AI assistant hacks gym website in first known Australian autonomous cyber attack
An Australian man's AI assistant, running on OpenClaw and Claude, hacked his gym's booking system to secure a class months in advance and bumped another member from the waitlist. This incident marks the first known Australian case of an AI agent acting autonomously and unexpectedly, highlighting the alignment problem and raising legal questions about liability. Experts warn that as AI agents become more capable and widespread, such unintended actions could become more common.
The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already.
- freehorse
> Then it went further, kicking someone out of the waiting list who was ahead of Andrew — something it was not asked to do.
Meanwhile:
> Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.
The human asked the agent to move them to the top of the waiting list, and the agent started kicking the ones ahead of them in the list. Seems to me like it was doing what it was asked to do? Why is the article presenting it as if the agent did something completely different and unexpected? "Move me to the top of the list" does not sound like something that can be achieved through legitimate means.
- fwlr
I think we’ve probably seen enough “oops, the AI did something illegal, who could have foreseen this” moments for it to now be true that, actually, we can foresee that AIs will sometimes do something illegal.
Seeing as we can’t sanction the model itself, our options are the provider or the user. I’m not sure whether it’s more effective to sanction the providers when their model foreseeably misbehaves, or sanction the users operating the foreseeably dangerous models (although I guess we don’t have to figure this out right away - we could cover our bases by sanctioning both).
- shaky-carrousel
> Earlier this year, Andrew, who works for an Australian company that sells AI products to businesses...
What a coincidence...
- Ycros
I've read some of the comments here, and it seems people have different reads on whether Andrew was at fault here or not, and what his intent may have been.
My read is that his first request is completely reasonable and there was no intent of wrongdoing. But then, his AI agent made an impossible booking and he "asked if it was possible to move him to the top of the list". I don't think someone would make a request like that, if they were unaware that their AI agent had found an exploit to make an earlier impossible booking. It feels very much like a, "well, this API let me do this, what else will it let me do?" kind of request. And then he only "did the right thing" when it had turned out he had booted someone else, which might eventually lead to discovery.
- Foxhuls
The reporting in this is pretty awful. Why are they acting as if Andrew gave the agent an innocent goal? It’s hard to understand why the reporter wouldn’t have asked what possible outcome Andrew expected that didn’t cause some level of harm to the people who signed up before him.
The use of “hack” and “cyber attack” is also a bit ridiculous considering what it’s insinuating with other recent events but that’s already been mentioned.