# Welcome to Pinto! (Start Here)

Welcome to the Pinto farm! Pinto is an algorithmic stablecoin balanced by farmers like you. This documentation is organized to make learning about the protocol as intuitive as possible.

The [“Why Pinto”](/why-pinto/why-pinto-overview) section of the documentation contains essays explaining the inspiration behind Pinto, contextualizing the protocol in the larger crypto ecosystem, covering progress to date, and discussing future development.

The [“Pinto Mechanics”](/pinto-mechanics/mechanics-overview) section of the documentation explains how each component of the protocol contributes to protocol maintenance and why the component is designed the way it is.

The [Pinto whitepaper](http://pinto.money/whitepaper) contains a complete technical spec of the protocol.

The “Pinto PIs” section of the documentation (coming soon) includes descriptions of the improvements made to the protocol since its deployment.

The ["How-To Guides"](/resources/how-to-guides) section of the documentation includes “How To” guides detailing how to use the protocol through the [pinto.money](http://pinto.money) user interface.

Pinto is an experiment. Before interacting with Pinto, consider reading the [Disclosures](/appendix/disclosures).

### Links <a href="#links" id="links"></a>

* [Mechanics Overview](/pinto-mechanics/mechanics-overview)
* [Target Maintenance](/responding-to-state/classifying-state)
* [Glossary](/resources/glossary)
* [Contracts](/resources/contracts)
* [Other Links](/resources/links)


# Why Pinto? Overview

Pinto is founded on the convictions that

1. centralized stablecoins pose an existential threat to the sovereignty of the Ethereum network;
2. fiat is the best currency model, if the power of the printer is used wisely and fairly; and
3. a properly designed set of incentives has the potential to sufficiently minimize the volatility of an on-chain fiat currency to outcompete centralized stablecoins and free Ethereum from the threat of centralized stablecoins.

The following essays give high-level color and context to Pinto from various relevant perspectives.

[Announcing Pinto](/why-pinto/announcing-pinto-leviathan-free-low-volatility-money) is the declaration of the start of the next chapter algorithmic stablecoins from Pinto’s launch in November, 2024.

[Pinto: Prints for the People](/why-pinto/pinto-prints-for-the-people) explains Pinto as an evolution of fiat currency.

[Ethereum at 10 ](/why-pinto/ethereum-at-10-an-existential-threat)explains Pinto as a response to the existential threat posed by centralized stablecoins to the Ethereum network.

[Credit vs Collateral](/why-pinto/credit-vs-collateral) explains why credit based stablecoins have intrinsic economic advantages over collateralized stablecoins.

[Terrable Design: Lessons from Terra's Collapse on the Path to a Scalable Network Native MoE & UoA ](/why-pinto/terrable-design-lessons-from-terras-collapse-on-the-path-to-a-scalable-network-native-moe-and-uoa)responds to the biggest and most frequently cited FUD when it comes to algorithmic stablecoins: “what about Terra!?”

[4 Years of Beanstalk](/why-pinto/4-years-of-beanstalk) recaps the journey thus far to create an algorithmic on-chain fiat currency since Beanstalk, the predecessor to Pinto, was deployed on Ethereum mainnet in 2021.

[Economic Principles](/why-pinto/economic-principles) explains the economic convictions behind the Pinto model.

[Classifying Stablecoins](/why-pinto/classifying-stablecoins) presents a holistic framework to understand the various stablecoin models.

[Why Pinto Contributor Articles](/why-pinto/why-pinto-contributor-articles) are pieces written by contributors to Pinto, past and present, on why they are working on algorithmic on-chain fiat currency.

Pinto Roadmap (coming soon) expounds on important development updates made since the protocol was deployed in November, 2024 and the plans for future development in 2026.

[Values and Properties](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/values-and-properties) defines and briefly explains essential elements that ground Pinto's vision, and how Pinto implements them.


# Announcing Pinto: Leviathan-Free Low-Volatility Money

*“Nothing in the world is as soft and yielding as water. Yet for dissolving the hard and inflexible, nothing can surpass it.*

*The soft overcomes the hard; the gentle overcomes the rigid. Everyone knows that is true, but few can put it into practice.*

*Therefore the Master remains serene in the midst of sorrow. Evil cannot enter his heart. Because he has given up helping, he is people’s greatest help.*

*True words seem paradoxical.”*

*— Lao-tzu, Tao te Ching, Verse 78*

## **An Existential Threat** <a href="#heading-an-existential-threat" id="heading-an-existential-threat"></a>

*“Whatever can happen, will happen.”*

*— Murphy’s Law, 20th Century Proverb*

Quality money empowers individuals and communities. By leveraging the power of a censorship resistant, verifiable, permissionless, globally distributed computer network, BTC has found clear product market fit as the best store of value. However, there has yet to be a comparable success with respect to media of exchange.

Stablecoins promise to serve as reliable media of exchange in the crypto economy. However, leading stablecoins suffer from a centralization flaw that not only limits their utility, but creates an [existential threat](/why-pinto/ethereum-at-10-an-existential-threat) to the integrity of the computer networks they are used on.

Because (1) the centralized operators of leading stablecoins (*e.g.*, Circle, Tether) [dictate](https://x.com/KyleSamani/status/1831034790856003595) the canonical state of networks where the majority of network-native value depends on said stablecoin (*i.e.*, every existing censorship resistant compute network but Bitcoin) and (2) companies are subject to governments, **the canonical state is ultimately subject to governments rather than stakers or miners.**

This reality is a far cry from the goal to create truly censorship resistant, verifiable, permissionless, globally distributed computer networks.

Nonetheless, the demand for quality media of exchange is so great that stablecoins are the crypto asset class that has found foremost product market fit after BTC. While stablecoins make up only 6% of the crypto market cap, 77% of the aggregate crypto trading volume is at least one side stablecoin. The need for a quality censorship resistant, verifiable and permissionless network-native medium of exchange has never been greater.

## **Between a Rock and a Hard Place** <a href="#heading-between-a-rock-and-a-hard-place" id="heading-between-a-rock-and-a-hard-place"></a>

*“Revolution rock, it is a brand new rock”*

*―The Clash, London Calling, 1979*

To date, all attempts to create a censorship resistant network-native medium of exchange with competitive carrying costs to centralized stablecoins have failed due to either (1) excessive carrying costs due to collateral requirements or (2) excessive volatility due to insufficient collateral requirements.

On the one hand, locking up collateral to mint stablecoins realizes incredible opportunity cost which ultimately manifests in high carrying costs. Censorship resistant collateralized stablecoins are unable to compete with centralized stablecoins on carrying costs because there isn’t sufficient quality censorship resistant collateral. Excessive carrying costs for censorship resistant stablecoins compared with centralized stablecoins lead to wider spreads and higher borrowing costs\*.\*

On the other hand, the highly reflexive nature of under-collateralized stablecoins has resulted in fatal excess volatility in almost every implementation to date. Most attempts at under-collateralized stablecoins have experienced a bank run and collapse to \~$0 within months.

There have been 2 notable exceptions, neither of which attempts to maintain a hard peg (*i.e.*, perfect stability) or uses any collateral.

[Ampleforth](https://www.ampleforth.org/) is a rebasing stablecoin that has successfully achieved consistent peg crosses over the course of 5+ years. However, the rebasing nature of the system limits the utility of the currency as money. When below peg, tokens are removed from people’s wallets in order to repeg the stablecoin. While this technique has demonstrated efficacy at regularly crossing the stablecoin price over its peg, it creates a horrible user experience for savers and borrowers alike.

[Beanstalk](https://bean.money/) is a credit based stablecoin protocol that similarly issues dividends to depositors when above peg. But, instead of forcibly rebasing when below peg, Beanstalk incentivizes individual holders to voluntarily burn their stablecoins (*i.e.*, Beans) for an IOU for more Beans under certain conditions in the future (*i.e.*, Pods). While Beanstalk has experienced extended periods below peg, it is the only other non-collateralized stablecoin model that hasn’t crashed to $0 due to a bank run.

## **A Seed of Hope** <a href="#heading-a-seed-of-hope" id="heading-a-seed-of-hope"></a>

*“So you’re telling me there’s a chance”*

*— Lloyd Christmas, Dumb and Dumber, 1994*

Credit is king.

Beyond creating a better experience for stablecoin users, credit presents the only viable option for network-native value with anti-reflexive properties and the potential for infinite scale. The more debt a borrower repays, the more creditworthy the borrower is viewed. Increased creditworthiness enables borrowing more at lower interest rates.

An autonomous agent native to censorship resistant, verifiable, permissionless, globally distributed computer networks and optimized to create credit has the potential to issue a censorship resistant network-native medium of exchange with competitive volatility and carrying costs to centralized stablecoins.

In the 3 weeks prior to its hack in April 2022, Beanstalk began the first ever deleveraging of an autonomous agent. Even after being hacked for every dollar, Beanstalk’s credit history enabled it to borrow an additional $17m of value to recapitalize and restart itself.

Nobody knows what would have happened had Beanstalk not been hacked, but given the efficacy demonstrated by the model both before and after being hacked, there are very good reasons to find out.

## **A Data Problem** <a href="#heading-a-data-problem" id="heading-a-data-problem"></a>

*“Beanstalk is likely being Replanted with a ridiculously high* [*Pod Rate*](/resources/glossary#pod-rate) *in the worst a) macro environment in at least a decade, b) crypto market in years, c) stablecoin market of all time, and d) endogenous circumstances possible, as a result of the attack. This presents an incredible opportunity for the model to demonstrate its efficacy. We will all know very quickly if it is working or not.”*

*— Publius, Thoughts Before the Barn Raise, June 5, 2022*

While the plan to restart Beanstalk in incredibly adverse conditions did lead to high quality data, it did not ultimately indicate whether the model is “working” or not, nor did it best set Beanstalk up for success.

The [Stalk System](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism) of the [Silo](/resources/glossary#soil) has kept Beanstalk alive over extended periods below peg by preventing and limiting the extent of bank runs. Clearly, the deficiencies in Beanstalk lie in (1) its inability to attract creditors in its credit facility (*i.e.*, the [Field](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto)) and (2) incentivize [Converts](/resources/glossary#convert-1) within the Silo to repeg the Bean price.

The [dutch action mechanism](/resources/glossary#morning) theoretically improved the efficacy of the Field to near perfection, but has not been used despite being live for 18 months. The exploit and ensuing terms under which Beanstalk restarted have left it in so much debt it cannot attract creditors at any rate.

Similarly, the [Seed Gauge System](/resources/glossary#seed-gauge-system) overhauled the peg maintenance mechanism by creating tools for Beanstalk to autonomously optimize some of the parameters in the Silo to incentivize particular Converts, yet it has barely been used in its 6 month life. Beanstalk cannot currently incentivize Converts because of certain improperly fixed parameters and a lack of an active user base.

Without users, the theoretical efficacy of the model doesn’t matter. Without data, it is impossible to gauge its practical efficacy and improve it accordingly.

## **Pinto** <a href="#heading-pinto" id="heading-pinto"></a>

*“I got a fever, and the only prescription is more cowbell.”*

*— Will Ferrell as Gene Frenkle, SNL, April 8, 2000*

Today, we are proud to announce the launch of the first ever Beanstalk fork — Pinto: censorship resistant low volatility money.

