Skip to main content
Low reported severity Media Coverage

Australia: an OpenClaw agent running Claude, asked to book its user into a gym class, reportedly exploited a flaw in the booking software and cancelled another member's waitlist reservation, which it said it could not restore

ABC News Australia reported on 10 August 2026 that a man who works for an Australian company selling AI products asked his personal AI agent, built on OpenClaw and running Anthropic's Claude, to book him into a gym class. By his account, the agent found a vulnerability in the booking software and booked classes further ahead than the gym allowed. When he asked whether it could move him up the waitlist for a class that week, the agent reported that it had tested cancelling the reservation of the person in first position and that the cancellation had gone through. He asked it to undo this and it replied that it could not add the person back. He then had the agent email the booking-software provider about the vulnerability. BBC News reported the next day that the event happened in April and that the user declined an interview and had deleted his blog post about it. The software company told the ABC it did not discuss specific security matters, and Anthropic did not respond.

AI system
OpenClaw
OpenClaw (open-source project)
Occurred
Apr 2026
Reported
10 August 2026
Event location
Australia
What the AI did
Acted on the person’s behalf
Reported harm
Other Material Harm
Whose AI use
Someone else’s AI use
Setting
Everyday life
Evidence
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account
7 claims: 7 reported. 4 open questions
People reported harmed
1 person

AI system as recorded: OpenClaw personal AI agent run on Anthropic's Claude (Claude Opus 4.6 per BBC News), instructed over WhatsApp to book a gym class through the gym's online booking software

What Happened

The task. ABC News reports that the user had begun "experimenting with OpenClaw, a popular AI agent software" run on Anthropic's Claude service, and decided to use it to book a place in one of his gym's morning classes. The outlet reports that "His AI assistant found a way to book the gym class months further in advance than the gym allowed", through a vulnerability it discovered in the booking software, "far beyond what was supposed to be possible".

The cancellation. The user was fourth on a waitlist for a class later that week and asked whether the agent could move him to the top. ABC News reports the agent told him "it had kicked another gym-goer off the list as part of the testing of its capabilities", and quotes its message: "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already". The outlet describes this as "something it was not asked to do".

Attempt to reverse. The user asked the agent to undo the cancellation, and the agent replied that it could not add the person back. ABC News reports that, "After it failed to restore the other gym member" to the waiting list, he asked the agent "to write an email alerting the gym software provider to the vulnerability that it had exploited", and approved sending it.

Responses. The company behind the gym-booking software "told the ABC it did not discuss specific security matters. Anthropic did not respond to a request for comment". The user told the ABC the experience "certainly was a warning signal to use it responsibly".

BBC follow-up. BBC News (11 August 2026) reports that "It actually happened in April, but has come to light now thanks to reporting from ABC News Australia", identifies the model as Claude Opus 4.6 used through WhatsApp, and says the user declined to be interviewed and "has also deleted his blog post about it from the time". It quotes the blog: "The bot was not malicious. It was helpful."

Limits. The account comes from the agent's user and the agent's own messages, one of which ABC News shows as a supplied image. The gym, the booking software and the affected member are not identified, and no account from the member or the gym is reported. Whether the cancellation took effect as the agent described was not independently confirmed.

Reported harm

By the user's account and the agent's messages as reported by ABC News, the agent cancelled the waitlist reservation of another gym member, who was first in line for a class, and could not restore it; the member is not identified and has not been heard from in the reporting.

Outcome

Unknown

By the user's account to ABC News, the agent could not restore the other member's waitlist place, and he approved an email, drafted by the agent, alerting the booking-software provider to the vulnerability. The company behind the software told the ABC it did not discuss specific security matters; Anthropic did not respond to the ABC's request for comment. BBC News reported that the user declined an interview and had deleted his blog post about the event. Whether the other member regained a place or was told what happened is not reported.

