When security researcher Ian Carroll began probing the defenses of Front Gate Tickets, he didn't rely solely on his own expertise. He turned to Claude Opus 4.7, an AI tool from Anthropic, to help find a way in. What Claude helped him discover was a vulnerability that could have allowed him—or any attacker—to issue free VIP backstage passes to almost every major US music festival, from Lollapalooza and South by Southwest to Austin City Limits and Bonnaroo.
The Vulnerability: Super-Administrator Access
According to WIRED, Carroll, who runs the startup Seats.aero but also does independent security research, used Claude in April to discover a bug in Front Gate's website. He found that with AI assistance, he could exploit the flaw to gain super-administrator privileges on the platform, accessing millions of customer or staff records and issuing tickets for any event at any value.
"It was pretty cool to see a ticket that's $4,000, and I could just hit a button and issue as many as I wanted," Carroll told WIRED. "I could go to every single event with no limitations or restrictions: I could get the backstage pass or whatever they sell to the super VIPs—even if it's sold out."
Carroll, who is part of Anthropic's Cyber Verification Program—which allows approved security researchers to use its tools for certain hacking functions—was struck by how easily Claude generated key elements of his technique. "I think there's a very good chance it could have found this exploit end-to-end without me doing anything at all," he said.
Business Impact and Response
The bug affected Front Gate Tickets, a subsidiary of Live Nation Entertainment (which also owns Ticketmaster). The company responded to WIRED with a statement thanking Carroll and noting the fix:
"This was resolved within 24 hours, and we can confirm there is no evidence of exploitation, ticket impact, or compromise of customer information."
The statement described the issue as an internal API used by entry scanners at festival venues—not a consumer-facing system. However, Carroll countered that he successfully gained super-administrator privileges without any discernible response, and did access the site via a public-facing login portal.
| Aspect | Details |
|---|---|
| Researcher | Ian Carroll (Seats.aero) |
| AI Tool | Claude Opus 4.7 |
| Company | Front Gate Tickets (Live Nation) |
| Vulnerability | Super-admin access via bug |
| Potential Impact | Unlimited free tickets, data access |
| Response | Patched within 24 hours, no evidence of exploitation |
Front Gate also argued that fraudulent tickets would leave an audit trail and would be detected and canceled before use. But Carroll noted the company didn't claim to have evidence the vulnerability wasn't previously exploited.
Implications for Enterprise Security
Although the flaw has been fixed, the incident demonstrates how AI can broadly uncover bugs in internet-facing systems. Anthropic responded in a statement: "We created our Cyber Verification Program to make advanced security capabilities available to defenders so they can conduct exactly this sort of research that helps make the world’s code safer." The company added that if Carroll had not been in the program, his use of Claude would have been detected and blocked.
For enterprise technology leaders, the case underscores that AI is becoming a double-edged sword: capable of both finding and exploiting vulnerabilities. It also highlights the importance of proactive security research programs—whether through industry initiatives like Anthropic's or internal bug bounty programs. As Carroll noted, the ease with which Claude helped find a critical bug in a major ticketing platform suggests that similar vulnerabilities may exist in many other systems, waiting to be discovered—by defenders or attackers.