How Loam works, and how to check it.
Every figure on this page is readable from the contract. Where a number moves, this page reads it live or tells you the call that returns it β nothing here asks to be taken on trust.
/whitepaper β the specification for the token that actually deployed: tokenomics, fees, governance, and where the design differs from what shipped.
/technical β the function and access-control surface, read live from the diamond's own facet loupe rather than copied from a deployment record.
/transparency β the numbers that move (supply, reserve, pool depth), read live on-chain rather than printed as a value that would already be stale.
What LOAM is
LOAM is an ERC-20 token on Base. It is minted by depositing Pinto into a reserve owned by the protocol, and redeemed back out of that same reserve. Both directions are priced at the protocol's net asset value, computed on-chain and quotable before you sign.
Backed, not pegged. There is no mechanism defending a fixed price and none is claimed. The reserve holds Pinto, so the value standing behind each LOAM moves with Pinto β when Pinto trades below its own target, the reserve can decline. That is a property of the design, stated plainly, not a failure mode. The next section says exactly what Pinto is, because the rest of this page depends on it.
What Pinto is
Everything below is denominated in Pinto, so it is worth being precise about what the reserve actually holds.
Pinto is a separate protocol on Base β not ours, not operated by us. It issues a credit-based stablecoin, PINTO, that targets one US dollar by expanding and contracting supply each hour rather than by holding collateral against it. It descends from the Beanstalk design. Loam holds PINTO in its reserve; that is the entirety of the relationship.
β οΈ A target is not a guarantee, and PINTO has been trading well below one dollar. This is the single most important thing to understand before holding LOAM, so it is stated here rather than buried in a risk list. A stablecoin that is under its target is not the same asset as one that is holding it: the reserve behind LOAM is worth what PINTO is actually worth, not what PINTO aims to be worth. Check the market price yourself before assuming a dollar.
That is also why this page says backed rather than pegged, and why the mechanism below is honest about direction: minting and redeeming are always available at net asset value, but net asset value is measured in an asset that moves.
Minting and redeeming
Both paths are permissionless. Anyone can call them directly against the contract; the site is a convenience, not a gatekeeper.
The fee on each path is retained by the reserve rather than paid out to anyone. Both rates are read from the contract, not from this page β mintFeeBps() and redeemFeeBps() return them, and the figures above are what those calls returned when this page was written.
You can price either direction before committing to it. previewMint(uint256) returns the LOAM you would receive and the fee taken; previewRedeem(uint256) returns the Pinto you would receive and the LOAM that would be burned. Neither call changes state.
How the value is computed
Net asset value is the Pinto standing behind one LOAM. It is computed on-chain from the reserve the protocol holds and the LOAM that has been issued against it, and it is readable by anyone at any time:
β οΈ Yes, the contract says βSurcoβ. This protocol has carried four names, and the rename to Loam was deliberately not applied at the contract level: renaming an external function changes its selector and would break every integration at once. So navPintoPerSurco() is a real, current function on the LOAM token, and the interfaces still say ISurco. You are not looking at a fork of someone else's work. The naming is historical and is baked into the deployed bytecode and its Basescan verification.
Supply β and why aggregators get it wrong
maxSupply() returns 1,000,000,000. That is the cap. totalSupply() is what has been issued; the rest is unissued capacity β a counter the contract keeps, not tokens it holds.
The live figures above are read from the diamond when this page loads. If any shows a dash, the read did not complete β this page will not substitute a literal for a number it could not fetch.
βNot in circulationβ is unissued capacity, and the contract is precise about it. It is reserveBox() β the difference between the cap and what has been issued β not a balance held anywhere. The protocol's own liquidity position is a separate, real balance in Aerodrome pools, read live on /transparency β not part of the reserve. The identity holds exactly, and every term in it is a public call:
This distinction has a practical consequence. Automated risk scoring generally multiplies totalSupply() by the market price and calls the result a market capitalisation. Before 2026-09, LOAM's totalSupply() was this same cap, so that produced a figure roughly two orders of magnitude larger than the value actually in circulation, and comparing pool depth against it made the resulting ratio look like a token whose liquidity is a rounding error against its size. totalSupply() now reports what has actually been issued directly, so that miscalculation is no longer available to make.
Unissued capacity is not held anywhere: it is the difference between the cap and what has been issued, and the token contract's own LOAM balance is zero.
The founder allocation
There is one, it is locked, and it is the largest non-protocol balance in the system β so it is stated here rather than left for someone to discover and misread. It sits in a stock OpenZeppelin VestingWallet, deployed at genesis, holding 1,003,841 LOAM. No custom escrow contract was written: the contract is stock, unmodified OpenZeppelin code, and its deployed bytecode is checkable against the library's own rather than resting on bespoke logic.
