A security researcher named OpenClaw discovered an API vulnerability allowing users to cancel other people's gym reservations. The flaw lacked basic authorization checks, enabling an attacker to manipulate waitlists by deleting existing bookings. This incident highlights the persistent risk of insecure APIs when integrating generative AI tools for automated web interaction.