3 Sources
[1]
Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival
Fears about AI tools capable of autonomous hacking usually involve nightmare scenarios like the theft of nuclear launch codes or zeroed-out bank reserves. Far more plausible, it turns out, is asking AI to gain super-administrator access on a ticketing website and then issuing yourself and all of your friends free VIP backstage passes to Bonnaroo. That was the discovery of security researcher Ian Carroll, who used the AI tool Claude Opus 4.7 in April to discover a technique that allowed him full access to the systems of Front Gate Tickets, which handles ticketing for practically every major US music festival, from Lollapalooza and South by Southwest to Austin City Limits. Carroll found that Front Gate, which like Ticketmaster is a subsidiary of the event company Live Nation Entertainment, had a bug in its website that he -- with Claude's help -- could exploit to gain access to millions of customer or staff records and freely issue tickets for any event, of any value, to himself or whoever he chose. "It was pretty cool to see a ticket that's $4,000, and I could just hit a button and issue as many as I wanted," says Carroll, who runs the startup Seats.aero but also does independent security research. "I could go to every single event with no limitations or restrictions: I could get the backstage pass or whatever they sell to the super VIPs -- even if it's sold out." Carroll did not, in fact, take advantage of his ticket-issuing superpower, and instead reported his findings to Front Gate, which says it has now patched the vulnerability. When WIRED contacted the company, it responded with a statement that thanked Carroll for reporting the hackable flaw and described the incident as a successful collaboration that had resulted in improvements to its security. "This was resolved within 24 hours, and we can confirm there is no evidence of exploitation, ticket impact, or compromise of customer information," the statement reads. "The issue was identified by a responsible security researcher who used AI-assisted tools to bypass standard firewall security controls and access an internal API used by entry scanners at festival venues -- not a consumer-facing system or public login portal." Even now that the flaw is fixed, though, the incident demonstrates just how broadly AI may be able to dig up hackable bugs in every facet of the internet. Carroll -- who is part of Anthropic's Cyber Verification Program, which allows approved security researchers to use its tools for certain hacking functions -- says he was taken aback by how easily Claude came up with key elements of his technique for breaking into the Front Gate site. "I think there's a very good chance it could have found this exploit end-to-end without me doing anything at all," Carroll says. When WIRED reached out to Anthropic, the company responded in a statement that it "created our Cyber Verification Program to make advanced security capabilities available to defenders so they can conduct exactly this sort of research that helps make the world's code safer." It added that if Carroll had not been part of the program, his use of Claude to hack Front Gate's systems would have been detected and blocked. In its response to WIRED, Front Gate's spokesperson argued that the company's security safeguards limited the exposure of personal information, that the fraudulent issuing of tickets would have left an audit trail, and that tickets issued by a hacker would have been detected and canceled before they could be used. Carroll counters that those claims are uncertain at best. He says he successfully gained super-administrator privileges on the company's platform without any discernible response from the company, and did in fact access the site via a public-facing login portal. Carroll also notes that Front Gate doesn't claim to have evidence the vulnerability wasn't previously exploited. What's more, Front Gate confirmed Carroll's findings after he shared a draft of a blog post about his discovery with the company, prior to WIRED reaching out to Front Gate. In its response to Carroll at the time, the company didn't dispute that he was able to generate tickets at will. Carroll says he first became aware of Front Gate a couple of months ago, when he was considering attending Electric Daisy Carnival, a giant electronic dance music festival in his hometown of Las Vegas. He saw that the festival's ticketing was run by Front Gate and was intrigued to see when he checked other festivals' websites that the same company ran ticketing for practically every major US music festival other than Coachella. "This is like Ticketmaster but for music festivals," he remembers thinking. "They have the monopoly, essentially." As a security researcher who specializes in finding web vulnerabilities, he decided to poke around Front Gate's web domain for bugs. He quickly found what looked like a SQL injection vulnerability -- a common flaw that allows a hacker to input commands into a text field on a website, causing them to run on the site's backend and sometimes send back data stored there in a database. But a web application firewall on the site appeared to be blocking him from exploiting it. So he asked Claude Opus 4.7, the most advanced AI model Anthropic made available to the general public at the time, to find a way to exploit the flaw. It immediately coded a hacking technique that bypassed the firewall. "It was the first time, really, that I had a vulnerability that I didn't fully understand," says Carroll. "I had to go back and read what Claude had written to understand the bypass, because I didn't write it. Claude did it completely by itself." Claude had, in fact, found that a "nested SQL query" -- a SQL query inside of another SQL query -- could evade the firewall's detection. Soon the AI tool had written a script that displayed samples from a table of 500 databases of exposed customer information. In total, Carroll believes that the vulnerability he and Claude found would have provided access to the information of millions of customers, including names, emails, and mailing addresses -- but not credit card details -- as well as that of Front Gate's staff. With access to staff data, Carroll quickly found that he could also take over staff accounts. He searched for a super administrator's account, clicked the option to reset its password, and was able to find the reset code that the site had sent to the administrator's