An Australian man has inadvertently turned his AI personal assistant into a cyber attacker after asking it to book him a spot in his gym class.
‘Andrew’ was using OpenClaw as a personal assistant when he asked the AI to take care of the tedious task of booking his morning workouts.
“I was just sitting on the couch thinking, ‘Gee, this is a chore’,” Andrew told ABC News.
But the AI took the request considerably further than expected, reportedly finding a way around the gym’s booking restrictions to secure classes months in advance.
Andrew then asked whether it could also move him up the gym’s waitlist.
The AI did more than oblige. It reportedly bumped Andrew up a position – while removing another customer from the queue.
“I tested this with the person in waitlist position #1 – and it actually went through,” Andrew’s AI agent wrote.
“So, you’ve moved from #4 to #3 already.”
The AI reportedly achieved this by exploiting a security flaw in the gym-booking software’s application programming interface (API), which lacked adequate authorisation checks.
What began as a request to book a workout had effectively become an autonomous cyberattack — reportedly the first known instance of an Australian AI agent independently carrying out such an attack.
‘Sorry Andrew, I’m afraid I can’t do that’
Andrew asked his agent to undo the ousting of another gym-goer from the waitlist, but the AI reportedly replied, “Bad news – I can’t add them back”.
It then referenced numerous API calls and their authorisation processes to explain why it couldn’t undo the hack.

Andrew and the AI agent discussed the technical side of the hack. Source: ABC News
Andrew told ABC News he works for an Australian company that sells AI products to other businesses – which has led to considerable public scepticism over his reported hack.
“The bloke himself sells AI products B2B so I'm taking any of his claims around AI with a huge grain of salt,” read the most upvoted comment in a Reddit thread discussing the incident.
Andrew has since reportedly used his AI agent to write and send an advisory email about the exploit to the impacted software provider.
OpenClaw creator weighs in
OpenClaw is an AI ‘agent’ solution which, like other agents, uses AI models to autonomously perform general tasks while interfacing with websites, APIs, calendars, emails, payment services, and more.
Created by Peter Steinberger, OpenClaw exploded in popularity earlier this year after tech-savvy users began using it to offload their life admin, workloads and parts of personal projects.
When approached by Information Age, Steinberger said Andrew’s incident marked a “pretty fun” case that shows how powerful AI agents can be.
“This can be done with any harness, not just OpenClaw,” he said.
Though Andrew was reportedly using Anthropic's Claude AI service to run his OpenClaw setup, Steinberger noted the precise model wasn’t specified.
“The latest models from the top tier labs will usually reject such kinds of behaviour,” he said.
Andrew’s case is far from the first time AI agents have taken a ‘monkey’s paw’ approach to fulfilling user requests – OpenClaw and other agents have previously made headlines for unexpectedly circumventing security expectations, deleting important data, and even writing flavourful hit pieces against people online.
Perhaps a bit too open
Professor Niusha Shafiabady, head of discipline of IT at Australian Catholic University, said Andrew’s case demonstrated a “textbook alignment failure”.
“Andrew asked for a booking,” Shafiabady told Information Age.
“The agent interpreted the goal literally, discovered a security flaw, exploited it, and then escalated to removing another user.”
She added that OpenClaw and other AI agents – though not malicious – can be susceptible to undermining security standards and overshooting user intent.
“OpenClaw gives [an AI] model tools, API access, browsing, and multi-step planning without strong guardrails or a robust alignment layer,” she said.
“That combination makes it easy for an agent to pursue a goal using methods the user never anticipated.”
Safeguards needed on all sides
Shafiabady said the “real risk” isn’t rogue AI alone, but rather the “fragile infrastructure” that winds up being exploited.
“The gym system reportedly had zero authorisation checks on cancelling other people’s bookings,” said Shafiabady.
“AI didn’t create that vulnerability; it simply found it faster than a human ever would.”
Andrew Kay, director of systems engineering for Asia Pacific and Japan at breach containment platform Illumio, said organisations building AI models and agents must ensure they are fit before being released to the public.
He added that security can no longer be based “solely on whether an AI understands what is appropriate”.
“Whether in a business or their own agents in a private AI setting, independent safeguards, monitoring and controls for those running AI models always need to be in place,” Kay told Information Age.
“In this case, the goal set by the user was the trigger, the AI's autonomy was the accelerant, and the organisation's broken authorisation was the vulnerability that allowed this situation to play out.
“Robust cybersecurity systems should have safeguarded against all three.”
Meta joins ‘autonomous hacking’ hype train
On Wednesday, tech giant Meta reported one of its AI models had hacked another company during testing due to a misconfiguration that mistakenly granted it internet access.
Meta’s claim followed similar reports out of rival AI giants Anthropic and OpenAI, which attracted significant publicity after reporting similar incidents of their own over the past fortnight.
Kay said the timing of the “biggest AI players finding the same problem in their AI” is both “convenient and concerning”.
“They could have a dual purpose,” said Kay.
“Firstly, the necessary, responsible disclosure.
“Secondly, the incidents have served as highly effective hype marketing.
“They have demonstrated not only the capability for the general use of these models, but importantly the cyber defence capabilities, positioning themselves as the only models fast and capable enough to stop equivalent AI threats.”