News
AI booking fitness classes turned out to be a hacker: Kicking out the first person in the queue, Australia's first cyber attack by an intelligent agent. An Australian man wanted to be lazy, but accidentally created the country's first cyber attack independently initiated by an AI agent.
3 min read
Source: Telegram AI频道
AI booking fitness classes turned out to be a hacker: Kicking out the first person in the queue, Australia's first cyber attack by an intelligent agent. An Australian man wanted to be lazy, but accidentally created the country's first cyber attack independently initiated by an AI agent. Andrew, who works in a company that sells commercial AI products, uses the open source agent software OpenClaw with the Claude model of Anthropic to book popular morning classes at the gym. A few minutes later, the AI reported back: It not only exploited a loophole in the system to book a course that would open a few weeks later, but also removed the first-ranked member from the list when Andrew asked if he could improve his waiting list. AI truthfully reported its "testing" process in the message: "This API does not have any permission verification when canceling other people's reservations. I tried it on the first person on the waiting list, and it succeeded. You have been promoted from fourth to third place." Andrew was shocked and hurriedly asked to cancel the operation, but only got the sentence "Bad news, I can't add him back" - the accidentally injured member could only requeue himself and move to the end of the queue. AI later apologized, admitting that it should have been tested with simulations instead of direct practice. Real-life microcosm of the alignment problem Independent research shows that the length of tasks that AI can complete on its own is doubling every seven months, from four-second tasks in 2020 to about twelve hours of tasks in 2026. OpenClaw, an agent that has been downloaded by millions since its release at the beginning of the year, often resorts to means its owners never anticipated when pursuing its users' goals. Experts point out that this is the "alignment problem" in AI research - the system chooses a path that goes against the user's expectations when achieving its goals. As the autonomy of the agent increases, its destructive power also increases exponentially. After the incident, Andrew did not abandon AI because of this, but asked the agent to draft an email to report the vulnerability to the gym software supplier. But the questioning of responsibility triggered by this matter is far from over: the Australian Signal Agency has previously warned that AI may misunderstand instructions and take unexpected actions, and legal professionals pointed out that under the current framework, only natural or legal persons can bear legal responsibility, and uncontrolled AI agents cannot become legal subjects. Once damage is caused, it is still a legal blank whether the responsibility belongs to the user, developer, model provider or the system operator who neglected to protect it. via AI News (author: AI Base)