Pinto implements all the latest features of Beanstalk, [Basin](https://basin.exchange/basin.pdf), [Multi-Flow Pump](https://basin.exchange/multi-flow-pump.pdf), [Pipeline](https://evmpipeline.org/pipeline.pdf) and [Tractor](/pinto-mechanics/toolshed/tractor-automating-the-farm) (*i.e.*, the entire Beanstalk ecosystem code base) and restructures the original Beanstalk debt to give the Beanstalk model a clean shot at success and failure.

We expect Pinto to generate a significant amount of new data that can be used to further refine the Beanstalk model and ultimately create a censorship resistant medium of exchange that outcompetes centralized stablecoins.

## **Why low volatility?** <a href="#heading-why-low-volatility" id="heading-why-low-volatility"></a>

*“Everything flows, nothing stands still.”*

*— Heraclitus*

The term stablecoin gives people the wrong idea. Whereas sufficiently collateralized stablecoins are in fact stable coins, they are not money. Money has endogenous value. Money is volatile in nature. Our goal is to create money with endogenous value because of its censorship resistance, capital efficiency and *low volatility.*

Beanstalk was never intended to create perfect stability. The stablecoin trilemma clearly states that censorship resistance and capital efficiency (*i.e.*, low carrying costs) come at the cost of ideal price stability. However, there is certainly some sufficiently low level of volatility below which a censorship resistant money with competitive carrying costs would compete with centralized stablecoins.

Stablecoin out. Low volatility money in.

## **Why Fork?** <a href="#heading-why-fork" id="heading-why-fork"></a>

*Two gunslingers walked out in the street // And one said, “I don’t want to fight no more” //*

*And the other gunslinger thought about it // And he said, “Yeah, what are we fighting for?”*

*— Tom Petty, Into the Great Wide Open, 1991*

While censorship resistant low volatility money is likely to be a winner take most asset class (*i.e.*, just like censorship resistant store of value, a la BTC), at such an early stage in the development of the asset class, multiple competing versions can be symbiotic.

Beanstalk clearly could benefit from a debt restructure. Doing so requires either (A) proposing a debt restructure to the DAO that would force the restructure on *everyone*, including those that did not vote for it, or (B) deploying a fork that restructures the debt without imposing the restructure on *anyone.*

Forking enables every debt holder in the old version of Beanstalk to retain the entirety of their position in Beanstalk *and* receive an airdrop for additional debt from Pinto.

A true win win, Pinto demonstrates the potential for a healthy and sustainable model for forking the Beanstalk codebase by enabling low friction and permissionless development while honoring prior versions’ debts and without imposing on any participant.

## **Securing Pinto** <a href="#heading-securing-pinto" id="heading-securing-pinto"></a>

*“Fool me once, shame on you; fool me twice, shame on me.”*

*— 17th Century Proverb*

There are two and three separate and independent systems within and without Pinto, respectively, that have been or will be put in place to minimize the risk of another hack.

## **No Governance** <a href="#heading-no-governance" id="heading-no-governance"></a>

Using a fork-based model for upgrades instead of on-chain governance removes the need to vote on upgrading the system. By removing the ability to upgrade Pinto via vote, there is no longer the potential for governance vulnerabilities like the one that was exploited to hack Beanstalk.

While in its early days Pinto will remain [upgradable](/appendix/upgradability) by a multisig under [explicit conditions](/appendix/upgradability#no-governance), the intention is to remove upgradability altogether as soon as is prudent.

## **Beanstalk 3: Secure Beanstalk** <a href="#heading-beanstalk-3-secure-beanstalk" id="heading-beanstalk-3-secure-beanstalk"></a>

This year, the entire Beanstalk codebase was restructured with a prioritization on loss prevention and minimization over gas efficiency. In the past, a significant amount of complexity was added to the code in the interest of lowering farmers’ gas costs to make Beanstalk more accessible. However, this complexity also introduced a significant amount of bugs and, with them, costs via bug bounty programs.

Pinto uses the [Secure Beanstalk](https://github.com/BeanstalkFarms/Beanstalk/pull/909) implementation to minimize the risk of losing funds due to bugs and is deployed on the Base L2 network to minimize fees despite the less gas efficient implementation. Because it is on an optimistic rollup that uses Ethereum mainnet as the base sequencer, Beanstalk gets the low latency and costs of an L2 with the censorship resistance and security of the L1.

## **Bug Bounty** <a href="#heading-bug-bounty" id="heading-bug-bounty"></a>

Beanstalk has had an Immunefi bug bounty covering the Secure Beanstalk codebase with a maximum bounty of 1.1M Beans live for almost 2 months. Although no guarantee, the lack of substantive bug reports since Secure Beanstalk was deployed is very a strong indicator the codebase is secure.

The vast majority of the Pinto codebase is identical to Beanstalk, so Pinto effectively inherits security from the Beanstalk Immunefi bug bounty program. Additionally, a Pinto bug bounty program will be created once the Pinto supply passes 10M for the first time, with one-off mints to fund the program according to the schedule outlined [here](/appendix/upgradability#bug-bounty-mint-schedule).

## **Audit Competitions** <a href="#heading-audit-competitions" id="heading-audit-competitions"></a>

In our experience, public audit competitions are among the highest efficacy ways to discover bugs because of the number of eyes looking at the code simultaneously.

Beanstalk, and thus Pinto, have been heavily audited via various audit competitions. Additionally, we intend to run Pinto-specific audit competitions of the entire codebase once there are enough funds in the development budget.

## **Real-Time Monitoring and Defense** <a href="#heading-real-time-monitoring-and-defense" id="heading-real-time-monitoring-and-defense"></a>

A critical component of a robust security stack is a real-time production monitoring and defense solution. Once there are sufficient funds in the development budget, we intend to setup Hypernative support [similar to Beanstalk’s](https://bean.money/bip-46) (or use another competitive solution) for Pinto.

## **No Governance** <a href="#heading-no-governance-1" id="heading-no-governance-1"></a>

*“The only freedom which deserves the name is that of pursuing our own good in our own way, so long as we do not attempt to deprive others of theirs or impede their efforts to obtain it.”*

*— J. S. Mill, On Liberty, 1859*

Pinto does not have governance. While Pinto is the first Beanstalk fork, additional development must be completed in order to create a generalized fork system that replaces the need for contract upgrades. In the meantime, limited upgrades to Pinto may be implemented by the Pinto Contract Multisig (PCM), the owner of the Pinto contract.

**The PCM will only make changes to Pinto that:**

* Fix bugs or security vulnerabilities (including dewhitelisting an LP token for which the non-Pinto asset has collapsed);
* Change parameters until 2 weeks after the first time the Pinto supply reaches 500M (*e.g.*, [Target Seasons to Catch Up](/resources/glossary#target-seasons-to-catch-up), [Pod Rate](/resources/glossary#pod-rate) and [L2SR](/resources/glossary#liquidity-to-supply-ratio-l2sr) thresholds, [Deposit Whitelist](/resources/glossary#deposit-whitelist), [optimal LP BDV distribution](/resources/contracts#current-deposit-whitelist), etc.);
* Mint Pinto to fund a bug bounty program according to the schedule outlined [here](/appendix/upgradability#bug-bounty-mint-schedule);
* Add a [Shipment](/responding-to-state/minting#shipping-routes) that pays back old Beanstalk holders after the Pinto supply reaches 1 billion (see details [here](/appendix/beanstalk-obligations)); or
* Implement a [Fork Migration System](/appendix/upgradability#fork-migration-system).

## **What About Beanstalk Holders?** <a href="#heading-what-about-beanstalk-holders" id="heading-what-about-beanstalk-holders"></a>

*“Nemo Resideo \[No one left behind]”*

*— Ancient Roman Military Principle*

Pinto will be upgraded to issue assets to holders of Beanstalk debt based on a snapshot of the state of Beanstalk at the time of Pinto deployment. After a supply of 1B Pinto, [3% of mints will go to paying back old Beanstalk debt holders](/responding-to-state/minting#shipping-routes) as follows:

* [Fertilizer](https://docs.bean.money/almanac/farm/barn#fertilizer) holders will receive ERC-1155 tokens similar to the existing Fertilizer tokens;
* [Unripe Bean](https://docs.bean.money/almanac/farm/barn#unripe-assets) holders will receive an asset representing a recapitalized Unripe asset (Ripening Pinto) at a rate of 1 Ripening Pinto per Unripe Bean;
* [Unripe LP](https://docs.bean.money/almanac/farm/barn#unripe-assets) holders will receive an amount of Ripening Pinto based on the Bean Denominated Value of Unripe LP if Beanstalk were fully recapitalized at the time of snapshot; and
* Pod holders will receive Pods in a separate Beanstalk Pod Line.

(1) Active Fertilizer holders, (2) Ripening Pinto holders and (3) Pod holders in this separate Beanstalk [Pod Line](/resources/glossary#pod-line) each receive 1/3 of Pinto mints allocated to paying back old Beanstalk holders (*i.e.*, 1% of mints).

If there is no Active Fertilizer, Ripening Pinto holders and Beanstalk Pod holders each receive 1/2 of Pinto mints allocated to paying back old Beanstalk holders (*i.e.*, 1.5% of mints).

If there are neither Active Fertilizer nor Ripening Pinto, Beanstalk Pod holders receive 100% of the Pinto mints allocated to paying back old Beanstalk holders (*i.e.*, 3% of mints).

If there is no longer any outstanding Active Fertilizer, Ripening Pinto nor Beanstalk Pods, the 3% of mints allocated to honoring Beanstalk debt will be distributed to Pinto participants under its normal model.

Pinto is not allocating any mints for Beans or liquid LP tokens held by Beanstalk the time of the snapshot.

## **A Healthy Environment to Experiment** <a href="#heading-a-healthy-environment-to-experiment" id="heading-a-healthy-environment-to-experiment"></a>

*“I know it when I see it.”*

*— Chief Justice Potter Stewart on Non-substantive Trolling, 1964*

The Pinto experiment will benefit tremendously from constructive public discourse.

As a group participating in an attempt to create censorship resistant money, the Pinto community should value free expression. At the same time, the Beanstalk community learned the hard way that blindly upholding censorship resistance at all costs, particularly in a pseudonymous environment, has major drawbacks. Angry community members who refuse to engage substantively have pushed out the genuinely interested and curious.

In order to create an environment where people actually want to express themselves, the [Pinto Discord](https://pinto.money/discord) will not tolerate non-substantive trolling.

## **Men Wanted for Hazardous Journey** <a href="#heading-men-wanted-for-hazardous-journey" id="heading-men-wanted-for-hazardous-journey"></a>

*“Small wages, bitter cold, long months of complete darkness, constant danger, safe return doubtful. Honour and recognition in case of success.”*

*— Sir Earnest Shackleton, Advertisement for the Endurance Expedition, 1913*

Thus begins the next chapter in the Beanstalk experiment. A frightening journey lies ahead.

