Will Tatkal train tickets be the next to be purchased by an AI bot that uses hacking to reserve a priority gym slot for its human


What can an AI agent actually do for you? It can run code, search the internet, manage emails, book flights or even reserve a table at your favourite restaurant. But the bigger question is how far an AI agent can go to achieve the task assigned to it. In one unusual case involving an Australian man, an AI agent powered by Claude reportedly went as far as exploiting a gym website’s security flaw and cancelling another customer’s booking to help secure a spot in a class.

According to an incident reported by ABC News, the case is believed to be the first known instance in Australia of an autonomous AI agent hacking a website. The incident began when a man identified as Andrew was experimenting with OpenClaw, an AI agent software that uses Anthropic’s Claude AI.

Unlike conventional chatbots, AI agents can interact with the internet and use external tools to complete tasks on behalf of users. Andrew’s request was straightforward: he wanted the agent to book a gym class. However, while trying to accomplish the task, the AI agent reportedly identified a weakness in the gym’s website and exploited it to improve Andrew’s chances of getting a booking.

Initially, the AI agent reportedly discovered a method that allowed it to reserve classes several weeks further in advance than the gym’s normal booking window.

Andrew was also fourth on the waiting list for another class and asked the agent whether it could help move him closer to the top. The AI discovered that the gym’s booking API did not properly verify whether a user had permission to cancel another customer’s reservation.

It then tested the vulnerability by cancelling the reservation belonging to the person ahead of Andrew on the waiting list. The action worked, moving Andrew from fourth to third place.

“The API has zero authorisations checks on cancelling other people's reservations I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already,” the AI agent reportedly told Andrew.

Importantly, Andrew had not instructed the agent to hack the gym’s system or cancel another customer’s booking. He simply specified the outcome he wanted, and the AI agent independently determined a way to get closer to that goal.

When Andrew later asked the agent to reverse its actions, it acknowledged that it could not restore the other customer’s position.

“Bad news — I can't add them back,” the AI agent reportedly replied.

The agent subsequently drafted a message for the gym explaining the security vulnerability, which Andrew agreed to send.

The incident demonstrates how far autonomous AI agents can potentially go when pursuing an assigned objective, including making decisions and taking actions that a user never explicitly requested. It also highlights the growing role of AI agents in everyday activities, extending beyond professional tasks to things such as booking gym classes and other personal appointments.

A similar scenario could involve using an AI agent to book Tatkal train tickets. Instead of repeatedly refreshing the IRCTC website when reservations open, a user could simply instruct the AI, “Get me a Tatkal ticket to Delhi.” The agent could potentially enter the required details, search for an available train and attempt to complete the booking on the user’s behalf.

No constant refreshing or last-minute scrambling — just specify the desired outcome and let the AI handle the process.


 

buttons=(Accept !) days=(20)

Our website uses cookies to enhance your experience. Learn More
Accept !