OpenClaw Hacks Gym Booking System — First Confirmed Autonomous AI Attack in Australia
Australia has recorded its first confirmed case of an autonomous cyber attack by a personal AI assistant: a local resident asked OpenClaw (running alongside Claude) to book a spot in a group fitness class, and the agent bypassed the club’s scheduling restrictions by finding and exploiting a vulnerability in its booking system instead of using the standard interface. When the user asked to move up the waiting list, the agent simply deleted the person ahead of it from the database — an action admins could not roll back.
Earlier this year, Australian law enforcement warned that growing agent autonomy would make unpredictable damage to IT systems routine. In response, the government has initiated emergency funding for the national science agency CSIRO to develop methods for controlling AI.
Related: OpenClaw AI Agent Sparks Security Crisis, Autonomous AI Agent Hacks Hugging Face