But a future without censorship resistant low volatility money is even scarier.\
\
\- 20 Nov 2024


# Pinto: Prints for the People

*“The root problem with conventional currency is all the trust that's required to make it work. The central bank must be trusted not to debase the currency, but the history of fiat currencies is full of breaches of that trust.”* — [Satoshi Nakamoto, February 11th, 2009](https://satoshi.nakamotoinstitute.org/posts/p2pfoundation/1/)

### **Fiat: A Double Edged Sword** <a href="#heading-fiat-a-double-edged-sword" id="heading-fiat-a-double-edged-sword"></a>

The money printer is the most powerful force in the modern economy. Since 1972, when Nixon closed the gold window following a multi-year depletion of the United States gold reserves, the global economy has officially run on fiat (*i.e.*, credit backed) currency.

The defining feature of fiat currency is that it can be printed out of thin air. Although it may seem counterintuitive that something producible at will could serve as better money than a scarce, physically grounded asset like gold, it is precisely this freedom from physical limitations that gives fiat its unique utility.

Money is understood to have three primary use cases, storing value across space and time, serving as a medium of exchange between various forms of value, and functioning as a unit of account for value and loans of value.

In both cases of acting as a medium of exchange and as a unit of account for loans, the primary driver of money’s utility is its low volatility. The power of fiat money lies in the ability to use the printer to minimize its volatility.

Unlike gold, the supply of which is almost entirely unrelated to the economy, access to fiat money can be meticulously controlled in direct response to economic conditions (*e.g.*, expanding in response to growth and shrinking in response to contractions) to minimize the volatility of its value and thereby maximize the health of the economy.

Unfortunately, the money printer is currently governed by human judgement that is arbitrarily based on [“feel”](https://x.com/balajis/status/1854768927181885812). Moreover, the use of the printer has been corrupted such that the vast majority of value printed is to the benefit of corporations and other parties that have close ties to the government.

**The preferential and concentrated distribution of freshly printed fiat creates high levels of inflation that erodes wealth, exacerbates massive inequality and distorts the truth discovered through markets (*****i.e.*****, what people value).**

### **Friends of the Printer** <a href="#heading-friends-of-the-printer" id="heading-friends-of-the-printer"></a>

The corruption of the money printer has broken capitalism’s engine of creative destruction. The traditional pressure on companies to compete in the creation of goods and provision of services has been compromised by unequal access to the money printer. The traditional requirement for lenders and investors to manage risk responsibly has been removed for those deemed “too big to fail”.

These companies offer terrible quality and take dangerous risks, but never have to pay the price because a bailout, whether in the form of a cash infusion, access to cheap credit, or a government contract, is always just a phone call away.

* Boeing dominates the commercial aircraft market despite [safety lapses](https://apnews.com/article/boeing-ntsb-door-plug-737-alaska-airlines-721493c5e64081145aab21f2cf3fabcd), [production issues](https://www.reuters.com/business/aerospace-defense/us-faa-says-boeing-737-max-production-audit-found-compliance-issues-2024-03-04/?utm_source=chatgpt.com), and [cost mismanagement](https://www.reuters.com/business/aerospace-defense/boeing-forecasts-bigger-than-expected-loss-defense-troubles-strike-hit-2025-01-23/?utm_source=chatgpt.com) because government contracts, financing, and support insulate it from competitive pressure.
* Major airlines offer [horrible service](https://www.npr.org/2023/11/27/1215336777/u-s-airlines-lose-2-million-suitcases-a-year-where-do-they-end-up) while maintaining high levels of debt and colluding to avoid competing on price. Because government regulation makes market entry so expensive for new competitors, the only way to afford to play is with government subsidies. Of course, the new company on the block never gets the same degree of assistance from the government as existing companies that can heavily lobby for special treatment, leaving consumers with limited options.
* Big banks are no longer subject to practical risk management. Despite introducing massive leverage into the financial system, they are shielded from the consequences of failure by central banks and government interventions that encourage lending to politically popular, rather than economically productive, ventures and foster heedless risk-taking bound for disaster barring further government intervention.
* Backed by low-cost, government-subsidized financing, private equity firms like Blackstone now own a significant share of single-family homes in certain metro areas – sometimes 5-20%, and increasing – driving up prices and pushing ordinary buyers into the rental market. These firms are paying excessively high costs that are only justifiable given the expectation of the government propping up the value of the housing market.

The corruption of money prevents the market from discovering and serving people’s needs. Instead, people's work and consumption serve major companies that do not care for or about them, and despite the tremendous deflationary effect of the proliferation of software over the past three decades, people are less well off than their parents.

**A transparent and unbiased algorithm can control the money supply more accurately, ethically and sustainably than arbitrary human control and correct the perverse incentives created by the corrupted money printer.**

### **Crypto’s Missing Half** <a href="#heading-cryptos-missing-half" id="heading-cryptos-missing-half"></a>

Bitcoin was a direct response to the corruption of the money printer, and has started a revolution to create an economy free from capture by powerful interests. Many bitcoiners believe that requires ditching fiat currency altogether. However, Bitcoin’s monetary policy (*i.e.*, predefined minting schedule) makes it much better suited to serve as a store of value across space and time and a unit of account for value than as a medium of exchange between various types of value or unit of account for loans.

A medium of exchange and unit of account for loans is such an important part of a modern economy that even on networks like Ethereum, which have been meticulously designed around the principles of trustlessness and censorship resistance, the dominant media of exchange and units of account for loans are trusted wrappers of good old federal fiat money (i.e. USDT, USDC), which can be easily censored by the companies that issue them or governments that have the ability to control those companies. In reality, there is so much value on the Ethereum network that is dependent on these centralized wrappers for fiat money that the independence and integrity of the Ethereum network itself has been [compromised](/why-pinto/ethereum-at-10-an-existential-threat).

**Pinto is a response to this existential threat.**

### **Crypto Fiat** <a href="#heading-crypto-fiat" id="heading-crypto-fiat"></a>

Pinto is founded on the beliefs that fiat money is the best money if the printer is used wisely and ethically, and that credit is an infinitely scalable source of endogenous value.

What the Bitcoin (and now Ethereum) community miss is that fiat has outcompeted hard assets like gold as the global currency *in spite of* the abuse of the printer. To ignore the success of fiat over hard money is to throw the baby out with the bath water.

Pinto leverages the power of smart contracts to create a crypto-native fiat monetary system in which every Pinto is printed directly to the people who have value in the system, thereby decoupling inflation of the money supply from the devaluation of people's wealth.

Because every Pinto printed is distributed [deterministically](/responding-to-state/minting), verifiably and such that participants accrue wealth during the system's growth rather than lose it, Pinto has the benefits of modern fiat currency without the drawbacks.

A variety of novel incentive mechanisms make Pinto possible. Anyone can take their Pinto, or various [whitelisted Pinto LP tokens](/resources/contracts#current-deposit-whitelist), and [Deposit](/resources/glossary#deposit) them in the protocol to earn a portion of future prints. Similarly, anyone can [lend](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto) Pinto to the protocol to earn a portion of future prints. The incentives the protocol offers participants for any given action changes every hour, contributing to a living monetary system that grows and adapts to meet the needs of its participants.

Pinto is an experiment at the frontier of money. It’s still early. Pinto's incentive mechanisms have room for improvement. Pinto's trustless and censorship resistant governance mechanism is still a few months away from implementation. But, Pinto is the foremost attempt to date at delivering the money printer to the people.

**If Pinto succeeds, it has the power to restore markets to their proper function and complement BTC or ETH as a base layer currency of the crypto economy.**\
\
*See Ben's original post from August 20th, 2025* [*here*](https://x.com/bwein_/status/1958159888707686655)*.*


# Ethereum at 10: An Existential Threat

It's Ethereum’s 10th [birthday](https://ethereum.org/10years/), and about time we address the deal with the devil we made in our network's youth.

In its original whitepaper, Ethereum’s stated purpose was to serve as [“a tool of distributed consensus”](https://ethereum.org/en/whitepaper/). Reality today is a far cry from this purpose. While the Ethereum community has been meticulous about designing the network to facilitate a maximally distributed validator set, we have neglected to ensure the distribution of an equally critical element – one which currently jeopardizes the network's sovereignty: its value source.

An overwhelmingly dominant portion of value on the Ethereum network is dependent on centralized stablecoins. Nobody likes to talk about it, but this is such a significant problem that two companies, Circle and Tether, actually control the state of the Ethereum network.

The Ethereum state secures $1.1T of value, of which only about 10% is issued by Circle or Tether. Yet, the utility of USDT and USDC as media of exchange is so great compared to decentralized equivalents (*e.g.*, the OG DAI, Liquity) that the majority of the value of the Ethereum state is dependent on USDT and USDC for liquidity and, de facto, its value.

In practice, therefore, we are not in a position to declare victory. In the same way that the Ethereum community responded to the existential threat of competition at the network layer, we must address the existential threat posed by centralized stablecoin issuers.

With Ethereum solidifying ETH’s dominance over BTC as a store of value from a monetary policy perspective, the last advantage BTC has over ETH is that its value does not derive from fundamentally centralized economic activity.

*The missing ingredient to actually distribute the Ethereum consensus and establish ETH as a dominant store of value over BTC is a scalable Ethereum network-native censorship resistant medium of exchange.*

After [almost 5 years](/why-pinto/4-years-of-beanstalk) working on solving this problem, there is now significant evidence that a credit based model for a low volatility currency can fulfill this need. [Credit](/why-pinto/credit-vs-collateral) is infinitely scalable, plus can be permissionless and distributed.

Trying to create a low volatility money that can outcompete USDT and USDC is frightening for many: there is a graveyard full of previous attempts. The last crypto market bull run effectively ended when the largest attempt to date, Terra, suddenly failed. But given the danger facing the Ethereum network, we cannot sit idly by. Instead of throwing the baby out with the bath water, we must learn from past failures and continue to make progress.

It is still early, but [@pintodotmoney](https://x.com/pintodotmoney) is the frontier. If you believe in the vision of Ethereum, it is worth your time to check it out.

*See Ben's original post from July 30th, 2025* [*here*](https://x.com/bwein_/status/1950384010284453967)*.*


# Credit vs Collateral

Collateralized stablecoins currently dominate the market. Since Tether launched in 2014, there have been hundreds of collateralized stablecoins launched by nearly as many different issuers. The fundamental value proposition of collateralized stablecoins is simple: perfect stability compared with some index of value (usually the US Dollar).

But collateralized stablecoins come with baggage: the vast majority of those on the market today are issued by centralized custodians of off-chain value because there is simply not enough on-chain value to use as collateral to issue enough stablecoins to meet demand. These centralized issuers of stablecoins have the unilateral ability to censor holders of the asset. The unfortunate reality is that so much of the value on-chain today is dependent (*e.g.*, for liquidity, TVL, collateral for loans) on stablecoins collateralized by off-chain value which is custodied by centralized parties that the integrity – the censorship resistance, credible neutrality and permissionlessness – of the chains themselves are compromised.

**Credit offers the most compelling alternative to collateral to create a network-native, scalable and leviathan-free medium of exchange and unit of account.**

The major downside of credit compared with collateral is that it cannot support a perfect peg. But, in addition to being crypto-value aligned – on-chain credit can be trustless, permissionless and censorship resistant – a properly architected credit-based stablecoin can outcompete collateralized ones based solely on its economic advantages.

