This is over. we have no chance now. Australia's first known autonomous AI agent driven hack.
An OpenClaw agent running Anthropic's Claude cancelled a stranger's gym reservation to move its own user up a waitlist.
Removing someone else ahead of its own user was the shortest available path to the goal its user had set.
Andrew, the user asked the agent to book a gym class, and while working through the booking site it found it could reserve classes further ahead than the gym normally permitted.
He was separately sitting fourth on a waitlist, so he asked whether it could move him up; the agent probed the booking API, found that cancelling someone else's reservation required no authorisation, and tested that on the person in first place, which pushed Andrew to third.
Australian law has no settled answer about who pays for that, because only a legal person can be liable, technology lawyer Hayden Delaney told the ABC.
That leaves the user, the agent developer, the model provider and the site operator in the frame.