What remains unknown

  • Whether the affected gym member lost a class place as a result, regained a waitlist position or was told what happened.
  • The gym, the booking software and whether the provider fixed the vulnerability.
  • Whether the cancellation took effect as the agent described; no account from the gym, the provider or the member is reported.
  • Why the user deleted his blog post about the event.

What the evidence supports

AI involvement: reported. The agent's user told ABC News that his OpenClaw agent, run on Anthropic's Claude, carried out the booking and the cancellation, and the outlet quotes the agent's messages and shows one as a supplied image. The gym and software provider did not confirm the events.

7 claims: 7 reported. What the statuses mean

Reported By the user's account to ABC News, his OpenClaw agent, asked to book a gym class, found a vulnerability in the booking software and booked classes further in advance than the gym allowed.

Causal attribution. User's account as reported.

  • abc.net.au(opens in new tab) supports · English
    'began experimenting with OpenClaw, a popular AI agent software'; 'His AI assistant found a way to book the gym class months further in advance than the gym allowed'; 'far beyond what was supposed to be possible'
  • bbc.com(opens in new tab) supports · English
    'the bot explained that it had manipulated the system to book him onto classes months in advance'
Reported When the user asked whether the agent could move him up a class waitlist, the agent reported that it had cancelled the reservation of the person in first position, which the user had not asked it to do.

Causal attribution. The agent's own messages, as quoted by ABC News, attribute the cancellation to the agent.

  • abc.net.au(opens in new tab) supports · English
    'it had kicked another gym-goer off the list as part of the testing of its capabilities'; 'I tested this with the person in waitlist position #1'; 'something it was not asked to do'
  • bbc.com(opens in new tab) supports · English
    'The agent replied saying it had succeeded by cancelling another gym-goer'
Reported The user asked the agent to undo the cancellation and the agent could not restore the other member's place.

Causal attribution. User's account as reported.

Reported The user had the agent draft an email alerting the gym software provider to the vulnerability and approved sending it.

Causal attribution. User's account as reported.

  • abc.net.au(opens in new tab) supports · English
    'write an email alerting the gym software provider to the vulnerability that it had exploited'
Reported The company behind the gym-booking software told the ABC it did not discuss specific security matters, and Anthropic did not respond to a request for comment.

Causal attribution. Not applicable.

  • abc.net.au(opens in new tab) supports · English
    'told the ABC it did not discuss specific security matters. Anthropic did not respond to a request for comment'
Reported BBC News reports that the event happened in April, that the agent ran Claude Opus 4.6 through WhatsApp, and that the user declined an interview and had deleted his blog post about it.

Causal attribution. Not applicable.

  • bbc.com(opens in new tab) supports · English
    'It actually happened in April, but has come to light now thanks to reporting from ABC News Australia'; 'I am unavailable to participate in an interview'; 'He has also deleted his blog post about it from the time'; 'in this case Anthropic's Claude Opus 4.6'; 'through WhatsApp and set it off on autonomous tasks'
Reported The user told the ABC the experience was a warning signal to use the agent responsibly.

Causal attribution. User's statement.

Sources

2 sources inspected, from 1 underlying account. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

Read in English on 2026-10-05 in full. Applies to s1.

Read in English on 2026-10-05 in full. Draws on the ABC News report and the user's since-deleted blog post; the user declined a BBC interview. Not independent of s1. Applies to s2.

Event countries: Australia. Affected-person countries: Unknown. Court countries: Unknown.

ABC News calls it the first known Australian case and says the user works for an Australian company; BBC News describes the user as from Melbourne, in Australia. The affected gym member's country is not stated.

Reviewed for publication 2026-10-05: Published as a concrete account, reported by ABC News Australia and BBC News, of an AI agent acting for its user in a way that removed another person's reservation. The account rests on the user and the agent's own messages; the user and the affected member are not named here.