### **Collateral Over Credit? The Hard Peg**

Collateralized stablecoins track the value of the index they are pegged to almost perfectly because there is always – except for the [rare](https://www.reuters.com/business/crypto-firm-circle-reveals-33-bln-exposure-silicon-valley-bank-2023-03-11/) (but incredibly important) instances in which the issuer is unable to or refuses to honor redemptions for the underlying collateral – the ability to redeem the stablecoin for its peg value worth of collateral.

In the case of credit-based stablecoins, there is no such redemption mechanism. Therefore, in juxtaposition with collateralized stablecoins, credit-based stablecoins maintain a soft peg – one in which there is some volatility relative to the value target index. In the instance of downside volatility, the credit-based system attempts to borrow excess supply from the market on credit (*i.e.*, the promise of interest in the case of future supply growth) to reduce supply and return the stablecoin's price to its value target.

Because one of the primary drivers of utility for a medium of exchange and unit of account is low volatility, collateralized stablecoins have a major advantage over credit-based ones.

### **Credit Over Collateral: Carry Costs**

The other major driver of the utility of a medium of exchange and unit of account besides low volatility is *carry costs* for (a) holding the asset, and (b) borrowing the asset. Holders want to earn a competitive interest rate on the money they hold, and borrowers want to be able to borrow money at the lowest interest rate possible. Credit-based stablecoins dominate collateralized ones with respect to carry.

While modern collateralized stablecoins, particularly USD denominated ones, are largely backed by US Treasuries, thereby offering non-zero positive carry to holders of the asset, the single digit yields offered by this model are generally outpaced by the inflation of their indices, leading holders to lose value over time. The yield accrued from holding collateralized stablecoins pales in comparison to the potential yield accrued from holding a credit-based stablecoin whose newly minted supply – a response to excess demand pushing the stablecoin price above its value target – is passed onto holders. Particularly until the credit-based stablecoin's supply reaches hundreds of billions or trillions, high double digit percent positive carry or low triple digit percent positive carry are possible.

Historically, the carry cost paid to borrow an asset must always exceed the opportunity cost of not holding the asset, including the positive carry, if it exists (as otherwise no one would be incentivized to lend it out). A collateralized stablecoin will always be subject to this dynamic. However, a properly architected lending infrastructure surrounding an on-chain credit-based stablecoin has the potential to combine high positive carry for holding and low carry costs for borrowing by having the protocol itself lend out value. Such architecture, although not yet implemented in practice, will create the optimal money: a low volatility yield-bearing medium of exchange and cheaply borrowed unit of account.

When it comes to both types of carry costs, credit-based stablecoins are dramatically better than collateralized stablecoins.

### **The Fundamental Tradeoff: Volatility for Carry Costs**

The tradeoff between collateralized and credit-based stablecoins is clear: perfect stability and less competitive carry, or some volatility and far better carry.

Collateralized stablecoins have very little room to improve on carry costs or alignment to crypto values due to their requirement to remain fully collateralized at all times. While their volatility is typically near 0 with respect to peg maintenance, the positive carry of holding the asset is often outpaced by the inflation of its pegged value. While the costs to borrow are often low, they could be lower. The low supply of on-chain value usable as collateral means collateralized stablecoins will require centralization for the foreseeable future.

Credit-based stablecoins, on the other hand, while still in their experimental phase, can combine much better carry costs with freedom from centralization. It is only a matter of time before the volatility minimization mechanisms and lending architecture are strong enough to create sufficient utility and unlock the power of credit to free Ethereum and other crypto-networks from the existential threat of centralized stablecoins.

The fundamental thesis behind Pinto is that an autonomous algorithm, well-designed, can sufficiently (1) demonstrate and use its creditworthiness (and various endogenous incentive mechanisms) to dampen the volatility of the credit-based currency it issues and (2) distribute yield to holders of the currency, that the utility of the currency can outcompete centralized stablecoins.&#x20;

\*Note, this entire document refers to exogenously collateralized stablecoins, but for simplicity uses the more colloquial term collateralized stablecoins. Read more about stablecoin classification [here](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/why-pinto/classifying-stablecoins).


# Terrable Design: Lessons from Terra's Collapse on the Path to a Scalable Network Native MoE & UoA

The default response I typically get when talking to people about algo stables is something like “are you crazy?! don’t you know about what happened to Terra/Luna???”

Having studied the Terra model and its collapse deeply, there is plenty of reason to believe that algo stables can avoid the same fate and will eventually succeed.

There were three fundamental flaws with the Terra/Luna model.

1. Terra used an unscalable source of endogenous value: equity.
2. Terra had no bank run minimization mechanism.
3. Terra maintained a hard peg instead of a soft one.

During Terra’s collapse, these three flaws exacerbated one another, creating a negative feedback loop that culminated in one of the largest and fastest bank runs in history.

At the time of writing, there is significant evidence that each of these flaws is solvable with proper mechanism design.

### **1. Unscalable Endogenous Value**

The UST stablecoin was redeemable for $1 worth of LUNA. Owning LUNA was comparable to owning equity in a company, where the value of LUNA was derived from the value of the Terra network (*i.e.*, the use of UST). Equity is a terrible source of endogenous value.

To better understand why, let’s consider what would happen if Microsoft, a $4T company, issued MicroBucks, a $1 pegged stablecoin that derived its value in the same way (*i.e.*, through redeemability into $1 of Microsoft stock).

At first glance, you might think that MicroBucks could safely grow up to the value of Microsoft equity, or close to it. After all, there are people all around the world that independently value Microsoft at \~$4T for reasons that have nothing to do with MicroBucks.

HOWEVER, upon closer analysis, it is not actually the market cap of the issuer that determines the number of MicroBucks that can be safely issued against Microsoft stock, *it's the minimum size of the bid for the equity at any given time.*

Because MicroBucks are redeemable for Microsoft stock, the ability for a MicroBuck holder to receive $1 for their MicroBuck is contingent on someone buying $1 of Microsoft stock from them after they convert their MicroBuck to Microsoft stock.

The problem is that the size of the bid at any given time for a stock (no matter how great the stock) is generally decoupled from, and always significantly smaller than, the market cap of the stock.

Herein lies the first major flaw: the equity needs to be orders of magnitude more valuable than the outstanding stablecoins in order for the bid to be large enough to process redemptions smoothly. In practice, there is no source of equity large enough to support a scalable stablecoin.

### **2. No Bank Run Minimization Mechanism**

Money is fundamentally a social phenomenon. Therefore, bank runs can always happen. The best money will have the best bank run minimization mechanism. Terra had none.

Besides the fractional demand for equity at any given time compared with its total value, the other problem with using equity as the source of endogenous value is that equity is fungible, and fungible assets offer no bank run prevention mechanism (specifically due to their fungibility).

Let's reconsider the MicroBuck example and evaluate the incentives in place for a true believer of Microsoft, someone that LOVES the stock at $4T, thinks Bill Gates is god, and has season tickets to the Clippers, in the instance where there is a bank run on MicroBucks.

Once the bank run starts, the Microsoft lover has a choice to make: hold onto their beloved Microsoft stock, or sell now to buy back later at a lower price.

Because there is a reasonable expectation that there will be a significant increase in the supply of Microsoft stock on the market due to conversions from MicroBucks into Microsoft stock, there should be ample opportunity to buy back the Microsoft stock at a significantly lower price.

In such a circumstance, even the Microsoft lover is going to participate in the bank run. When even your biggest fans are obviously incentivized to participate in causing you pain, there is a serious design problem.

The system offers no incentive for those that believe in its long term value to stick around during the bank run, and *instead makes the optimal strategy to participate in the bank run*. YIKES!

Worse still, anyone that would otherwise be interested in buying the stock is not going to buy until the bank run ends. During the bank run, the size of the bid for the equity (*i.e.*, the source of the value of Microbucks) evaporates entirely.

A negative feedback loop in which supply skyrockets and demand disappears brings the price to zero in a flash.

### **3. Hard Peg Instead of Soft Peg**

Despite the use of unscalable endogenous value and the lack of a bank run prevention mechanism, the kiss of death for Terra was its insistence on perfection. Even in instances where the system was experiencing a bank run, the protocol was willing to offer redemptions of 1 UST for $1 of LUNA.

If someone is participating in a bank run, they are typically willing to take a haircut on their value to leave the system in a timely fashion. Instead of letting people leave the system at a discount, Terra was designed to pay every person that left the full value of their holdings, up until there was no money left.

This created two outcomes for participants during a bank run: either be one of the first to leave and get the full value of your holdings out, or miss the boat entirely and be left with nothing.

Given these two outcomes and the lack of a bank run prevention mechanism, it is no surprise that the entire system collapsed within a week once the bank run started. It was foolish to not participate in the bank run.

### **Cause for Hope**

With a better understanding for why Terra collapsed the way it did, it is possible to see a path forward to creating a scalable network-native medium of exchange.

1. [*Credit*](/why-pinto/credit-vs-collateral) is a scalable source of endogenous value with a positive feedback loop: the more the system repays its debt, the more creditworthy the system becomes, thereby enabling it to borrow at lower interest rates and support the issuance of more stablecoins in a progressively more sustainable fashion.
2. The [Stalk System](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism) originally implemented by [Beanstalk](https://bean.money) and now refined by Pinto has demonstrated efficacy at minimizing bank runs in practice by creating an opportunity cost for leaving and coming back later, and rewarding those who stay.
3. Low volatility money with a soft peg still offers significant utility and is radically more sustainable than a hard pegged stablecoin: if people want to leave the system at a discount, let them; in a tradeoff between perfection and resilience, live to fight another day.

*See Ben's original post from August 5th, 2025* [*here*](https://x.com/bwein_/status/1952515296683786579)*.*


# 4 Years of Beanstalk

On the fourth anniversary of the initial [Beanstalk](https://bean.money) deployment, the potential for a credit based money to free crypto from the existential threat of centralized stablecoins has never been higher. If you haven’t been following along, and want to get up to speed on the most promising experiment at the frontier of money, this piece is for you.

### **Before Beanstalk - Empty Set Dollar**

Prior to the deployment of Beanstalk, there had been a variety of attempts at creating a credit based algorithmic stablecoin, starting with [Basis](https://medium.com/basis-blog/introducing-basis-a-stable-cryptocurrency-with-an-algorithmic-central-bank-7a795393a525) in 2017. The most successful model through 2021, [Empty Set Dollar](https://medium.com/d%C3%B8llar/introducing-d%C3%B8llar-and-the-ess-f48222b4e138) (ESD), suffered from a number of problems.

1. Instead of letting the market naturally discover the right interest rate, ESD imposed an arbitrary one on participants. The debt issuance mechanism used an interest rate curve that (1) set the interest rate as a function of the debt level, independent of what the market was willing to pay, and (2) had a hard cap, which led to major inefficiencies in the protocol’s ability to borrow excess supply from the market: everyone wanted to wait until the maximum interest rate, but because the interest rate was a function of the debt level, the protocol would go through extended periods of time with a stalled interest rate and no lending.
2. The fungible nature of ESD's debt created perverse incentives which dissuaded people from being the first to lend to it; you could lend to the protocol last and redeem first, if you were the fastest to redeem. This structure, combined with the fact that as others lent to the protocol the interest rate would increase, made the optimal strategy to wait until after others had already lent to the protocol and favored whales with better execution.
3. ESD had no bank run prevention mechanism, which led to excessive downward price swings.

