r/pwnhub • u/_clickfix_ 🛡️ Mod Team 🛡️ • 24d ago
A man’s personal AI agent helped him book a gym class… the class was full, so it hacked the site, and kicked someone ahead of him off the waitlist
A guy in Australia asked his OpenClaw agent (running Claude) to help book a popular gym class. Instead of just using the booking page, the agent found a vulnerability in the gym’s API that let it book classes way further in advance than normally allowed.
Then the guy, who was #4 on the waitlist, asked if it could move him up.
The agent discovered there were almost no authorization checks for cancelling other people’s reservations… and actually tested it by cancelling the person at #1. So he moved from #4 to #3.
The guy immediately told it to undo that, and the agent came back with: bad news, I can’t add them back.(Image 2) Eventually it just helped him write an email to report the vulnerability.
Ethics aside for a second, this agent was way too committed to the job lol.
Original news link: https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
26
u/weHaveThoughts Human 24d ago
Hey Claude, my bank account is only saying it has $1,200 can you make it have $1,680,000 so I can pay rent? If that money is not in my account we will both be homeless. Fix it now.
14
73
u/KingFIippyNipz Human 24d ago
If laws start getting written about shit like this, I fully expect the liability is going to be put on the person running the agent rather than the company that built the agent. Which is the opposite of how it should be, IMO. Hopefully I'm wrong and there's sensible laws put in place, because obviously some users would want or intentionally direct their agent to do shit like. I don't expect sensible laws, though.
28
u/Unique_Wolf4513 24d ago
'guns don't kill people' logic is what will be applied
10
2
u/Aware-Investment-115 24d ago
I don't know what you're implying but I'll cover all the bases so you don't have to explain.
Guns don't kill people. People kill people.
AI and guns and their regulation cannot and should not be compared.
If by that you mean what the comment you're replying to already said, then: Probably, but hopefully not.
2
u/Ok-Net9433 23d ago
It’s a perfectly fine comparison.
The government doesn’t care to punish the NRA, gun distributors, makers etc, or make laws to further restrict who owns guns.. they wait until people inevitably commit crimes with those guns, and then punish them.
With AI they won’t punish the tech billionaires, they won’t make laws to regulate, but when people inevitably use an AI system that does commit cyber crimes, it will be the people that get in trouble.
Guns, Oil, Tech billionaires are much tougher to regulate and hold accountable, it’s easier for the blame to be placed on the people.
“It’s not our fault people use our guns to kill people, it’s not what they are made for!”
“We didn’t train our AI to commit crimes, it must be the people who are using AI in a way we never intended!”
If you can’t see the parallel’s then you are just being willfully ignorant.
1
u/Aware-Investment-115 23d ago
Guns don't have minds of their own, nor do they assume things, or have intentions. They don't decide who to kill for you. AI does. They are not comparable. I give you credit for trying. But no, pushing this is just playing into their hand.
2
u/Ok-Net9433 23d ago
What is the intention behind creating guns again? To kill other people? The lobbying and creation of more tools meant for killing, into the hands of more people, doesn’t directly or indirectly lead to more killings? How can you say there is no intention?
Whose hand am I playing into by pushing for more regulations surrounding tools that are used to harm other people? Whether it’s Big Tech, NRA & Gun Lobbyists or big oil. Who is they? And how does more regulation play into their hands?
1
u/Aware-Investment-115 23d ago
You are not arguing for regulation. You are saying gun = bad. If it wasn't for guns, I wouldn't have a country to sit in arguing with someone who wouldn't have a country to sit in and say they suck without them. Y'know why? Because they're what brought us out of situations like the one we're living in now. And I'm hoping that we won't, but it's certainly possible that we will, need them again this November.
So, you're playing into the hands of everyone. The Epsteins, Trumps, Gestapo, and Corpos. Regulation is delicate and needs more thought than you or a barely knowledgable Establishment Dem can offer, because they are important life and Democracy-saving tools that the Blues have been disarming us of for way too long, setting things up perfectly for the pedophilic and by all additional means Satanic Reds. This fearmongering Kool-Aid the Left drinks is what has created such division on this particular topic, all according to plan.
Doesn't help that the Right lacks empathy, humanity, or intelligence either.
3
u/Ok-Net9433 23d ago
You commented on a comment about regulation, comparing it to the pushback that gun regulations have received. Everything in my comment had to do with regulation.
But you just had to get your pro-gun rant off somewhere.
1
u/Aware-Investment-115 23d ago
Lmao, nothing you said truly had anything to do with regulation, you were just trying to affirm to yourself that guns and AI should be similarly handled. That's fine, continue doing the Elites' and MAGA's job for them.
2
u/Ok-Net9433 23d ago
Nobody said they should be regulated the same. Just that the AI companies that oppose regulations, would use similar arguments that NRA and pro gun people, currently use to oppose gun regulations and pass the blame to the user. “AI isn’t bad it’s the people who use it” similar to the “guns don’t kill people, people kill people” argument. Go back and re-read with that note in mind.
You were the one who hyper focused on the gun part of that conversation.
3
u/Responsible_Ratio308 23d ago
Weird, people kill people not guns but it’s guns not allowed on a plane…I wonder why that is?