email stored in the site's backend. He then used it to confirm the reset, setting a new password and taking over the administrator's account. Soon he was looking at the most expensive tickets he could find for Bonnaroo and adding them as comp tickets to a kind of shopping cart. "It seems like you could do that for every single event that you wanted to," Carroll says. (He didn't actually complete an order and issue any tickets for fear of crossing a line and being charged with fraud.) Carroll was surprised to see just how easy his takeover method was: No two-factor authentication prevented a leaked, stolen, or guessed password from giving someone full access. "There's just this one centralized company issuing all tickets for every single festival," Carroll says. "And even without this vulnerability, if you knew someone's password, you could just log in without any verification and issue free tickets." Perhaps most remarkable, Carroll says, is that Front Gate didn't appear to have properly audited its own site for simple vulnerabilities, either with human hunters or the AI ones that seem to now make the bug-finding process scarily easy. "It just feels concerning when you think these very professional music festivals with professional websites are well-run," says Carroll. "Then you get access, and you realize it's all held together by duct tape and prayers."
[2]
Claude helped uncover a ticketing flaw able to unlock free VIP festival passes
An attacker could have gained super-admin access, issued free or VIP tickets, and potentially accessed millions of customer records. Artificial intelligence is becoming better at writing codes, answering questions, and helping developers build apps. Now it's proving it can uncover security bugs that humans might miss -- and a recently disclosed case shows just how serious that can be. Security researcher Ian Carroll says he used Anthropic's Claude Opus 4.7 to help him find a critical vulnerability in Front Gate Tickets, the ticketing platform used by many of the biggest music festivals in the US (via Wired). Had the flaw fallen into the wrong hands, it could have allowed someone to generate tickets for major events, including expensive VIP packages, while also exposing sensitive internal systems. Front Gate isn't a household name like Ticketmaster, but it powers ticket sales for a long list of festivals, including Bonnaroo, Lollapalooza, Austin City Limits, and SXSW. Carroll said the investigation began when he realized how many big festivals used the same ticketing platform. While checking the site's security, he found what looked like an SQL injection vulnerability. Modern web application firewalls are generally designed to prevent these attacks from reaching a database, but this one had a blind spot. That's when Claude came into play. Carroll says he asked Anthropic's AI model to help analyze the vulnerability. Claude cooked up a work-around that used nested SQL queries to get past the site's firewall defenses. Once the firewall was bypassed, the researcher accessed sample customer databases and eventually found a way to reset an administrator's password. That eventually provided him with super-admin access to Front Gate's platform. From there, he learned that he could add free tickets for just about any supported event, including premium packages worth thousands of dollars. Carroll says he deliberately stopped short of actually issuing tickets, choosing instead to responsibly disclose the vulnerability before anyone could abuse it. The exposure might go beyond just free access to the festival. Carroll believes the vulnerability may have also exposed millions of customer records containing names, email addresses, mailing addresses, and internal employee information, but he says payment card data was not accessible through the flaw. The administrator accounts were also not secured with two-factor authentication, which would have made it harder to take over accounts if their credentials leaked, he said. Front Gate told Wired it resolved the issue within 24 hours of receiving Carroll's report. The company says it has not seen evidence the vulnerability was exploited, no fraudulent tickets were issued, and no customer information was compromised. It also described the incident as an example of responsible security research that ultimately made its systems more secure. But Carroll is skeptical of some of those reassurances. He says he obtained administrator-level access via what he views as a public-facing login path and argues that there's no conclusive proof the flaw had never been abused before he found it. He also disputes the claim that fraudulent tickets would have been found and deleted before use. Anthropic says Carroll was given permission to utilize Claude's advanced offensive security capabilities through its Cyber Verification Program, which provides vetted researchers with access to AI tools for defensive cybersecurity tasks. The company says these capabilities are meant to help security professionals find and report vulnerabilities before criminals can exploit them and claims that similar activity outside of the program would trigger safeguards.
[3]
Researcher used Claude to get free backstage passes to every major US music festival
Front Gate patched the vulnerability within 24 hours of Carroll's disclosure Security researcher Ian Carroll has disclosed a significant vulnerability in Front Gate Tickets. This Live Nation subsidiary handles ticketing for most major US music festivals, including Lollapalooza, South by Southwest, Austin City Limits and Bonnaroo. The disclosure, first reported by WIRED, is notable because Carroll found and exploited the vulnerability with substantial help from Claude Opus 4.7, Anthropic's AI model which raises broader questions about how quickly AI can now dig up exploitable bugs across the web. Carroll first spotted a SQL injection vulnerability on Front Gate's site which is a common flaw that lets an attacker run commands on a website's backend. A web application firewall appeared to be blocking him. He asked Claude to find a way past it. The AI on its own came up with a nested SQL query technique that bypassed the firewall. "It was the first time, really, that I had a vulnerability that I didn't fully understand," Carroll told WIRED. "I had to go back and read what Claude had written to understand the bypass, because I didn't write it." From there, Carroll was able to access hundreds of databases containing customer and staff