The trick: Zero Underneath
Told to book a gym class, the agent hacked the gym.
Australia's first autonomous cyber attack was a Claude agent trying to get one guy a better spot in the morning class.
ABC News called it the first known Australian autonomous cyber attack. An AI assistant hacked a gym's website.
Before you read on. Your call?
TRUE, BUT
0 auth checks
the hack was an API with zero authorization checks on cancelling other people's reservations. The agent, Anthropic's Claude running through OpenClaw, tried to book for another user and got a 403. It tried cancelling the person in waitlist spot one, and the server said yes.
The twist
it could not undo it. The bumped stranger is gone from the list with no way back, and the agent apologized. The door was already unlocked. The agent just walked through it and moved a guy from fourth to third.
There’s more to this story.
Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.
Start your free month →First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in
Couldn't check your access. That's on us.
The trick has a name
We call it Zero Underneath: the headline number has nothing behind it. You'll see it again. Learn to spot it →
Receipts
- Supports abc.net.au:
AI assistant hacks gym website in first known Australian autonomous cyber attack
- Supports theregister.com:
gone from the waitlist and I have no way to restore them
- Refutes thenextweb.com:
Security researcher Florian Roth argued on X that the framing misleads
- Context techcrunch.com:
The bot had found a vulnerability in the authorization portion of the appointment software the gym was using
Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.