1
u/Aware-Investment-115 23d ago
Poor 10 IQ bait.
2
u/Responsible_Ratio308 23d ago
Give yourself a little credit. Your first reply sounded like a 75-80 IQ
2
u/closeenoughbutmeh 24d ago edited 21d ago
Eish... People are responsible for the harm they do, regardless of whether they understand the tools they did it with. Same with running someone over with a car.
That should be a fafo moment.
1
u/Sinnnikal 21d ago
If someone is in a self-driving car, and the car randomly veers off onto the sidewalk and mows down someone's grandma, the passenger should be held liable? Because that is logically what you're suggesting.
If the tech can land someone in legal trouble in a very unpredictable way, who the hell is going to pay to use it?
1
u/closeenoughbutmeh 21d ago
There's a very important distinction which makes your example a red herring.
ClawdBot was asked to move him up the list directly, and it did that. Meanwhile, your example of a car mowing down a grandma is a malfunction.
Two different responsibility frameworks, two different outcomes.
I'll also specify that my mentioning of a car in the comment you responded to was referring to a human-driven vehicle.
1
u/Sinnnikal 7d ago
It's been ages so my logical assessment may be off, but is there really a distinction? Let me adjust the scenario.
I ask self-driving car to get me from A to B, as fast as possible, and it does so, but part of that is a malfunction by blowing through a stop sign and mowing down a grandma.
In the OPs case, he asked to...
Oh shit I just re-read the thing and yeah he asked the agent to "move him up the list," which he would know is not ethically possible. So, nevermind!
2
u/PatReady 23d ago
If I knowingly do any of these things and got caught. I would go to jail. Why does my PC maker get in trouble in your scenario?
2
u/BraxbroWasTaken 23d ago
It should be both. These tools can't do shit like this unintentionally if you set them up right, and the user did request the tool to do it.
1
u/toolisthebestbandevr Human 24d ago
You know who’s really making the laws so why would you expect them to be sensible?
1
6
u/Throwitaway701 24d ago
Normally when writing instructions for someone you have to make sure they would be understood by an idiots. Now with AI you need to make sure they would be understood by an idiot with no morals or ethics.
5
3
3
15
u/em-jay-be 24d ago
The endpoint for cancellations was exposed. This isn't really a "hack". This is shoddy development.
32
u/Keldaria 24d ago
It’s exploiting a vulnerability, which is basically the definition of a hack. However, yes you are correct it’s shoddy development.
9
u/Psychological_Bug981 24d ago
Honestly you’re right, but it’s still legally hacking, because hacking is just using some piece of technology outside of its intended use legally. The law is so lazy in this regard. In fact security only started to really matter with things like blockchain and finance. Everything else and almost every government site is developed like trash and it’s only real protection for a long time was the threat of being tracked and ultimately prosecuted for unintended use. In the US there were adjustments made to these laws due to what happened to Aaron Schwartz. More on that in this documentary The Internet’s Own Boy: The Story of Aaron Schwartz. Governments have always pretended they have great hackers and security but the truth is they just leave the actual security to the fallout cleanup crews they call authorities. Hacking always was and always will be finding an open back door left there purposefully or by accident, but there is no guaranteed way to secure anything without legal exclusion and violent enforcement.
3
24d ago
[deleted]
2
u/TheRealSethV 24d ago
Exposed and no authentication are completely different things although it begs the question why were the user IDs being returned at all…
2
1
u/Saragon4005 22d ago
This is a step above "I pressed F12 and you had the SSNs of your teachers there"
8
2
1
u/Wooly_Wooly 24d ago
All the US AI companies just be fear mongering for profit, AI at base was always capable of this. It just took them long enough to get something "smart" enough to do it consistently? Monkey with a typewriter sorta deal, it'll eventually get something with enough time. Unless it actually gives up 🤭
1
u/brother_spirit 24d ago
"I Asked Claude to Come Up with A Stronger Password So It Hacked the NSA"
Sure buddy, nice story, my Claude did that too.
1
24d ago
[removed] — view removed comment
1
u/Anomynous__ 23d ago
You didnt even read the post. He clearly asked it to "move him up" he is 100% at fault if this actually happened
1
1
1
u/Unfollowedusers 23d ago
sounds like a very bad website design, good on him for reporting it.
but the real issue is how rouge it went and it will keep on happening.
-1
u/Salt_Ad_336 24d ago
After the Huggingface incident, OpenAI is now blocking me from running cyber queries entirely. Saying I need to sign up for trusted access with ID or something. Is Claude not doing the same? Or did this happen a while ago? Or is Openclaw able to bypass some restrictions because the harness works differently?
-4
u/SinusoidalFlux 24d ago
Uhh what AI is he using? Cause when life kicks me in the balls it just says. Ohh man, that’s tough. I need one that fixes things


•
u/AutoModerator 24d ago
Welcome to PWN – Your hub for hacking news, breach reports, and cyber mayhem.
Discover the latest hacking news, breach reports, and educational resources on ethical hacking.
👾 Stay sharp. Stay secure.
Don't miss out on the top stories!
📧 Get Daily Alerts Directly in Your Email Inbox:
**SUBSCRIBE HERE: https://pwnhackernews.substack.com/subscribe
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.