Researchers have discovered and demonstrated a vulnerability in the XRP Ledger payment system that could allow attackers to create spendable XRP out of thin air without providing funds, thereby breaking XRP's fixed supply rule. The vulnerability is believed to have existed since 2015. RippleX, Ripple's development division, released an emergency software update (xrpld 3.4.1) on September 25 to fix the issue. RippleX stated that there is currently no evidence that the vulnerability has been exploited on any public network.