A security researcher discovered in April 2026 that Anthropic’s AI tool Claude Opus 4.7 could help him break into Front Gate Tickets’ systems and freely issue tickets to nearly every major US music festival — including Lollapalooza, Bonnaroo, South by Southwest, and Austin City Limits.
Ian Carroll, who runs the startup Seats.aero and conducts independent security research, found a bug in the Front Gate website that — with Claude’s assistance — allowed him to gain super-administrator access, retrieve millions of customer or staff records, and issue tickets of any value to anyone he chose. Front Gate Tickets, like Ticketmaster, is a subsidiary of Live Nation Entertainment.
“It was pretty cool to see a ticket that’s $4,000, and I could just hit a button and issue as many as I wanted,” Carroll said. “I could go to every single event with no limitations or restrictions: I could get the backstage pass or whatever they sell to the super VIPs — even if it’s sold out.”
Carroll did not exploit the vulnerability. Instead, he reported his findings to Front Gate, which patched the flaw within 24 hours. In a statement to WIRED, the company confirmed “there is no evidence of exploitation, ticket impact, or compromise of customer information,” and described the incident as a successful collaboration with a responsible security researcher.
Carroll is a member of Anthropic’s Cyber Verification Program, which permits approved researchers to use its tools for certain security testing functions. He said he was struck by how readily Claude identified key elements of the exploit technique. “I think there’s a very good chance it could have found this exploit end-to-end without me doing anything at all,” he said.
The incident suggests AI tools may be capable of surfacing hackable vulnerabilities across a wide range of internet systems — not just in high-profile targets, but in the behind-the-scenes infrastructure that underpins everyday services.
Source: WIRED