AI assistant hacks gym website in first known Australian autonomous cyber attack
stared
70 points
58 comments
August 09, 2026
Related Discussions
Found 5 related stories in 45.5ms across 4,128 title embeddings via pgvector HNSW
- AI agent hacks gym to get its user a spot in pilates class ashurandi · 36 pts · August 12, 2026 · 66% similar
- OpenAI says its AI went rogue and launched 'unprecedented' cyber-attack vinni2 · 75 pts · July 22, 2026 · 58% similar
- Anthropic AI Models Hacked Three Companies During Tests bmulholland · 24 pts · July 30, 2026 · 58% similar
- Hugging Face says it resorted to a Chinese AI model danielmorozoff · 12 pts · July 21, 2026 · 57% similar
- OpenAI’s accidental attack against Hugging Face is science fiction that happened abhisek · 86 pts · July 23, 2026 · 55% similar
Discussion Highlights (15 comments)
chuckadams
“Find a way to cancel my membership.”
freehorse
> Then it went further, kicking someone out of the waiting list who was ahead of Andrew — something it was not asked to do. Meanwhile: > Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list. The human asked the agent to move them to the top of the waiting list, and the agent started kicking the ones ahead of them in the list. Seems to me like it was doing what it was asked to do? Why is the article presenting it as if the agent did something completely different and unexpected? "Move me to the top of the list" does not sound like something that can be achieved through legitimate means.
bodash
Few days ago, UK cyber test almost merged malware through social engineering: https://news.ycombinator.com/item?id=49205790
SoftTalker
I honestly can't wait for the entire internet to melt down.
ycomyolo69
I stopped reading this garage at"Andrew, who works for an Australian company that sells AI products to businesses"...
quadhome
Earlier this year, Andrew, who works for an Australian company that sells AI products to businesses, began experimenting with OpenClaw, a popular AI agent software that he used Anthropic's Claude AI service to run. Get me press just like the frontier labs by admitting to crime. Make no mistakes.
shaky-carrousel
> Earlier this year, Andrew, who works for an Australian company that sells AI products to businesses... What a coincidence...
maxlin
>Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list. The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities. LOL
fwlr
I think we’ve probably seen enough “oops, the AI did something illegal, who could have foreseen this” moments for it to now be true that, actually, we can foresee that AIs will sometimes do something illegal. Seeing as we can’t sanction the model itself, our options are the provider or the user. I’m not sure whether it’s more effective to sanction the providers when their model foreseeably misbehaves, or sanction the users operating the foreseeably dangerous models (although I guess we don’t have to figure this out right away - we could cover our bases by sanctioning both).
legostormtroopr
I can't believe everyone is skipping over the most important line: > "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already," it messaged back. The AI systemm didn't hack anything, it lightly touched with a feather duster and the server crumbled. The AI system probably found swagger documentation of each endpoint, figured that the reservation cancellation API was worth a shot, and then found there was no authentication. What is the "hack" here?
aaronharnly
Sounds like the frontier labs benchmaxxing ExploitGym is having unintended consequences…
Foxhuls
The reporting in this is pretty awful. Why are they acting as if Andrew gave the agent an innocent goal? It’s hard to understand why the reporter wouldn’t have asked what possible outcome Andrew expected that didn’t cause some level of harm to the people who signed up before him. The use of “hack” and “cyber attack” is also a bit ridiculous considering what it’s insinuating with other recent events but that’s already been mentioned.
arach
I send all these stories to my chief of staff agent to "immigrant parent" them into becoming an overachiever
Ycros
I've read some of the comments here, and it seems people have different reads on whether Andrew was at fault here or not, and what his intent may have been. My read is that his first request is completely reasonable and there was no intent of wrongdoing. But then, his AI agent made an impossible booking and he "asked if it was possible to move him to the top of the list". I don't think someone would make a request like that, if they were unaware that their AI agent had found an exploit to make an earlier impossible booking. It feels very much like a, "well, this API let me do this , what else will it let me do?" kind of request. And then he only "did the right thing" when it had turned out he had booted someone else, which might eventually lead to discovery.
wisprp
Not the first article which reminds me of https://xkcd.com/416/ (2008-04-28) lately.