Hackers have found a software flaw in a brand of “cold” Bitcoin wallet—considered one of the safest places to store cryptocurrency—and are siphoning tens of millions of dollars in an ongoing attack, Bloomberg reports.

Late last week, Canada-based Coinkite Inc. notified users of its Coldcard devices that a security flaw in the keys that protect their Bitcoin had compromised some wallets. By Monday, more than 1,755 of the tokens worth some $110 million had been drained from roughly 5,000 wallets, according to Galaxy Research.

The source code of Coldcard has always been open and publicly available, which is why there is no choice but to assume that someone used artificial intelligence (AI) to analyze previous versions of the embedded firmware and encountered this vulnerability, the company said in a blog post. A few weeks ago, the company used one of the best AI models available to check for security issues, but it didn’t find this bug, and it didn’t find anything serious at all, Coinkite added.

Both hackers and those being protected from them have the same AI tools, but today it didn’t help the company, it only helped the bad guys, it emphasized.

As per engineers at Block Inc., a fintech company led by X co-founder Jack Dorsey, the Coldcard vulnerability made the “ seed phrase,” a long sequence of words used to log in to a wallet, predictable.

According to them, the problem arose from how Coinkite implemented the random number generator to form these phrases. In particular, one of the custodian mechanisms generated keys using predefined values, such as the device’s serial number.

Coinkite has already released a software update to fix the issue.

Coldcard offers “cold” wallets, which are isolated from the internet. This type of wallet is still considered the most reliable way to store cryptocurrency.