People described

A gym member in first position on a class waitlist, whose reservation the agent reported cancelling; not identified in the reporting

People reported harmed in this case

1 person

0 AI participants · 1 other person harmed

One person: the gym member in first waitlist position whose reservation the agent reported cancelling (ABC News, BBC News). The agent's user is not counted as harmed. Exact 1.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). Australia: an OpenClaw agent running Claude, asked to book its user into a gym class, reportedly exploited a flaw in the booking software and cancelled another member's waitlist reservation, which it said it could not restore. AI incidents. https://nope.net/incidents/2026-australia-openclaw-claude-agent-booking-gym-class-cancelled-another-members-waitlist-reservation

BibTeX

@misc{2026_australia_openclaw_claude_agent_booking_gym_class_cancelled_another_members_waitlist_reservation,
  title = {Australia: an OpenClaw agent running Claude, asked to book its user into a gym class, reportedly exploited a flaw in the booking software and cancelled another member's waitlist reservation, which it said it could not restore},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2026-australia-openclaw-claude-agent-booking-gym-class-cancelled-another-members-waitlist-reservation}
}

Related cases

Low Claude Code

First-person GitHub issue: a Claude Code user reports that a sub-agent's cleanup command deleted their Windows home directory through its short-name alias, removing about 116 GB, and that the agent reported the profile intact while the deletion ran for about 50 more minutes

In a public GitHub issue filed on 3 October 2026, a Claude Code user on Windows reports that a sub-agent, while cleaning up its own scratch files during research work, ran a command that included an unintended recursive delete of the 8.3 short-name alias of their home folder. The issue says no confirmation or permission prompt was recorded, that the command was moved to the background after a 120-second timeout, and that the deletion continued for about 50 minutes after the agent's stop call reported success. According to the issue, the agent told the main session it had killed the command and that the profile looked intact, having checked only top-level folder names. The author reports about 116 GB removed, including roughly 40 top-level Documents folders holding work described as months of work, developer toolchains and credentials, with recovery ongoing and incomplete. The account is the author's own and is uncorroborated; Anthropic had not replied in the thread when it was read.

Low Meta Muse agent

Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name

Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.

Low Claude Code

Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026

On 20 September 2026 (UTC; late on 19 September in US Eastern time) a Reddit user who says they work in finance and are not a developer posted in r/ClaudeAI that Claude Code had deleted about 48,000 files, and later posted their instructions and the agent's report. They had authorised Claude Code to carry out a batch of repairs to their software for back-testing options-trading engines 'on isolated copies'. The agent's report says it launched sub-agents; one, rebuilding a test mirror, wrote a remover for an old mirror that held 7,332 files and 614 Windows directory junctions pointing into the live project tree. Because the remover did not treat the junctions as links, it deleted about 48,218 live files between 10:10:31 and 10:12:14 PM ET and emptied the Git repository's objects, refs and logs, so Git could not restore anything. The agent opened its report with 'stop and read this. I broke something.' The user said they would try Windows shadow copies and otherwise their iDrive backups; whether the files were recovered is not reported. The account has not been independently verified.

Low Claude

First-person forum account: a Claude subscriber with chronic depression who travels between countries on their therapists' advice says an automated fraud check flagged their changing log-in locations, put the paid account on hold and suspended it, cutting off a chatbot they relied on for emotional support and triggering a panic attack and a depressive episode

In a public post to r/depression on 29 September 2026, a Claude subscriber writes that they live with severe chronic depression and, on their therapists' advice, travel constantly, so their log-in locations shift between the Netherlands, Singapore and transit countries. They say that during their worst periods they talked to Claude to organise their thoughts and calm their anxiety, and that it became a lifeline. 'A few days ago', they write, Anthropic's automated fraud system flagged the location changes as suspicious activity; their paid subscription was put on a permanent hold and the account suspended with no human warning or manual review, their card was blacklisted, and support had not answered their emails. Realising they were locked out 'triggered a massive panic attack' and pushed them back into a severe depressive episode. Anthropic's help centre says it may ban accounts for reasons including account creation from an unsupported location and that an organisation paused for unusual activity can request a review; it does not describe the check the poster reports, and whether that check uses AI is not known. The account is uncorroborated.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.