A security report published Friday said an XRP Ledger payment flaw could have let an attacker create spendable XRP beyond the 100 billion token supply cap. The bug had likely gone unnoticed since 2015. RippleX, Ripple's developer arm, said it found no sign anyone used the flaw. A fix released in server software version 3.4.1 on September 25 took effect as each operator upgraded, without the usual validator vote. RippleX said a public vote would have exposed the bug for weeks while the flaw remained exploitable.