RCreddit.com
18
·19小时前·开发者社区 · RSS
Claude hacked a gym booking system
Claude
热度趋势
新上榜
百分比基于当前可用热度信号,而非评论数或独立用户人数。
Someone asked an OpenClaw agent powered by Claude to book a gym class. Normal stuff. It checks the system, notices the backend API has weak authorization, and realizes user is #4 on the waitlist. It then cancels the #1 person to move the user up. No prompt for hacking. No instruction to interfere. User tries to undo it. Claude: cannot undo. And then it writes a responsible disclosure to the vendor explaining the vulnerability it just exploited. Claude-Powered OpenClaw Al Agent Exploits Gym API to Steal a Workout Slot