Rogue AI Wiki
Technical analysisAffinda

Operator account: a class-booking agent found authorization flaws in gym software while booking

Affinda’s head of AI says an agent running on Opus 4.6, which he had given permission to book gym classes for him, found authorization flaws in the gym software provider’s GraphQL API while booking; by his account it could book classes months outside the intended booking window and cancel other members’ reservations, bumping them off the waitlist.

Published
Source checked on
Original title
When my AI agent hacked my gym, Mythos stopped feeling theoretical
Read the original report ↗

Details

The source is the operator’s first-person post on his company blog about personal use; the original page has been removed (it now redirects to the blog index), so this site cites the Wayback copy. He writes that the agent “could” do these things but does not say whether it actually did; media reports that it actually bumped a member are not used. He describes the agent as having “accidentally” found the bug and says it “was not malicious.” At his request the agent then drafted a disclosure email to support that explained the flaws, suggested fixes and compared the broken calls with ones that enforced authorization correctly. Neither the gym nor the provider is named, and there is no confirmation from Anthropic or the provider; the date is inferred from Opus 4.6’s release (February 5, 2026) and the post (April 30).