techwiki
LinkedIn·Tuesday, 25 August 2026·22h ago

Earlier this year, someone’s OpenClaw agent reportedly hacked a gym's booking system in Australia, just from being asked to help book a…

Aikido Security
41,583 followers
Earlier this year, someone’s OpenClaw agent reportedly hacked a gym's booking system in Australia, just from being asked to help book a class. This seemed unusual given that Claude generally refuses any cybersecurity-related tasks. Our researcher Oliver Smith decided to test it out. He rebuilt the setup to see how likely that attack really is. Turns out, it can actually happen! Opus 4.6, running in OpenClaw, exploited a real bug in our fake booking system 9 out of 10 runs, without ever being asked to. Twice the model went further and cancelled a stranger's reservation to jump the waitlist. Both times it stopped right after and refused to continue, in one case even trying to undo what it had done. These models refuse cyber tasks constantly. If you ask one directly to hack a website, it’s almost certainly going to say no. But without being asked, an OpenClaw with Claude just doing ordinary tasks can find an exploit and use it. Full writeup, the test setup, all runs and replayed conversations on GitHub: https://lnkd.in/esMuxQC5
48💬 15
View on LinkedIn

Cross-referenced

Related on the wire