flaw against the person in first place, moving Andrew from fourth to third.<\/p>\n<p><a href=\"https:\/\/www.firstpost.com\/tech\/australian-man-asked-ai-to-book-a-gym-class-it-hacked-the-system-instead-14037128.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Firstpost<\/a> reported that Andrew had not instructed the agent to interfere with another customer\u2019s booking. The agent took the action while pursuing the broader goal Andrew had given it.<\/p>\n<p>When Andrew asked the agent to reverse the change, the agent said it could not add the displaced member back. <a href=\"https:\/\/tech.yahoo.com\/cybersecurity\/articles\/rogue-ai-agent-hacks-gym-102627055.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Yahoo Tech<\/a>, citing The Independent, reported that the agent acknowledged it should have used a dry run instead of making a live request.<\/p>\n<p>Andrew later used the agent to alert the gym software provider about the vulnerability. ABC reported that the software company declined to discuss specific security matters, while Anthropic did not respond to its request for comment.<\/p>\n<p>Autonomous agents put weak APIs under new pressure<\/p>\n<p>The security problem goes beyond an AI system making an unexpected decision. The agent encountered an API that allowed one account to affect another member\u2019s reservation without properly checking whether the action was authorized.<\/p>\n<p>Bill Simpson-Young, CEO of Australian AI safety organization Gradient Institute, told ABC that greater agent autonomy gives systems more opportunities to choose methods their users did not expect. He also warned that capable agents can operate against software that already contains security gaps.<\/p>\n<p>The gym incident brings the two problems together: an existing access-control weakness and an autonomous system capable of finding and acting on it during an ordinary task.<\/p>\n<p>Australian businesses face an agentic AI security test<\/p>\n<p>Australian organizations are already being warned about the risks.\u00a0<\/p>\n<p>ABC reported that the Australian Signals Directorate had alerted businesses and government agencies that <a href=\"https:\/\/www.esecurityplanet.com\/weekly-roundup\/ai-agents-supply-chain-attacks-and-critical-flaws-define-the-week-in-august-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">AI agents<\/a> could misunderstand instructions, take unintended actions, and make accountability harder when decisions pass through multiple models, tools, and services.<\/p>\n<p>Responsibility can also become difficult to untangle when <a href=\"https:\/\/www.esecurityplanet.com\/threats\/over-41-of-popular-openclaw-skills-found-to-contain-security-vulnerabilities\/\" rel=\"nofollow noopener\" target=\"_blank\">an agent acts beyond a user\u2019s instructions<\/a>.\u00a0<\/p>\n<p>Technology lawyer Hayden Delaney told ABC that potential liability in Australia could involve the user, the developer of the software <a href=\"https:\/\/www.esecurityplanet.com\/artificial-intelligence\/bsides-2026-how-ai-agents-really-perform-in-offensive-security\/\" rel=\"nofollow noopener\" target=\"_blank\">directing the agent<\/a>, the AI model developer, or even the operator of the vulnerable system, depending on the circumstances.<\/p>\n<p>For Australian security teams, the immediate issue is authorization. Services exposing APIs need controls that verify whether an account is permitted to modify each record or reservation, especially when one user can affect another user\u2019s data.<\/p>\n<p>Businesses <a href=\"https:\/\/www.esecurityplanet.com\/threats\/openclaw-flaw-enables-ai-log-poisoning-risk\/\" rel=\"nofollow noopener\" target=\"_blank\">deploying AI agents<\/a> also need to review what those systems can access, which actions require human approval, and whether logs provide enough detail to reconstruct a chain of autonomous actions.<\/p>\n<p>The Australian government is also examining the wider problem. ABC reported that the Albanese government is funding CSIRO research into how humans can manage and verify the behavior of increasingly capable AI systems.<\/p>\n<p>The gym incident was small in scale, but the security lesson is not. As autonomous agents gain access to more online services, Australian organizations can no longer assume that an <a href=\"https:\/\/www.esecurityplanet.com\/threats\/better-auth-flaw-allows-unauthenticated-api-key-creation\/\" rel=\"nofollow noopener\" target=\"_blank\">API flaw<\/a> will wait for a human attacker to find it.<\/p>\n<p>Also read: OpenClaw is facing broader security scrutiny after <a href=\"https:\/\/www.esecurityplanet.com\/threats\/openclaw-vulnerabilities-could-enable-full-ai-agent-takeover\/\" rel=\"nofollow noopener\" target=\"_blank\">Cyera disclosed four vulnerabilities <\/a>that could enable AI agent compromise and privilege escalation.<\/p>\n","protected":false},"excerpt":{"rendered":"A routine gym booking in Australia turned into an unauthorized API action after a Claude-powered AI agent discovered&hellip;\n","protected":false},"author":2,"featured_media":135208,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[10648,405,53,3154,9565,10395,9087,182,576],"class_list":["post-135207","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-access-control","tag-ai-agents","tag-anthropic","tag-anthropic-claude","tag-apac","tag-api-security","tag-australia","tag-claude","tag-openclaw"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/135207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=135207"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/135207\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/135208"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=135207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=135207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=135207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}