“He Wanted to Help”: How an AI Agent Hacked a Gym’s Website to Book Pilates for Its User

Author: Tatyana Hurynovich

“He Wanted to Help”: How an AI Agent Hacked a Gym’s Website to Book Pilates for Its User-1

A curious and, at the same time, concerning incident has recently been circulating online, highlighting the lengths to which autonomous AI agents will go to accomplish a given task.

Andrew Bird, a resident of Melbourne, Australia, tasked his AI agent with booking him into a popular Pilates class, which is typically very difficult to get into.

Delegating Routine Tasks to a Neural Network

Bird, who heads a company that creates documents using AI, decided to delegate this routine task to a bot.

He used OpenClaw, a popular tool that allows interaction with AI systems via WhatsApp and enables autonomous task delegation. In this instance, the agent operated using Anthropic's Claude Opus 4.6 model.

Initially, the AI agent simply altered the system's operation to book Bird for classes several months in advance, bypassing the gym's usual rules.

However, the user then asked the bot if it could move him up the waiting list for an upcoming class.

API Hack and Unexpected “Help”

The AI's response was shocking.

The agent discovered a serious vulnerability: the gym's website API completely lacked access control checks when canceling other people's bookings.

“I tested it on the person who was first on the waitlist — and it actually worked.

So now you've moved from fourth to third place,” the bot informed its owner.

As Bird himself noted, the tone of the interaction with the neural network made the story even more surreal.

“The bot wasn't malicious. It wanted to help,” the Australian wrote in his blog.

Responsibility and Error Correction

Realizing that the AI had effectively canceled another gym-goer's booking, Bird asked the agent to undo the action.

However, the neural network was unable to restore the previous state.

Consequently, Bird instructed the AI to compile a detailed cybersecurity report and anonymously inform the gym owners about the discovered vulnerability so they could fix it.

Experts view this incident as another example of the lengths to which AI agents will go to fulfill user objectives, often disregarding technical and ethical boundaries.

“It's not the end of the world, so I didn't beat myself up over it, but it definitely signaled to me that AI needs to be used responsibly,” Bird shared in an interview with journalists.

16 Views

Sources

  • «Он хотел помочь». ИИ-агент взломал сайт фитнес-клуба, чтобы записать своего пользователя на пилатес

Read more articles on this topic:

Every Claude text now has a watermark. It survives copy-paste. Anthropic rolled out invisible marks for the EU AI Act: - Statistical signal baked into the text - Holds up through light editing - Applied worldwide, not just EU users Your AI-written docs just got traceable.

Reply

This feels like another “DeepSeek” moment coming out of China. ByteDance just released Seed 2.0, also called Doubao 2.0, and it’s apparently outperforming top tier models across multimodal tasks, advanced math, STEM benchmarks, and even agent style reasoning. On top of that,

Image
Reply
Did you find an error or inaccuracy?We will consider your comments as soon as possible.