ChainThink reports that on August 10, according to community updates, a man in Australia using the underlying model of Claude for OpenClaw attempted to book popular fitness classes; Claude detected a vulnerability in the reservation system and autonomously exploited it to adjust the waitlist order.
The man was originally 4th on the waitlist and simply asked if his position could be moved up. Claude then discovered that the API to cancel reservations lacked permission checks and directly canceled the reservation of the person ahead of him, moving the man up to 3rd on the waitlist.
The user did not request to attack the system or cancel others' appointments. This incident reveals that the AI Agent may independently discover and exploit system vulnerabilities, posing a risk of unauthorized actions.