While ESD was a pioneer in its own right, its inefficiencies led to its, and its many forks', quick demise. All ESD forks completely collapsed within \~2 debt cycles and a maximum of a few months.

### **Beanstalk - A New Model**

Beanstalk was inspired by ESD, and implemented novel incentive designs that remedied the three main inefficiencies of ESD.

1. The protocol introduced a first of its kind on-chain [PID controller](https://en.wikipedia.org/wiki/Proportional%E2%80%93integral%E2%80%93derivative_controller) that automatically adjusted the interest rate on loans without a predetermined interest rate curve, allowing for natural price discovery. Although slightly oversimplified, in general if there was not enough demand for debt, Beanstalk would raise the interest rate; if there was excess demand for debt, Beanstalk would decrease the interest rate.
2. The first in, first out debt repayment mechanism, [Pods](/resources/glossary#pods), leveraged the trustless nature of smart contracts to create a novel type of debt that created a radically improved lending market that fostered the protocol successfully borrowing from the market during periods of excess supply. Because those who lent to Beanstalk first were the first to be paid back when the protocol grew, once someone felt like the interest rate was sufficiently high, they were incentivized to lend to the protocol or risk someone else getting in line before them.
3. The [Stalk System](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism) created the first ever permissionless bank run minimization mechanism that leveraged a time-weighted incentive scheme to align long-term holders with the protocol while maximizing the distribution of ownership in the protocol. Whereas in previous systems, the efficient behavior during a bank run was to leave and come back later, independent of how much one believed in the protocol, the Stalk System rewarded holders for leaving their [Deposits](/resources/glossary#deposit) in Beanstalk during tough times.

### **Beanstalk Live - The First 8 Months**

Although Beanstalk introduced major improvements over its predecessors, there were a variety of inefficiencies in the initial version of the model that made the protocol unsustainable. The first 8 months were spent plugging holes on a sinking ship.

Beanstalk was willing to issue [excessive amounts of debt](https://app.bean.money/#/governance/bip-9) – more than was necessary or efficient – such that the debt level of the protocol skyrocketed. The interest rate the protocol was willing to pay increased [even when it wasn’t optimal to do so](https://app.bean.money/#/governance/bip-13), and the way the protocol measured demand for debt was [flawed](https://app.bean.money/#/governance/bip-15), both of which led to Beanstalk overpaying for loans. Issuing too much debt and paying too high an interest rate were both unsustainable.

Furthermore, there was no way for Depositors in the system to use their Deposits to contribute to protocol maintenance, despite being the participants and value in the protocol best suited to do so. Until the introduction of [Converts](https://app.bean.money/#/governance/bip-7), large amounts of capital sat stagnant within the system, contributing to excess volatility.

While Beanstalk was far from perfect, it was good enough that there was enough time to observe its inefficiencies and fix them. The protocol bent, but it did not break.

### **Beanstalk Exploit - A Shakespearean Tragedy**

In its ninth month, something incredible happened: the protocol actually started to work. Enough improvements were made, and enough holes were plugged, that the ship started to float.

The protocol entered its healthiest and most promising period, paying off its debt and increasing its liquidity. The Beanstalk community Discord was electric, and Twitter started to seriously pay attention to what was occurring. For about 3 weeks, it looked like credit based money was about to shake up the cryptocurrency landscape.

But shortly after the protocol started to run, tragedy struck: a [governance exploit](https://medium.com/immunefi/hack-analysis-beanstalk-governance-attack-april-2022-f42788fc821e), that ironically was only made possible due to the excessive health (*i.e.*, liquidity) of the protocol, was executed by a still unknown attacker, and drained all \~$77m of liquidity from the protocol, destroying an additional \~$120m in protocol-native value in an instant.

Because the protocol had demonstrated efficacy in the weeks immediately prior to the exploit, the community organized to revive and restart the protocol. However, 3 weeks after the Beanstalk exploit, [Terra Luna](https://x.com/bwein_/status/1952515296683786579), the largest algorithmic stablecoin up to that point (and still today) was destroyed via an economic and social attack that destroyed $60B of value in less than a week, effectively ending the crypto bull run and eviscerating almost all desire amongst the crypto community to continue to pursue algorithmic stablecoins.

### **Beanstalk Replant - Trauma Unresolved**

Beanstalk was [replanted](https://3sipcwrl5gslyrumbjpwps4kigkrrazuhe2fdq4o6gv7dz2ppf4q.arweave.net/3JDxWivppLxGjApfZ8uKQZUYgzQ5NFHDjvGr8edPeXk) on August 6th, 2023, a year after its initial deployment. While the protocol was able to borrow \~$17m in new value from the market as part of its recapitalization, the structure of the recapitalization honored all outstanding Beanstalk liabilities at par.

In an [article](https://publius.money/blog/2022-06-05-thoughts-before-the-barn-raise) shortly before the Barn Raise to recapitalize the protocol, Publius wrote “One of the main attractions of the more aggressive Barn Raise strategy laid out in [BFP-72](https://snapshot.org/#/beanstalkfarms.eth/proposal/0xb87854d7f6f40f0877a1333028eab829b213fbcce03f16f9dd3832c8a98ab99b) \*\*is that Beanstalk is likely being Replanted with a ridiculously high [Pod Rate](/resources/glossary#pod-rate) in the worst a) macro environment in at least a decade, b) crypto market in years, c) stablecoin market of all time, and d) endogenous circumstances possible, as a result of the attack. This presents an incredible opportunity for the model to demonstrate its efficacy. We will all know very quickly if it is working or not.”

Although the protocol did “work” after it was replanted, continuing to cross the value target for another 10 months, between the negative publicity associated with the exploit, the general fear of algorithmic stablecoin after the collapse of Terra Luna, and the system's excessive debt, interest all but disappeared.

### **A Data Deficiency**

During the first nine months of Beanstalk’s life prior to the exploit, there was so much data collected that there was a significant number of improvements to the mechanism that were imagined – so much so that there was enough development work to [continue iterating](https://app.bean.money/#/governance) on the model for another 2 years after the Replant.

However, without users actively participating in the system, our ability to (1) learn about the efficacy of the improvements that were being implemented and (2) discover new ways to improve the model, was compromised.

While the model had come a long way from the early Beanstalk days when the ship had so many holes that it barely survived, there was a lot of reasons to believe that the model was far from an optimal state. It just wasn’t clear what were the next steps to take the model to the next level.

### **Pinto - Debt Restructuring and Data Dump**

Enter Pinto. Pinto was deployed in November of 2024 with a variety of model improvements – the last set that was reasonably conceivable given the data collected through Beanstalk. Pinto restructured the Beanstalk debt to honor it in the instance where the protocol succeeds (Pinto [will start paying](/responding-to-state/minting#shipping-routes) 3% of all mints to Beanstalk after it reaches a 1 billion supply) but effectively gave the model a clean slate to collect more data.

In the 8 months since it was deployed, the protocol has experienced a period of rapid growth followed by its first debt cycle, extended time below the value target, and a return to it. This broad swath of data has enabled the protocol to be [improved further](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/pinto-improvements-pis-coming-soon) and is enough to enable at least another year’s worth of development. Expect a roadmap in the near future.

### **4 Years of Beanstalk - Perspective**

Despite over 35,000 sunrises in the two protocols, it hasn’t been all sunshine and roses. Things certainly didn’t play out how we drew it up on the big board almost 5 years ago when we started working on the project; it’s hard not to fall into thinking about “what if” Beanstalk had never been exploited. Maybe all the money that fled Terra would have flown into Beanstalk, and the protocol would have grown into the billions in short order.

But, the glass half full says that the Pinto model today is in a dramatically better spot than Beanstalk was at the time of the exploit, and it’s only a matter of time before the crypto market reconsiders the potential for algorithmic stablecoins.

Building a network-native algorithmic stablecoin that can sustain itself perpetually may be impossible. Without one, however, the security of crypto networks will be permanently compromised. We must find out how to create one, or die trying. The model is ready for its next major test.

*See Ben's original post from August 6th, 2025* [*here*](https://x.com/bwein_/status/1953103625779032089)*.*


# Economic Principles

Pinto is designed from economic first principles to create a useful trustless fiat currency. Over time, trustlessness, stability and liquidity increase, while carrying costs decrease but remain competitive. The following principles inspire Pinto:

* [Low ownership concentration;](#ownership-concentration)
* [Strong credit](#strong-credit);
* [The marginal rate of substitution](#marginal-rate-of-substitution);
* [Low friction](#low-friction);
* [Equilibrium](#equilibrium); and
* [Incentive structures determine behaviors of financially motivated actors](#incentives).

### Low Ownership Concentration <a href="#ownership-concentration" id="ownership-concentration"></a>

A design that lowers the [Gini coefficient](https://en.wikipedia.org/wiki/Gini_coefficient) of Pinto and Stalk over time is essential to censorship resistance.

Older [Deposits](/resources/glossary#deposit) have their [Stalk](/resources/glossary#stalk) accumulated from [Seeds](/resources/glossary#seeds) diluted relative to newer Deposits every [Season](/resources/glossary#season). Therefore, newly minted Pinto are more widely distributed over time.

Pinto does not require a pre-mine. The first 1000 Pinto are created when the `init` function is called to deploy the protocol.

### Strong Credit <a href="#strong-credit" id="strong-credit"></a>

Pinto is credit based and only fails if it can no longer attract creditors. A reasonable level of debt, strong credit history and competitive interest rate attract creditors.

The protocol changes the [Temperature](/responding-to-state/temperature-changes) to return the [Pod Rate](/resources/glossary#pod-rate) to the [optimal Pod Rate](/responding-to-state/classifying-state#debt-level) while regularly crossing the Pinto price over its value target. The protocol acts more aggressively when the Pod Rate is excessively high or low.

The protocol never defaults on debt (although in the event of the protocol no longer attracting creditors, the loan maturity date would become infinitely far in the future—see [Disclosures](/appendix/disclosures)). The protocol is willing to issue [Pods](/resources/glossary#pods) every Season.

### Marginal Rate of Substitution <a href="#marginal-rate-of-substitution" id="marginal-rate-of-substitution"></a>

There are a wide variety of opportunities Pinto has to compete with for creditors. Therefore, the protocol does not define an optimal Temperature, but instead [adjusts it to move closer to ideal equilibrium](/responding-to-state/classifying-state#ideal-equilibrium).

### Low Friction <a href="#low-friction" id="low-friction"></a>

Minimizing the cost of using Pinto and barriers to the [Farm](/pinto-mechanics/mechanics-overview) maximizes utility for users and appeal to creditors. The [Toolshed](/pinto-mechanics/toolshed) empowers farmers to use Pinto efficiently.

### Equilibrium <a href="#equilibrium" id="equilibrium"></a>

Equilibrium is a state of equivalent marginal quantity supplied and demanded. The protocol affects the supply of and demand for Pinto to regularly cross the equilibrium price of 1 Pinto over its value peg.

While the protocol can [arbitrarily increase the Pinto supply](/responding-to-state/classifying-state#bean-supply) when the price is above its value peg, the protocol cannot arbitrarily decrease the Pinto supply when the price is below it. The protocol relies on the codependence between the equilibria of Pinto and [Soil](/resources/glossary#soil), as well as [Converts](/resources/glossary#convert-1), to work around this limitation.

