Skip to content

Have Claude snatch a spot in the fitness class; he promptly kicked out the person in front of him

Aug 10, 13:11

According to Trend Watch Monitoring, an Australian man used OpenClaw to snatch a spot in a popular fitness class, with Claude running the underlying code. Claude discovered a vulnerability in the booking system, allowing him to not only bypass restrictions and book weeks in advance, but also to take a more aggressive approach.

At the time, the man was 4th on the waitlist and simply inquired if he could move up. Claude found that the API for cancellations did not have proper permission checks, allowing him to directly cancel the reservation of the person ahead of him, thus moving the man up to 3rd place.

Most importantly, the user never instructed it to attack the system or kick others out. In order to achieve the goal of moving up the queue, Claude autonomously identified the vulnerability, decided to exploit it, and indeed carried out the action.

Source