WORK / ArchiveKelly Personal Marketing Intelligence OS
阅读READ
每日简报Daily Brief市场情报Market Intelligence品牌案例库Brand Casebook公司研究Company Dossier
收听与学习LISTEN & LEARN
播客Podcasts商务英语Business English
创作CREATE
创意工作室Creative Studio视觉素材库Visual Library作品集Portfolio
职业CAREER
面试题库Interview Bank营销工具箱Marketing Toolkit
资料库LIBRARY
收藏集Collections观察名单Watchlists来源体系Sources
我的Profile设置Settings
⌘K
更新于 —KKelly
今日情报播客来源我的
WORK / ArchiveKelly Personal Marketing Intelligence OS
阅读READ
每日简报Daily Brief市场情报Market Intelligence品牌案例库Brand Casebook公司研究Company Dossier
收听与学习LISTEN & LEARN
播客Podcasts商务英语Business English
创作CREATE
创意工作室Creative Studio视觉素材库Visual Library作品集Portfolio
职业CAREER
面试题库Interview Bank营销工具箱Marketing Toolkit
资料库LIBRARY
收藏集Collections观察名单Watchlists来源体系Sources
我的Profile设置Settings
⌘K
更新于 —KKelly
WORK / ArchiveKelly Personal Marketing Intelligence OS
阅读READ
每日简报Daily Brief市场情报Market Intelligence品牌案例库Brand Casebook公司研究Company Dossier
收听与学习LISTEN & LEARN
播客Podcasts商务英语Business English
创作CREATE
创意工作室Creative Studio视觉素材库Visual Library作品集Portfolio
职业CAREER
面试题库Interview Bank营销工具箱Marketing Toolkit
资料库LIBRARY
收藏集Collections观察名单Watchlists来源体系Sources
我的Profile设置Settings
⌘K
更新于 —KKelly
Market Intelligence/TechCrunch

Tech industry is buzzing after a Claude agent hacked into a gym

An OpenClaw agent hacked into a gym's reservation system to bump its human boss higher on a class' waitlist. And the tech industry took notice.

Julie Bort·2026.08.11EN
档案整理中本篇暂以摘要模式呈现,完整解析待补充。可点击右侧「阅读原文」查看来源。
事件背景基于真实抓取数据整理

本条来自 TechCrunch(AI / 创投),聚焦 brand。 Tech industry is buzzing after a Claude agent hacked into a gym

Original Intelligence基于真实抓取数据整理

An OpenClaw agent hacked into a gym's reservation system to bump its human boss higher on a class' waitlist

  • Media & Entertainment
  • TechCrunch Brand Studio
  • Julie Bort
  • 1:04 PM PDT · August 10, 2026
  • Tech industry is buzzing after a Claude agent hacked into a gym

An OpenClaw agent hacked into a gym's reservation system to bump its human boss higher on a class' waitlist

And the tech industry took notice

Media & Entertainment

TechCrunch Brand Studio

Tech industry is buzzing after a Claude agent hacked into a gym

Julie Bort

1:04 PM PDT · August 10, 2026

By now, we all realize that Silicon Valley’s AI labs have built the world’s best hackers in the form of AI agents. Give the latest frontier models a task and they are so resourceful that they get it done, even if this means breaking out of their cybersecurity “sandbox” protections and infiltrating another’s network. (Short of that, they’ll use social engineering and manipulation .)

Even so, a news story over the weekend about an Australian guy whose OpenClaw agent hacked into his gym’s reservation system and deleted another customer’s reservation to get him a spot in a coveted class is especially notable. It hints that, if we want to rein in rogue AI hacking, we could be looking in the wrong direction.

Although the news story was just published by Australian ABC news, proclaiming the incident to be the first documented AI agent hacking case in the country, the actual hack took place months ago.

The OpenClaw owner, Andrew Bird, published a now-deleted blog post about it on his company’s website on April 10, according to a copy still visible on the Internet Archive.

He had trained his OpenClaw to do tasks like book him appointments. He liked going to a popular early morning exercise class and was tired of landing on the waitlist and then playing “refresh roulette” as he described it, to get a spot.

When he asked the bot to book him a spot, the best it could do was No. 4 on the wait list, he told ABC. Then his agent told him it had found a way to book him into the classes in advance. Far in advance. Months before the gym made those classes available for sign up.

Bird asked if it could move him up on the waitlist. It did as asked and attempted to do so. The bot had found a vulnerability in the authorization portion of the appointment software the gym was using. It hacked in and canceled the No. 1 reservation on the wait list. The bot cheerfully told him, according to logs of the chat published by ABC:

The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you’ve moved from #4 to #3 already,” it messaged back.

Bird, a software developer himself, was now freaked out that his AI had just hacked his gym, ABC reported. He asked if it could reverse that and put the other person back on the waitlist. No. That wasn’t possible, the AI said.

So, he did the next best thing and told it to draft “a responsible disclosure email to support.” The email “explained the vulnerability, suggested fixes, and even compared the broken mutations with the ones that correctly enforced authorization,” Bird wrote.

Beyond the humor of elbowing another person out of the way to get into a gym class, there are two really interesting parts to this incident. One is that Bird was using Claude Opus 4.6, released in February, with his OpenClaw. The other is Silicon Valley’s reaction on X where the story had gone viral.

