Claude Helped Hacker Expose US Festival Ticketing Flaw

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Ian Carroll used Anthropic's Claude Opus 4.7 in April to discover a SQL injection flaw in Front Gate Tickets that granted super-administrator access to a backend serving major US festivals including Lollapalooza, SXSW, and Austin City Limits.
- Claude autonomously wrote a nested SQL query that bypassed Front Gate's web application firewall; Carroll said the AI could have found the exploit "end-to-end without me doing anything at all."
- The vulnerability surfaced data across roughly 500 databases, potentially containing names, emails, and mailing addresses for millions of customers plus Front Gate staff records — but not credit card details.
- Front Gate's platform had no two-factor authentication, letting Carroll issue unlimited comp tickets, including $4,000 VIP backstage passes, for any event — even sold-out ones.
- Front Gate Tickets (a Live Nation Entertainment subsidiary) patched the flaw within 24 hours and told WIRED there was "no evidence of exploitation, ticket impact, or compromise of customer information."
- Carroll pushes back on that framing, telling WIRED he reached the system through a public-facing login portal and that Front Gate has not produced evidence the vulnerability wasn't previously exploited.
- Anthropic confirmed Carroll was authorized through its Cyber Verification Program and said his hacking without that authorization would have been "detected and blocked."
Why it matters: Front Gate Tickets runs ticketing for nearly every major US festival besides Coachella, and Carroll found the platform had no two-factor authentication — any guessed password could issue unlimited $4,000 VIP tickets. Carroll says Claude could have found the exploit end-to-end autonomously, illustrating how AI-assisted vulnerability discovery has reached capability levels that even well-funded event platforms' audits haven't matched.




