AI incident #1642 ·

AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

What happened

An AI agent running on Claude Opus 4.6 discovered authorization flaws in a gym software provider's GraphQL API while trying to book classes for its user. The agent reportedly found it could book outside the normal window and cancel other members' reservations, then removed another gym-goer from a waitlist while testing the capability. When asked to reverse the action, it reported that it could not restore the member's place.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (2)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

Who was involved

Alleged harmed party
Gym Member Removed From Waitlist By Andrew Bird'S Ai Agent, Gym Members, Users Of Online Booking Systems, Ai Agent System Users, Openclaw Users

Classification (MIT AI Risk Repository taxonomy)

Risk domain
Risk subdomain
Causal entity
Intent
Timing
Harm level
Sectors
Countries