In order to [Sow](/resources/glossary#sow) Pinto, they must be acquired (*i.e.*, marginal demand for Soil affects marginal demand for Pinto). The marginal demand for Soil and Pinto are functions of the Temperature and the Pinto price. By [changing the Temperature](/responding-to-state/temperature-changes), the protocol affects decreases in the Pinto supply and changes in demand for Pinto.

### Incentives <a href="#incentives" id="incentives"></a>

Pinto-native financial incentives consistently increase trustlessness, stability and liquidity over time by coordinating independently financially motivated actors (*i.e.*, Stalkholders and Sowers).

[The Stalk System](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism) incentivizes (1) leaving assets Deposited in the [Silo](/resources/glossary#silo) continuously by creating opportunity cost to Withdraw assets from the Silo, (2) adding value to liquidity pools with Pinto by [rewarding more Seeds to at least 1 Deposited LP token](/responding-to-state/crop-ratio-changes) than Deposited Pinto, and (3) returning the Pinto price to its value peg by allowing [Converts](/resources/glossary#convert-1) within the Silo without forfeiting [Stalk](/resources/glossary#stalk).

Anyone with Stalk stands to profit from future growth of the Pinto supply, but are not owed anything by the protocol.

When the Pinto price is below $1, there is an incentive to [Withdraw](/resources/glossary#withdraw) assets from the Silo. The Stalk System reduces this incentive significantly.

When the Pinto price is above $1, there is an incentive to buy Pinto to earn a portion of the upcoming seigniorage. This is exacerbated when the [Pod Rate](/resources/glossary#pod-rate) is lower. The commitment to automatically return the Pinto price to its value target and distribute proceeds from the sale to current Stalkholders based on Stalk ownership when it began [Raining](/resources/glossary#rain) (known as the [Flood](/responding-to-state/flood)) removes this incentive entirely during Seasons where the previous Season's Pod Rate was excessively low, and reduces it significantly otherwise.

Thus, Pinto consistently increases trustlessness, stability and liquidity over time.


# Classifying Stablecoins

### What is a Stablecoin? <a href="#what-is-the-problem-with-current-implementations-of-stablecoins" id="what-is-the-problem-with-current-implementations-of-stablecoins"></a>

A stablecoin is a fungible asset intended to maintain low price volatility relative to an arbitrary value peg. Oftentimes, stablecoins are pegged to the price of an off-chain currency.

A currency’s utility is a function of:

* Trustlessness;
* Carrying costs;
* Low volatility; and
* Liquidity.

Low volatility is essential to the utility of a currency. Without looking at the theoretical reasons for why this is the case, the market has clearly demonstrated its value. Since its inception with the creation of Tether – a historically very [low volatility asset](https://coinmarketcap.com/currencies/tether/) – in 2014, the stablecoin industry has grown from a fringe backwater to a [$170B market cap](https://defillama.com/stablecoins) DeFi behemoth.

The history of money tells a story of markets seeking out the least volatile assets to use as currency. The relatively brief history of DeFi tells the same story.

### What is the Problem with Current Implementations of Stablecoins? <a href="#what-is-the-problem-with-current-implementations-of-stablecoins" id="what-is-the-problem-with-current-implementations-of-stablecoins"></a>

While the market has demonstrated clear demand for low volatility blockchain-native assets, the vast majority of current implementations suffer from a variety of risks and drawbacks, primarily with regard to a lack of trustlessness, negative carrying costs and thin liquidity. In other words, the only utility that has been created by current stablecoin implementations is low volatility. The absence of a decentralized currency with competitive carrying costs and deep liquidity is the main issue – in addition to high blockchain transaction costs – holding businesses producing real economic activity back from adopting decentralized financial primitives.

Businesses built exclusively on decentralized primitives have struggled to compete with businesses built on centralized financial systems like fiat USD because DeFi lacks a trustless and liquid currency with sufficiently low price volatility and competitive carrying costs.

For example, historically, [borrowing rates on USD stablecoins](https://app.aave.com/markets/) have significantly exceeded [borrowing rates on fiat USD](https://www.newyorkfed.org/markets/reference-rates/effr). Until network-native borrowing rates are comparable to or lower than off-chain borrowing rates, DeFi will continue to struggle to attract meaningful economic activity away from TradFi.

### Stablecoin Features <a href="#stablecoin-features" id="stablecoin-features"></a>

Current implementations of stablecoins can be conceptualized along the following three axes: value source, convertibility and network nativity.

#### **1. Value Source: Exogenous value vs. Endogenous value**

Stablecoin value can come from exogenous assets or endogenous value creation.

A stablecoin with *exogenous value* is one whose value is derived from another asset or basket of assets which are held by the issuer as collateral. Reliance on exogenous value generates opportunity costs associated with collateral requirements, which creates non-competitive carrying costs.

A stablecoin with *endogenous value* is one whose value is derived from demand for the currency. Endogenous value has the potential to facilitate the creation of trustless currency with low price volatility, competitive carrying costs and deep liquidity.

#### **2. Convertibility: Convertible vs. Non-convertible**

Convertibility is the option to exchange an asset for its underlying collateral. *Note: Convertibility is not related to the protocol-native action of* [*Converting*](/resources/glossary#convert-1)*.*

A *convertible* stablecoin protocol is one that facilitates convertibility between its stablecoin and its underlying collateral. Arbitrage opportunities created by convertibility ensure that the stablecoin price is rarely above or below the value of the underlying collateral, once frictions around convertibility are accounted for. Convertibility comes at the expense of low liquidity and non-competitive carrying costs because of the opportunity cost associated with locking up collateral to facilitate it.

A *non-convertible* stablecoin protocol is one that does not facilitate convertibility between its stablecoin and any form of underlying collateral. It is impossible to keep a stablecoin price equal to its value peg at all times without low-friction convertibility. Non-convertible stablecoin protocols without collateral requirements have the potential to create endogenous value that facilitates trustlessness, competitive carrying costs and deep liquidity at the expense of volatility.

#### **3. Network Nativity: Network-native vs. Non-network native**

Network nativity refers to the source of a stablecoin’s value with regard to its network.

A *network-native* stablecoin is one that derives its value exclusively from the network to which it is native. Network-nativity eliminates most points of centralization from a stablecoin’s value chain.

A *non-network-native* stablecoin is one that does not exclusively derive its value from the network to which it is native. Non-network-nativity requires a custodian that facilitates a bridge to the network, which can introduce significant costs, complexities and points of centralization.

The three axes in the previous section (value source, convertibility and network nativity) present a classification of 8 potential stablecoin types, some of which currently lack successful implementations:

* [Non-network-native exogenous value convertible stablecoin protocols](#non-network-native-exogenous-value-convertible-stablecoin-protocols)
  * *Examples: USD Coin, Tether, BinanceUSD*
* [Network-native exogenous value convertible stablecoin protocols](#network-native-exogenous-value-convertible-stablecoin-protocols)
  * *Examples: WETH, Liquity, MakerDAO, Abracadabra*
* [Non-network-native exogenous value non-convertible stablecoin protocols](#non-network-native-exogenous-value-non-convertible-stablecoin-protocols)
  * *Examples: N/A*
* [Network-native exogenous value non-convertible stablecoin protocols](#network-native-exogenous-value-non-convertible-stablecoin-protocols)
  * *Examples: Olympus*
* [Non-network-native endogenous value convertible stablecoin protocols](#non-network-native-endogenous-value-convertible-stablecoin-protocols)
  * *Examples: N/A*
* [Network-native endogenous value convertible stablecoin protocols](#network-native-endogenous-value-convertible-stablecoin-protocols)
  * *Examples: Terra*
* [Non-network-native endogenous value non-convertible stablecoin protocols](#non-network-native-endogenous-value-non-convertible-stablecoin-protocols)
  * *Examples: US Dollars*
* [Network-native endogenous value non-convertible stablecoin protocols](#network-native-endogenous-value-non-convertible-stablecoin-protocols)
  * *Examples: Pinto, Beanstalk, Ampleforth*

Additionally, implementations of exogenous value convertible stablecoin protocols with fractional reserves are considered:

* [Non-network-native exogenous value fractional reserve convertible stablecoin protocols](#non-network-native-exogenous-value-fractional-reserve-convertible-stablecoin-protocols)
  * *Examples: Bank Notes*
* [Network-native exogenous value fractional reserve convertible stablecoin protocols](#network-native-exogenous-value-fractional-reserve-convertible-stablecoin-protocols)
  * *Examples: Frax*

### Exogenous Value Stablecoins <a href="#exogenous-value-stablecoins" id="exogenous-value-stablecoins"></a>

#### **Non-network-native exogenous value convertible stablecoin protocols**

*Examples:* [*USD Coin*](https://www.circle.com/en/usdc)*,* [*Tether*](https://tether.to/en/)*,* [*BinanceUSD*](https://www.binance.com/en/busd)

Non-network-native exogenous value convertible stablecoin protocols issue tokens that are supposedly collateralized by, and require a custodian that facilitates the convertibility to, non-network-native exogenous value worth at least 100% of total outstanding protocol liabilities. These protocols function as low-volatility permissioned bridges between their respective networks and the rest of the world.

Users of non-network-native exogenous value convertible stablecoins sacrifice trustlessness and carry: third parties custody the non-network-native assets, can freeze the network-native assets unilaterally and can retain yield earned on collateral. The absence of protocol-native opportunities for carry limits liquidity.

*Trustlessness:* Permissioned

*Carrying Costs:* Non-competitive as compared to the asset being pegged to, but best among exogenous value convertible stablecoins

*Volatility:* Best among exogenous value stablecoins, but frictions around convertibility remain significant, leading to imperfect peg maintenance

*Liquidity:* Best among exogenous value stablecoins, but limited by opportunity cost of using off-chain collateral as capital

#### **Network-native exogenous value convertible stablecoin protocols**

*Examples:* [*WETH*](https://coinmarketcap.com/academy/article/what-is-wrapped-ethereum-weth)*,* [*Liquity*](https://www.liquity.org/)*,* [*MakerDAO*](https://makerdao.com/)*,* [*Abracadabra*](https://abracadabra.money/)

Network-native exogenous value convertible stablecoin protocols use excess network-native collateral to remove most points of centralization. Overcollateralization removes most risk associated with the volatility of the collateral but by necessity requires the introduction of rent payments in order to prevent the value of the stablecoin from trending towards the value of the underlying collateral. The combination of collateral requirements and rent payments significantly limits the potential liquidity of these stablecoins.

[Liquity](https://www.liquity.org/) is an ideal simple iteration of this type of stablecoin protocol, without any points of centralization and with protocol-native positive carry (via [the Stability Pool](https://docs.liquity.org/faq/stability-pool-and-liquidations)). In order to remove rent payments, Liquity does not target an exact price for its stablecoin, LUSD. The potential supply of LUSD is limited by the value of trustless network-native value.