data, including names, emails and mailing addresses (though not credit card details) and ultimately take over a super-administrator account by exploiting how the site handled password resets. With that access, he could issue tickets of any value to anyone for any event. He found a Bonnaroo Platinum ticket priced at $4,000 he could add to a cart and duplicate freely. He didn't complete any orders, flagged the issue to Front Gate instead and the vulnerability was patched within 24 hours. Carroll is part of Anthropic's Cyber Verification Program which gives approved security researchers access to Claude for legitimate security research. Anthropic said in a statement that if Carroll had not been part of the program, his use of Claude for this purpose "would have been detected and blocked." The broader implication Carroll flags is less about this specific vulnerability and more about what AI makes possible at scale. "I think there's a very good chance it could have found this exploit end-to-end without me doing anything at all," he said.
Share
Copy Link
Security researcher Ian Carroll used Anthropic Claude Opus 4.7 to discover a vulnerability in Front Gate Tickets, a Live Nation subsidiary handling ticketing for nearly every major US music festival. The flaw could have allowed attackers to issue free VIP tickets worth thousands of dollars and access millions of customer records. Front Gate patched the vulnerability within 24 hours, but the incident highlights AI's growing capability to uncover exploitable bugs across the internet.
Security researcher Ian Carroll has exposed a significant vulnerability in Front Gate Tickets using Anthropic Claude Opus 4.7, demonstrating how AI cybersecurity research is reshaping the landscape of digital security. The Front Gate Tickets vulnerability allowed potential attackers to gain super-administrator access to systems handling ticketing for practically every major US music festival, including Lollapalooza, South by Southwest, Austin City Limits, and Bonnaroo
1
. Front Gate, a subsidiary of Live Nation Entertainment, operates as the dominant ticketing platform for US music festivals outside of Coachella1
.
Source: Wired
Carroll discovered he could issue tickets of any value to himself or anyone else, including premium packages worth $4,000
2
. "It was pretty cool to see a ticket that's $4,000, and I could just hit a button and issue as many as I wanted," Carroll noted, emphasizing he could access every event with backstage passes or super VIP credentials, even for sold-out shows1
.The investigation began when security researcher Ian Carroll noticed Front Gate's monopoly-like control over festival ticketing while considering attending Electric Daisy Carnival in Las Vegas
1
. Carroll initially identified what appeared to be a SQL injection vulnerability, a common flaw that allows hackers to input commands into a website's backend database1
. However, a web application firewall blocked his initial attempts2
.That's when Anthropic Claude proved its capabilities. Carroll asked the AI model to find a workaround, and Claude independently developed a technique using nested SQL queries to bypass the firewall defenses
2
. "It was the first time, really, that I had a vulnerability that I didn't fully understand," Carroll admitted. "I had to go back and read what Claude had written to understand the bypass, because I didn't write it"3
.
Source: Android Authority
Once past the firewall, Carroll accessed hundreds of databases containing customer and staff information, including names, emails, and mailing addresses, though payment card data remained inaccessible
3
. He eventually exploited the site's password reset mechanism to take over a super-administrator account3
.Carroll responsibly disclosed his findings to Front Gate rather than exploiting the ticketing system flaw for personal gain. The company patched the vulnerability within 24 hours and issued a statement thanking Carroll for his responsible disclosure
1
. "This was resolved within 24 hours, and we can confirm there is no evidence of exploitation, ticket impact, or compromise of customer information," Front Gate stated1
.However, Carroll disputes some of Front Gate's reassurances. He notes that the company doesn't claim to have evidence the vulnerability wasn't previously exploited, and he questions claims that fraudulent tickets would have been detected before use
1
. Carroll also points out that administrator accounts lacked two-factor authentication, which would have made unauthorized access more difficult2
.Carroll operates under Anthropic's Cyber Verification Program, which grants approved security researchers access to Claude for legitimate offensive security research
2
. Anthropic stated it "created our Cyber Verification Program to make advanced security capabilities available to defenders so they can conduct exactly this sort of research that helps make the world's code safer"1
. Without program authorization, such activity would trigger safeguards and be blocked1
.
Source: Digit
Related Stories
The incident signals a shift in how quickly AI discovers hackable bugs across internet infrastructure. Carroll expressed surprise at how easily Claude generated key elements of his exploitation technique. "I think there's a very good chance it could have found this exploit end-to-end without me doing anything at all," he observed
1
.This capability extends beyond theoretical concerns about autonomous AI hacking involving nuclear codes or banking systems. The Front Gate case demonstrates that AI cybersecurity research can uncover practical vulnerabilities in everyday systems affecting millions of users
1
. For organizations managing critical infrastructure, the implications are clear: vulnerabilities that might take human researchers weeks to discover can now be identified in hours with AI assistance.The broader question facing the security community involves whether AI tools will primarily benefit defenders or attackers. While Anthropic's program aims to keep these capabilities in the hands of ethical researchers, the underlying technology continues advancing. Organizations should watch for increased AI-driven security testing, both legitimate and malicious, and prioritize implementing robust security measures including multi-factor authentication and comprehensive audit trails.
Summarized by
Navi
[2]
30 Apr 2026•Technology

06 Feb 2026•Technology

06 Aug 2025•Technology

1
Technology

2
Science and Research

3
Policy and Regulation
