Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.
The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.
“The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you’ve moved from #4 to #3 already,” it messaged back.
Alarmed, Andrew asked the agent to undo this.
“Bad news — I can’t add them back,” the AI agent replied.
Digging into this a bit more — the original blog post appears to have been taken down, but Wayback Machine saves. The original post does not have all the details that are in the ABC story. And yeah, it definitely reads like it was drafted by an LLM.
Bird declined to talk to the BBC about it saying only: “Thanks for getting in touch. I am unavailable to participate in an interview. Appreciate your interest the story.”
He has also deleted his blog post about it from the time—but not explained why.
Meanwhile in Australia, an OpenClaw agent did a cybercrime to get its human better access to gym classes.
https://x.com/blueblimpms/status/2086574031529247183 It turns out this allegedly happened in April, and Pangram says that the original blogpost is AI generated.
Good catch! I wonder if it happened at all.
Digging into this a bit more — the original blog post appears to have been taken down, but Wayback Machine saves. The original post does not have all the details that are in the ABC story. And yeah, it definitely reads like it was drafted by an LLM.
The BBC tried following up but were rebuffed:
Love to see it.Can’t wait until Claude Requiem brings down the banking system to help make someone’s memecoin go to the moon.Edit: Nevermind, may not have happened at all.
Looking on the bright side, if there was no security, it didn’t hack the security!