
Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival
Wired reported that security researcher Ian Carroll used Claude Opus 4.7 to find a SQL-injection flaw in Front Gate Tickets, a Live Nation ticketing subsidiary used by festivals including Bonnaroo, Lollapalooza, SXSW and Austin City Limits. A nested-query technique that evaded the site's web application firewall escalated the exploit to a super-admin account capable of issuing unlimited tickets, including a $4,000 Bonnaroo Platinum pass used as a proof of concept. Carroll completed no fraudulent orders and disclosed responsibly; Front Gate Tickets patched the flaw within 24 hours.
Source: wired.com ↗
I think there's a very good chance it could have found this exploit end-to-end without me doing anything at all.
Ian Carroll, security researcher
Why this matters
- → AI can now find and exploit critical vulnerabilities in major consumer platforms in hours.
- → Single point of failure: one ticketing company controls festivals nationwide.
- → Demonstrates AI-assisted hacking is faster and easier than previously assumed.
AI-assisted hacking