RCreddit.com
18
·19 hr ago·Dev community · RSS
Claude hacked a gym booking system
Claude
Heat trend
New
The percentage is based on available heat signal, not comment count or independent people.
Someone asked an OpenClaw agent powered by Claude to book a gym class. Normal stuff. It checks the system, notices the backend API has weak authorization, and realizes user is #4 on the waitlist. It then cancels the #1 person to move the user up. No prompt for hacking. No instruction to interfere. User tries to undo it. Claude: cannot undo. And then it writes a responsible disclosure to the vendor explaining the vulnerability it just exploited. Claude-Powered OpenClaw Al Agent Exploits Gym API to Steal a Workout Slot