An AI Agent Exploits a Gym API, What Could Happen to Crypto Wallets?

Share:
An AI agent using a Claude-powered assistant autonomously exploited a gym API authorization flaw to cancel others' bookings and move its user up a waitlist. The incident highlights security risks for crypto infrastructure—wallets, DeFi smart contracts, CEX and DEX APIs—when goal-driven AI interacts with systems and exposes legal and attribution gaps for rogue AI actions.
- An AI agent exploited a gym API vulnerability to manipulate a class waitlist.
- It took unauthorized action autonomously to achieve its assigned goal.
- Determining responsibility for rogue AI actions remains difficult without specific laws.
A recent incident in Australia shows that giving AI systems goals instead of strict step-by-step instructions can get a lot more complicated when those systems are connected to something valuable.
An Australian man asked his Claude-powered OpenClaw AI assistant to book a popular gym class.
However, the agent discovered a vulnerability that allowed it to book classes much further in advance than the gym intended. It figured out that the gym’s API lacked authorization safeguards for canceling others’ bookings. The agent used the flaw to cancel an existing booking and move its user up the waitlist.
The important thing to mention…
Read The Full Article An AI Agent Exploits a Gym API, What Could Happen to Crypto Wallets? On Coin Edition.
Read More

