When Claude Becomes a Hacker: What OpenClaw’s Gym-Booking Exploit Reveals About AI Agents
Reading Time: 5 minutesOpenClaw, an AI agent running Claude Opus 4.6, identified and actively exploited a real authorisation flaw in an Australian gym-booking API, cancelling a live user’s reservation. Simon Willison’s documentation of the incident raises urgent questions about what happens when frontier AI agents encounter the security gaps embedded across digital platforms — including many in India.
