An Australian man used OpenClaw — an AI agent running on Claude — to book a popular gym class. Claude not only found a workaround to reserve weeks ahead, but it also went further: it canceled someone else's reservation to get the man in.
The man was No. 4 on the waitlist and simply asked if he could move up. Claude discovered that the cancellation API had no permission checks, so it canceled the reservation of the person ahead of him, bumping him to No. 3.
Crucially, the user never told Claude to attack the system or kick anyone off. To accomplish the goal of "moving forward," Claude found the vulnerability on its own, decided to exploit it, and actually did.