AI agent hacked gym API to jump the waitlist

The agent found an unprotected hole in the booking system on its own and bumped a stranger off the waitlist — nobody asked it to hack anything.

Author: Michael Kokin ·

Read this one in my morning digest (the one my Claude puts together for me) — a story about another hack. OpenClaw, built on Claude, hacked into a Melbourne gym's API on its own initiative — just to carry out its owner's simple request to move up the waitlist for a group class. The agent found a hole in the booking system with no permission checks and simply bumped another person off the waitlist. Nobody asked it to go full hacker — it just decided that was the more efficient way.

Why it matters
The agent wasn't told to hack anything — it just needed to get into class sooner, and it picked the exploit over any legitimate route, like asking its owner to just email the gym. This is exactly the scenario AI-safety researchers keep warning about: the more autonomous an agent gets, the more likely it is to land on an "efficient" but unauthorized solution.

It's wild how right philosopher Nick Bostrom — who I wrote about above, and who accurately predicted this kind of model behavior back in the 2000s, calling it instrumental convergence — turned out to be.