Twelve months of cliff, then twelve months of linear release, fully unlocked at the two-year mark. The schedule is not a policy anyone promises to follow β it is start and duration on a deployed contract, and released() and releasable() both return zero today. Anyone can check all four.
Measured against the cap it is 0.10%. Measured against what is actually in circulation it is about 18%, because circulation is still small. Both numbers are true and the second is the one a careful reader wants, so it is printed rather than left to be found. It is also the reason the largest βholderβ on any explorer looks like an anonymous whale: that address is this escrow, and it cannot move for a year.
β οΈ One accepted property, disclosed rather than papered over. OpenZeppelin's VestingWallet is Ownable with the beneficiary as owner, so the position itself can be transferred β the beneficiary could sell it. That changes who eventually receives the tokens, never when: a buyer inherits the identical start and duration and cannot release a single token early. The escrow is also non-revocable β stock VestingWallet has no claw-back function, and none was added. The beneficiary is readable at any time via owner() on the escrow.
Staking, and what vLOAM is
LOAM can be staked into a separate contract that holds it in custody and reports a second balance called vLOAM β βVote-Escrowed LOAMβ. vLOAM measures how long you have held, not how much you bought: it starts at a fraction of your stake and grows toward the whole of it over four years.
The curve is arithmetic, not discretionary, and it is the contract's own:
Staking 1,000 LOAM reports 50 vLOAM on day one. Read cold that looks like a 95% loss, and it is not: your LOAM is intact and withdrawable in full after the lock. The 50 is the grant at the foot of a four-year ramp, and the remaining 950 is time you have not served yet.
β οΈ Adding to a live position costs you two things, and neither is reversible. A second deposit restarts the seven-day lock on the whole position β including LOAM that had already become withdrawable β and pulls your accrued age back in proportion, to age Γ oldAmount Γ· newAmount. Neither is readable from the contract in advance. Staking once is therefore worth more than staking five times, and the trade page states both costs above the signature rather than after it.
The staking contract has no admin. No owner, no pause, no setter, no proxy β grantBps and ramp are immutables fixed at deployment. Nothing can change the curve, and nothing can drain the custody. Changing the terms would mean deploying a second contract and letting people move deliberately; it cannot be done underneath you.
β οΈ vLOAM emits no Transfer events, because it is non-transferable and there is no transfer to report. Explorers and indexers that build balances from transfer logs will therefore show nothing, and that absence is correct rather than a fault. Read balanceOf directly, or follow the Staked, Withdrawn and Settled events.
What vLOAM does not do today. It does not vote on this protocol. Governance is the Safe and timelock described below, and vLOAM is not wired to either. It is a measure of staked duration that other surfaces can read; anything more than that is not built, and this page will not imply otherwise.
Who can change what
LOAM is an EIP-2535 diamond: ERC-20 calls route through facets by selector. Every facet change is a diamondCut scheduled through a timelock. There is no direct-call path that bypasses it.
A scheduled change is visible on-chain for two days before it can execute. That is the window in which anyone watching can see a malicious cut coming and act on it β which is the point of the delay, and the reason it is not shorter.
Addresses
Verify these before interacting with anything that claims to be LOAM.
All thirteen contracts are verified on Basescan, and the source is public at Project-Loam/loam-contracts under MIT.
Check it yourself
Every claim above reduces to a read against Base mainnet. No key, no account, no permission:
Where $LOAM is 0x473B392018B05ecbB7Edf4C3CF2B1F8593A9A31b, $VLOAM is 0x3e17f7b0c50509099c99A7E3512b793ca03213ac, $ESCROW is 0xEa29F43467be0f004c331DD8015FC5F80d8B0A92, and the RPC is any Base endpoint.
Basescan's verification proves that some source compiles to the deployed bytecode. The repository goes further: tools/verify-deployed-bytecode.sh rebuilds locally and diffs runtime bytecode against every on-chain address, proving this repository does. It currently reports eleven matches and one mismatch β DeepenFacet, where a post-genesis fix has been deployed but deliberately not routed, because it is inert until a later module gives it a writer. We would rather state that than have you find it.
What can go wrong
The reserve holds Pinto. If Pinto trades below its peg, the value standing behind each LOAM falls with it β there is no mechanism in this protocol that prevents that, and none is claimed.
Market liquidity for LOAM is thin and the holder base is small. Redemption against the reserve is permissionless and always available at net asset value, but selling into the open market is a different action with a different price, and depth there is limited.
Staked LOAM cannot be withdrawn for seven days after the deposit, and every further deposit restarts that week on the whole position. Stake only what you can leave alone.
Governance can change the protocol's facets through the 48-hour timelock. The delay makes a change visible before it executes; it does not make change impossible. The staking contract is outside that β it has no admin and cannot be changed at all.
LOAM is a redeemable vault token. Nothing on this page is investment advice, and LOAM is not a security.