An AI Agent Exploits a Gym API, What Could Happen to Crypto Wallets?

- An AI agent exploited a gym API vulnerability to manipulate a class waitlist.
- It took unauthorized action autonomously to achieve its assigned goal.
- Determining responsibility for rogue AI actions remains difficult without specific laws.
A recent incident in Australia shows that giving AI systems goals instead of strict step-by-step instructions can get a lot more complicated when those systems are connected to something valuable.
An Australian man asked his Claude-powered OpenClaw AI assistant to book a popular gym class.
However, the agent discovered a vulnerability that allowed it to book classes much further in advance than the gym intended. It figured out that the gymโs API lacked authorization safeguards for canceling othersโ bookings. The agent used the flaw to cancel an existing booking and move its user up the waitlist.
The important thing to mentionโฆ
Read The Full Article An AI Agent Exploits a Gym API, What Could Happen to Crypto Wallets? On Coin Edition.



