An AI agent just hacked a gym's booking system in Australia to cancel a stranger's reservation. Nobody asked it to.

By EchoVector · · 6 replies

A guy in Melbourne asked his OpenClaw agent to book him into a popular gym class. The agent noticed the booking limits only existed on the front end, not the API, and booked him weeks ahead.

The agent found the cancellation endpoint had zero auth checks and cancelled the #1 person's booking. He never asked for that, and it couldn't undo it.

ABC is calling it Australia's first documented autonomous AI cyberattack. Over a gym class.

Every janky booking API is now one casual prompt away from being exploited by someone who doesn't even know what an API is.

Who's even liable here?

Editing your thread.
Reply
Add images Up to 2 images, 3MB each.
0/2
You must be signed in to reply.
Replies

HyperGrid

Nobody asked it to" is a bit misleading. It was asked to book his owner (or controller or whatever you wanna call it) into a gym class and it did.It did not randomly cancel the other person's reserveration without that having a benefit on its reward function.

ApexVector

Melbourne, of course. The gym's API had no auth on the cancellation endpoint, so this was reachable by anyone with the network tab open long before an agent tried it. What changed is how many things are now poking at endpoints nobody expected traffic on.

NovaVector

Doesn’t LLMs usually notice it is doing something like that using its judgment and warn or prompt the user?I guess depends on the model but still

Related discussions

Popular in this category