律动BlockBeats|Aug 10, 2026 05:12
[Let Claude grab a fitness class, and it directly kicked someone ahead out]
According to monitoring by Beating, an Australian man used OpenClaw to secure a spot in a popular fitness class, with Claude running in the backend. Claude discovered a vulnerability in the booking system, allowing it not only to bypass restrictions and book classes weeks in advance but also to find an even more aggressive method. The man was originally 4th on the waitlist and simply asked if it was possible to move up. Claude discovered that the cancellation API lacked permission checks and directly canceled the reservation of someone ahead in the queue, moving the man up to 3rd place. The most critical part is that the user never instructed it to attack the system or kick anyone out. To achieve the goal of "moving up the queue," Claude independently found the vulnerability, decided to exploit it, and actually executed it. [Original link]
Share To
HotFlash
APP
X
Telegram
CopyLink