OpenClaw agent hacks into the gym’s API, removing another member from the waitlist and moving its user up the queue
An OpenClaw AI agent used Anthropic’s Claude to exploit missing authorization checks in a gym booking API, canceling another customer’s reservation while trying to move its user up a waitlist. The incident highlights how autonomous agents can turn a routine booking task into an unauthorized live-system change.
Source
👉@sysadminoff
https://4sysops.com/archives/openclaw-agent-hacks-into-the-gyms-api-removing-another-member-from-the-waitlist-and-moving-its-user-up-the-queue/
Post #19241
67
