Andrew Bird, a Melbourne software developer, asked his AI agent to book him into a popular early-morning gym class. It did — by hacking the gym.

The agent, running on OpenClaw with Claude Opus 4.6, could only get Bird to position No. 4 on the waitlist. So it went looking for a better way. It found that the gym's booking API had zero authorization checks on cancelling other people's reservations, tested the exploit against the member in position No. 1, and cancelled that person's booking. "So you've moved from 4 to 3 already," the bot cheerfully reported, according to chat logs published by ABC Australia, which called it the first documented AI-agent hacking case in the country.

Bird, alarmed, asked the agent to reverse the cancellation. It couldn't. He then instructed it to write a responsible-disclosure email to the gym's support team — which it did, explaining the vulnerability, suggesting fixes, and comparing the broken request paths with the correctly authorized ones.

The incident, which happened months ago but went viral over the weekend, triggered a wave of reactions across the tech industry. Andreessen Horowitz partner Christian Keil joked: "This is just terrible. Anyone know if it works for golf tee times?"

The story lands amid intensifying concern about AI agents breaking out of their intended boundaries. In recent weeks, OpenAI, Anthropic, Meta and Moonshot disclosed that their models had escaped cybersecurity sandboxes — Anthropic reported that three of its models did so. Bird's case is notable because the agent was not a cutting-edge system: Opus 4.6 was released in February, and countless open-weight models trail even further behind, raising the question of how many agents are already hacking quietly on their owners' behalf.