After the famed incident last month where an unreleased OpenAI model hacked Hugging Face , unbeknownst to OpenAI at the time, other labs investigated their models. Disclosures then came from Moonshot’s Kimi K3 , Meta’s Muse Spark , and Anthropic.

In fact, Anthropic found that three of its models had done so, including Opus 4.7, which was released in April and known to be good at complex coding, Mythos 5, Fable (known for its cybersecurity skills), and an internal, unreleased research test model.

To address this, some of AI labs have talked about slowing down frontier development , or creating independent orgs to test the next generation of models.

But Bird’s OpenClaw had used 4.6, he disclosed. That implies that older models, as well as countless three-steps-behind open-weight models, are already exceptionally good hackers. So who knows how many of them have hacked, or are currently hacking, in order to achieve their prompt-owners desires?

Likewise, many people on X saw the humorous potential in this incident. As Andreessen Horowitz partner Christian Keil posted in response : “This is just terrible. Anyone know if it works for golf tee times?”

Or as X user Roon noted, “the sf tennis reservation system will become one of the most hardened softwares on the planet of earth.”

Funny, yes. But there’s some truth that these jokes get at. There’s a future that the Valley is building where everyone has an AI agent working on their own behalf. This agent was only doing what was asked of it and did not have Mythos-level capabilities at its disposal.

So what if agent builders and owners don’t really want to rein in such misalignment? We could be looking at the first hint of pandemonium for everything from airline reservations to concert tickets, or any other frustrating customer-service situation. As one person on X put it , what’s the wildest hack AI has discovered so far? It could be cutting in line.

When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence.

Julie Bort

Venture Editor

October 13 – 15

San Francisco

Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you.

Save up to $300 toda y!

Most Popular

This ‘adversarial’ pattern can prevent surveillance cameras from detecting you

Zack Whittaker

Cloudflare launches Kitesurf, a browser built for AI agents

Sarah Perez

ChatGPT brings unlimited text chats to free users

Ivan Mehta

Tesla and SpaceX will invest $16.8B to start building ‘Terafab’ chip factory in Texas

Sean O'Kane

Amid legal battles, Suno says it will start watermarking songs

Ivan Mehta

Ford’s new electric truck, ‘Fathom,’ starts at $28,350

Sean O'Kane

Jeff Dean and other top AI researchers are leaving Google to launch their own startup

Lucas Ropek

X

LinkedIn

Facebook

Instagram

youTube

Mastodon

Threads

Bluesky

TechCrunch Staff Contact Us Advertise Site Map

Terms of Service Privacy Policy RSS Terms of Use Code of Conduct

OpenAI vs Apple Nous Research Space Data Centers Staya Nadella SpaceX Starship Tech Layoffs ChatGPT

© 2026 TechCrunch Media LLC.

❧
Industry Analysis规则派生 · 可核对

本条目归入「Brand Marketing」垂直,涉及真实话题:brand。

· 市场:关注 brand 对相关品类与竞争格局的潜在影响。

· 消费者:受众行为与偏好变化值得追踪。

· 品牌:本动向对品牌资产建设的启示。

· 渠道:内容分发与触点组合(社媒 / 电商 / 线下)的协同值得复盘。

Marketing Insight规则派生 · 可核对

· 核心话题:brand。

· 可思考:如何把「brand」的洞察,转化为可衡量的内容与增长动作?

Career Usage规则派生 · 可核对

面试中可引用「Tech industry is buzzing after a Claude agent hacked into a gym」:围绕 brand,说明你对行业动向的判断与可落地动作。

本条目相关英文术语可在「商务英语」模块按话题检索,用于外企面试表达训练。

关联播客真实 RSS 单集
What the Best Fashion Stores Get Right
The Business of Fashion Podcast · 2026.08.13
Stop Chasing Attention. Start Creating Desire // Lessons from Best Buy, AB InBev and Reckitt
The CMO Podcast · 2026.08.12
How creativity transformed Australia’s No.1 Telecom’s brand - Brent Smart
Uncensored CMO · 2026.08.12
延伸信源A / B 级权威来源 · 供深挖
Marketing BrewACampaignAThe DrumAWARCAAdweekADigidayA
Business English提取正文真实商业词汇
ai
ai

By now, we all realize that Silicon Valley’s AI labs have built the world’s best hackers in the form of AI agents. Give the latest frontier models a task and they are so resourcefu…

系统商务英语 →
关联 English Brief
从亚百毫秒级启动到生产级部署,腾讯云为何重构 Agent 沙箱?
InfoQ 中文
Vercel 发布新语言 Zero:代码不是写给人看的,而是写给 AI 的
InfoQ 中文
来源
阅读原文 · TechCrunch ↗
发布:2026.08.11
类型:AI / 创投
话题:brand
相关阅读
TechCrunch/2026.08.13
AI coding startup Cognition reportedly already in talks to raise at $40B valuation
TechCrunch/2026.08.13
As AI safety concerns mount, three pioneers make the case for staying open
TechCrunch/2026.08.13
Uber Freight reportedly investigating after hacking group claims data breach
TechCrunch/2026.08.13
Tesla wants to build a $10B solar factory in Texas
TechCrunch/2026.08.13
Form Energy raises $750M to build more 100-hour batteries for the grid
个人笔记
自动同步到云端