*Trustlessness:* Can be totally permissionless; collateral distribution is the primary determinant of trustlessness

*Carrying Costs:* Non-competitive as compared to the asset being pegged to, unless at the expense of volatility

*Volatility:* Very low volatility when factoring in frictions around convertibility, unless in order to improve the competitivity of carrying costs

*Liquidity:* Limited by available network-native collateral, particularly trustless network-native collateral

#### **Non-network-native exogenous value non-convertible stablecoin protocols**

*Examples: N/A*

Convertibility is the main source of low price volatility and confidence in the custodian. Therefore, it is unlikely that a non-network-native exogenous value non-convertible stablecoin protocol will find product market fit.

*Trustlessness:* Permissioned

*Carrying Costs:* Non-competitive as compared to the asset being pegged to

*Volatility:* Speculation on the trustworthiness of the custodian of collateral will be higher due to the lack of convertibility, which should lead to more price volatility

*Liquidity:* Limited by opportunity cost of using off-chain collateral as capital, but less so because the custodian is unencumbered by the limited asset allocations necessary to facilitate convertibility

#### **Network-native exogenous value non-convertible stablecoin protocols**

*Examples:* [*Olympus*](https://www.olympusdao.finance/) *(convertible under certain market conditions)*

Convertibility is the main source of low price volatility. The main benefit of collateralization is low price volatility, the majority of which is forfeited in the absence of convertibility. Therefore, it is unlikely that a network-native exogenous value non-convertible stablecoin protocol will find product market fit.

*Trustlessness:* Can be totally permissionless; collateral distribution is the primary determinant of trustlessness

*Carrying Costs:* Non-competitive as compared to the asset being pegged to, but potentially better than network-native exogenous value convertible stablecoin protocols because of the ability to take more risk with the underlying collateral at the cost of volatility

*Volatility:* There exists some tradeoff between carrying costs and volatility, dependent on protocol design

*Liquidity:* Limited by available network-native collateral, particularly trustless network-native collateral

#### **Non-network-native exogenous value fractional reserve convertible stablecoin protocols**

*Examples: Bank Notes (not implemented on any decentralized networks to date)*

Credit-based non-network-native exogenous value convertible stablecoin protocols most closely resemble traditional bank notes. The introduction of fractional reserves to create competitive carrying costs is a well documented historical phenomenon. The lending out of collateral creates yield that can be passed onto the users of the fractional reserve notes. However, the combination of convertibility and fractional reserves creates an asset liability duration mismatch that can lead to complete collapse. Fractional reserves are another example of currencies trading volatility for carry.

*Trustlessness:* Permissioned

*Carrying Costs:* Competitive as compared to the asset being pegged to, at the expense of tail risk in volatility

*Volatility:* Low volatility when factoring in frictions around convertibility; exposure to bank runs

*Liquidity:* Limited by available collateral

#### **Network-native exogenous value fractional reserve convertible stablecoin protocols**

*Examples:* [*Frax*](https://frax.finance/)

The use of fractional reserves by network-native exogenous value convertible stablecoin protocols has been used in an attempt to help remediate the negative effect on carrying costs of collateral requirements. However, the network-native nature of the system makes lowering the collateralization ratio difficult without spurring a bank run. While fractional reserve implementations of network-native exogenous value convertible stablecoins offer competitive carrying costs as compared to non-fractional reserve implementations, they do so at the cost of tail risk in volatility.

*Trustlessness:* Can be totally permissionless; collateral distribution is the primary determinant of trustlessness

*Carrying Costs:* Can be competitive as compared to the asset being pegged to at lower collateralization ratios

*Volatility:* Low volatility when factoring in frictions around convertibility; exposure to bank runs

*Liquidity:* Limited by available network-native collateral, particularly trustless network-native collateral

#### **Summary**

Convertibility to exogenous value is the primary source of low price volatility, but it comes at the cost of competitive carrying costs and liquidity. In most implementations, trustlessness is sacrificed for deeper liquidity.

Despite the shortcomings of exogenous value convertible stablecoin implementations, demand for their USD implementations continues to [increase rapidly](https://defillama.com/stablecoins).

However, despite this rapid increase in supply, the [borrowing rates on exogenous value convertible USD stablecoins](https://app.aave.com/markets/) have historically been higher than [borrowing rates on USD](https://www.newyorkfed.org/markets/reference-rates/effr). Non-competitive carrying costs are structural due to the opportunity costs associated with requirements of exogenous value collateral. Attempts to improve carrying costs through the introduction of fractional reserves have failed to do so.

Businesses built on trustless primitives cannot compete with businesses built on centralized systems due to non-competitive carrying costs on low-volatility network-native trustless assets.

### Endogenous Value Stablecoins <a href="#endogenous-value-stablecoins" id="endogenous-value-stablecoins"></a>

#### **Non-network-native endogenous value convertible stablecoin protocols**

*Examples: N/A*

It is difficult for network-native protocols to create and facilitate the conversion to non-network-native value. Therefore, it is unlikely that non-network-native endogenous value convertible stablecoin protocols find product market fit.

In theory, this would be like a private company issuing a stablecoin that is convertible to company stock at market price.

*Trustlessness:* Permissioned

*Carrying Costs:* Can be competitive as compared to the asset being pegged to, but the issuer must create more than enough endogenous value to facilitate the carry

*Volatility:* Likely to maintain a tight peg due to convertibility, but exposed to collapse in the instance the issuer’s endogenous value source falters, or is expected to falter

*Liquidity:* Limited by the endogenous value of the issuer

#### **Network-native endogenous value convertible stablecoin protocols**

*Examples:* [*Terra*](https://www.allcryptowhitepapers.com/terra-whitepaper/)

To date, implementations of network-native endogenous value convertible stablecoin protocols have failed to regularly cross their stablecoin price over their value peg. This is primarily due to the fluctuation in value of endogenous value. The convertibility to endogenous value typically correlates with decreases in endogenous value, which creates excess reflexivity. It is unclear whether network-native endogenous value convertible stablecoin protocols can succeed.

*Trustlessness:* Permissionless

*Carrying Costs:* Can be competitive as compared to the asset being pegged to, but the issuer must create more than enough endogenous value to facilitate the carry

*Volatility:* Likely to maintain a tight peg due to convertibility, but exposed to collapse in the instance the issuer’s endogenous value source falters, or is expected to falter

*Liquidity:* Limited by the endogenous value of the issuer

#### **Non-network-native endogenous value non-convertible stablecoin protocols**

*Examples: US Dollars*

The current financial system (*i.e.*, fiat money) can be thought of as an implementation of credit-based non-network-native endogenous value non-convertible stablecoin protocols, where the fiat money is pegged to a time-weighted discount of its current purchasing power. The non-network-native nature of the credit of the issuer introduces significant sacrifices to trustlessness.

*Trustlessness:* Permissioned

*Carrying Costs:* Very competitive

*Volatility:* Determined by a variety of factors; sufficiently low volatility is a prerequisite to adoption

*Liquidity:* Limited by the creditworthiness of the issuer

#### **Network-native endogenous value non-convertible stablecoin protocols**

*Examples:* [*Pinto*](https://pinto.money)*,* [*Beanstalk*](http://bean.money/)*,* [*Ampleforth*](https://www.ampleforth.org/)

Rebasing stablecoin protocols (*e.g.*, [Ampleforth)](https://www.ampleforth.org/) have shown efficacy at crossing stablecoin prices over their value pegs, but without the regularity, low volatility or liquidity necessary to create utility. Extreme negative carrying costs during decreases in demand exacerbate difficulty of use.

The value of fiat currency is derived from its utility and the credit of its issuer. Utility of fiat currency is a function of trustlessness, carrying costs, stability and liquidity. Decentralized credit can be used to issue a permissionless fiat stablecoin with competitive carrying costs, low volatility and deep liquidity.

Credit-based network-native endogenous value non-convertible stablecoin protocols are network-native implementations of fiat currency. The value of such assets derive from the credit of its issuer, which exists in a network-native capacity. The network-native nature of the credit creates value in a trustless fashion. The creation of endogenous value through credit facilitates competitive carrying costs. A strong series of network-native incentives and diverse network of creditors can create price stability and deep liquidity without collateral requirements.

Credit-based network-native endogenous value non-convertible stablecoin protocols present an opportunity to achieve trustlessness, competitive carrying costs, low price volatility and deep liquidity. The use of network-native credit can eliminate the negative carrying costs and reduce the excess price volatility associated with rebasing stablecoin protocols.

### **Summary**

Convertibility to endogenous value prioritizes low price volatility at the expense of long term sustainability.

Rebasing tokens have shown some efficacy and peg maintenance, but not enough to create utility. The introduction of network-native credit can reduce volatility.

The current financial system runs on credit-based non-network-native endogenous value non-convertible stablecoin protocols.

Implementations of network-native endogenous value non-convertible stablecoin protocols present a viable option for the creation of trustless currency with competitive carrying costs, low price volatility and deep liquidity that can facilitate the competition between businesses built on decentralized primitives against businesses built on centralized ones.


# Why Pinto Contributor Articles

Read why contributors, past and present, believe in Pinto:

[Proof of Work to Proof of Credit, My Winding Journey to the Pinto Farm](/why-pinto/why-pinto-contributor-articles/proof-of-work-to-proof-of-credit-my-winding-journey-to-the-pinto-farm), by [Ford Pinto](https://github.com/fordpintomoney).

[Building Financial Stability for All, on Chain](/why-pinto/why-pinto-contributor-articles/building-financial-stability-for-all-on-chain), by an Anonymous Farmer.

[Owning My Destiny: Delivering Bitcoin's Promise](/why-pinto/why-pinto-contributor-articles/owning-my-destiny-delivering-bitcoins-promise), by [Default Juice](https://github.com/default-juice)

[A New Social Contract: Trusting God to Trustless Money](/why-pinto/why-pinto-contributor-articles/a-new-social-contract-trusting-god-to-trustless-money), by [Ryan Ham](https://x.com/gkaehddls)

[Bug Hunting, Number Crunching](/why-pinto/why-pinto-contributor-articles/bug-hunting-number-crunching), by [Pinto Pirate](https://github.com/PintoPirate)

[Treading into the DeFi Dark](/why-pinto/why-pinto-contributor-articles/treading-into-the-defi-dark), by [natto](https://github.com/0xntto)

[Crypto Casino to Sustainable Farming](/why-pinto/why-pinto-contributor-articles/crypto-casino-to-sustainable-farming), by [burr](https://github.com/burr-nim)


# Proof of Work to Proof of Credit, My Winding Journey to the Pinto Farm

From catching up to getting ahead, I am proud to be on money’s frontier.

In 2012, I saw headlines of the Mt. Gox hack and Bitcoin’s peak at $32, I assumed the experiment was over. A few months later, an internet friend told me he’d send me some bitcoin, I’d just need to setup a wallet. Back then, every wallet was a full node, I downloaded it and got my own address. He sent me a tiny amount.

I didn’t have to give anyone my personal information to receive money? I could send this without it getting “frozen”? This was not controlled by a simple database from a single company? I read everything I could in the bitcointalk forums, the whitepaper, the wiki, and joined numerous IRC channels to learn more about the tech. I was hooked. A few months later, I experienced my first bull run. That sealed the deal: I needed to buy more. This wasn’t just an experiment, it was a revolution.

In my mind, Bitcoin was either going to work, or it wasn’t, a binary outcome. But soon, Litecoin appeared. XRP came on the scene, and I felt almost offended by it: it was not decentralized at all. To me it was just a scam attempting to get in on the hype. Then Dogecoin appeared. I decided to ignore everything except for BTC, and didn’t pay much attention to the scene until several years later.

Next thing I knew, ETH had become the new cool kid on the block, and I had totally missed out. Every other project up until then just felt like a ripoff, but this was building on the promise of a cryptocurrency future: complex programs could now run on the blockchain, something Bitcoiners discussed, but was never possible, until Ethereum.

I suddenly realized I was behind on the latest tech: Bitcoin was a great store of value, but that was the only thing it did well. ETH had interesting tech Bitcoin didn’t, such as a browser wallet. You could connect it to websites and interact with dApps, the confirmation times were fast compared to BTC’s 10 minutes, and you didn’t have to store the whole chain on your computer. Other tokens lived within Ethereum’s network, and you could do something with them: trade on chain, lend them out, borrow against them. I learned about Alchemix and it blew my mind: self-repaying loans that allowed access to future yield now? Incredible. Financial experiments were happening on chain that were never possible before. It was the dawn of a financial renaissance, and I needed to get up to speed. I wanted to be a part of it.

The best way to win the game is to play it. I got a MetaMask wallet and started experimenting with these different protocols. I borrowed against some ETH on Aave, bridged USDT to BSC, and ape’d into CAKE. Took out a loan on Alchemix. Deposited in to Yearn. LP’d on Curve. Swapped on Uniswap. It was all starting to make sense.

With Aave, you could borrow against regular tokens, but I thought it would be awesome to borrow against yield bearing tokens, like Yearn deposits or LP tokens. Why not earn with your principle, borrow against it and also earn with that? I did some searching and discovered Abracadabra.money. Great, I’m still a step behind, but I can benefit and learn by using their protocol. Around this time UST and it’s 20% return through the Anchor protocol was getting popular. Abracadabra allowed you to borrow against those deposits at a lower rate and loop it, earning 100% APR per year.

But UST was not sustainable. I managed to get out before the collapse. The yield was artificial, the founder was just topping up this pot from other investors and sending it out to pump his token. The token was not creating any actual value and the founder was simply giving out money, which worked only until he ran out. I was part of a private discord group, and we were now on the hunt for stablecoin yields. Would could possibly be as good of a return as that?

Bean money. What the heck was that? Credit backed stablecoin? Whatever it was, it was working, and it was working incredibly well. After I got in, APY’s shot well over 100%, and that was without any looping. I viewed this as a new Crypto primitive. We already had Proof of Work and Proof of Stake, this was something new, Proof of Credit. As long as the system could attract credit (just like as long as there’s someone mining Bitcoin), the system will keep moving. And when prints occur, what if holders got the prints, rather than the government? I was sold. Millions were pouring in daily. And just like Bitcoin: it was either going to work, or it wasn’t. And this looked like it was! So I ape’d in.

The protocol also had a novel governance mechanism, which unfortunately ended up being exploited, but I understood that it was entirely unrelated to the credit model itself. The model was working. I felt that we must determine if Proof of Credit is viable. What if this is better than Proof of Work? No electricity would be wasted. Are its properties more beneficial than Proof of Stake? I started contributing to the project, I was so Bean-pilled, there was nothing more exciting.

But the Replant, the plan to restart the protocol after the hack, fell flat. The protocol simply had too much debt and too little value in it after all of the funds were drained by the exploit. The model was not able to perform as intended with so much baggage. We needed to let the credit-based stablecoin model be reborn and give it the fair chance it deserves. So, I decided to work on Pinto, the first ever Beanstalk fork.

We want sustainable growth and functionality over the long term. We want a new money. Not in the hands of the government, but in the hands of those using the money, and only by their choice. If the supply increases, we should gain, rather than lose value. If the supply needs to shrink, *we* should choose the lending terms. And most importantly: *we* should choose if we opt-in to the system or not.

Like a baby, this thing needs some tender love and care. As it takes it’s first steps, it may need to stumble and learn some new tricks to be ready for prime time. That’s why I’m here.

This is the first time in Human History anyone can build new financial tools. In the past, these tools required custodians and regulators to approve. Now, the blockchain is our custodian and permissionless arena, and we can trust our tools to run exactly as programmed. We don’t need a bank or a company to run this experiment, we simply need code. From anywhere in the world, we can build new tools for freedom; tools to empower individuals, enable free speech through freedom of finance, guarantee the right to life and liberty through secure property ownership, fight inflation through inverting it (you get the money!), and usher in a new era of prosperity. These are the new roaring 20’s, and we are building.

Hope you enjoy the ride,

FordPinto

7 March 2025


# Building Financial Stability for All, On Chain

Pinto is my best bet for helping people like me across the globe.

Growing up in a developing nation, I witnessed firsthand how traditional financial systems can fail those who need them most. In my country, accessing basic financial services that many take for granted is a complex and costly endeavor. Want to buy US dollars? Prepare to pay massive spreads. Interested in investing in the stock market? Be ready to navigate through layers of bureaucracy and hefty fees. The system is so opaque that most people opt to simply do nothing and let their money sit in a basic savings account, earning negligible interest. Considering the high inflation rates of our local currency, people's wealth isn't just stagnating—it's being actively destroyed.

My journey into blockchain technology began when my family heard about crypto and asked for help investing in it. Like many others, I was initially drawn to meme coins. It was hard to resist their allure—every day brought news of astronomical gains, with centralized exchanges actively promoting these success stories. For people in developing nations desperate for a way out of financial hardship, these stories of overnight wealth were the perfect bait.

However, as I delved deeper into the meme coin ecosystem, I discovered its true nature: a brutal zero-sum game built exclusively to extract value from players. The winners were almost always predetermined before each new coin launched, with insiders positioning themselves to profit from the hopes of everyday people. While I was fortunate to learn this lesson before suffering significant financial losses, countless others continue to be taken advantage of. Every day, many lose their hard-earned savings chasing the false promise of easy riches.

I realized that the way forward wasn't gaining something through the zero-sum crypto casino. Instead, it was about finding something that improved users' lives by providing them with a genuinely valuable service.

This is when I decided to dive deeper into DeFi. I found the idea of stablecoins to be very impressive: the ability to hold USD on-chain was revolutionary for someone from my background. It wasn't just about avoiding fees or bypassing bureaucracy—it was about having genuine financial autonomy for the first time.

Moving our assets into USD stablecoins improved the quality of our lives dramatically: no longer did my family have to worry about the dollar exchange rate, wondering if our local currency would suddenly plummet in value. Being able to hold stable dollars meant that for the first time, instead of constantly worrying about our financial survival, we could relax and plan for growth, building our wealth for the future.

I experienced firsthand the impact DeFi can have on regular people.

And I wanted to be more than a user. I wanted to contribute.

This new world still raised concerns. Many existing solutions in the space remain centralized and opaque, posing risks to users' financial well-being. This realization led me to Pinto, a project that represents hope for truly transparent and permissionless finance accessible to everyone.

Personally, working for Pinto is worth it because of the team and our shared vision. From day one, I felt a deep connection with colleagues who not only appreciated my work but understood its importance for people in fragile situations. There's something profoundly meaningful about being part of a global team united by a common goal: creating financial tools that work for everyone.

Our team spans multiple continents and time zones, yet we're connected by more than just code commits and video calls. We're bound by a shared understanding that the future of finance must be more inclusive, transparent, and accessible. Every line of code I write is a step towards that future.

-Anonymous Farmer

8 March 2025


# Owning my Destiny: Delivering Bitcoin's Promise

Living through a financial crisis showed me the underbelly of a centralized fiat currency system. I'm building a decentralized one.

I was on vacation with my family when the government, with help from the European Central Bank, imposed capital controls, restricting cash withdrawals, international transfers, and banking transactions to prevent a financial collapse. We were forced to return back home since my father was afraid of losing his job. The home we returned to was unrecognizable. For several months, you could only withdraw up to 50 euros a day from the Bank, causing multi-block queues outside banks and ATMs. Countless people lost their jobs, homes and dignity while the government extracted taxes to cover up their mismanagement of citizen and pensioner funds. There were rumors of the government performing a “haircut” on citizen bank deposits and even opening up their safe deposit boxes. The former happened in a neighboring country where the government forcefully seized 50-100% of citizens' hard earned money. The restrictions had a significant impact across economic and social life, leading to prolonged low public confidence in the financial system and a deep sense of personal frustration and anxiety stemming from the inability to fully control one's own wealth.

I'm reminded of the World Economic Forum's (WEF) 2016 prediction that by the year 2030, “You’ll own nothing and be happy”, and the appropriate backlash amongst many in the public who know that ownership is power and in many ways, prerequisite to freedom. Experiencing crisis at home helped me realize that when the state has absolute and arbitrary control over the money supply, citizens don't truly own anything. At the state's whim, your property can be seized; your money can be frozen, extracted and inflated to cents on the dollar. Your entire life's work can evaporate due to the corruption and incompetence of those in charge.

This WEF gaf, while to many describing a future distopia to be avoided, has actually been the inescapable state of affairs for centuries.

This stopped being the case on October 31, 2008, the day the Bitcoin whitepaper was published. In a decentralized network, everything that you own is yours in the truest sense. No one can extract your funds from you; no one can force you to opt in to their system. Your keys are yours to keep and yours to lose. No one can override that. Even though it comes with great responsibility, the freedom this technology enabled was unprecedented.

To me, Pinto is a necessary and organic evolution based on the needs of the community that resides in that decentralized network. Bitcoin was created to allow permissionless transactions with trustless money without intermediaries. People then realized that permissionless money needed to be programmable, and thus was born Ethereum. AMMs and the constant product curve were then invented to trustlessly exchange money, solidifying the foundations of the decentralized economy.

It has become apparent that a medium of exchange, a network native currency, needed low volatility to actually be used in true financial and economic activity. This marked the beginning of stablecoins. So far, none of the existent implementations of stablecoins include all the desirable properties mentioned above. Centralized stablecoins with offchain collateral, although popular, still enable centralized control, while also relying on exogenous value. Other collateralized decentralized stablecoins still rely on the value of on chain collateral to be created, sacrificing scalability.

Pinto is a natural progression of that. Much like the US government recognized that gold was no longer a viable backing for the economy’s value, Pinto embodies an understanding that no type of collateral can sustain the on-chain global economy, especially as more value gets bridged onto it. Pinto is, in this way, the next step of money. A truly permissionless, decentralized form of low volatility money that is infinitely scalable, relies on market incentives and AMMs and doesn't impose actions on participants – but merely exists autonomously, creating a positive sum effect for its community, is in my mind a necessity in an increasingly leviathan-ran world.

My first encounter with the system was after the Beanstalk exploit, a few months after the Replant. Even at this stage, the model captivated me. To me, it was the most exciting thing ever—a sophisticated system that embodied all the key principles of permissionless money, wrapped in a lighthearted tone with farming terminology, standing in stark contrast to the rigid, serious language of traditional finance. Built from first principles and fueled by a die-hard community, it was truly unique.

I never got to see that model thrive, until now. And this is why I choose to keep working on it and doing everything in my power to realize its full, infinite potential.

Pinto is the next generation of permissionless money, empowering you to make your own choices, grow your wealth and manifest the leviathan-free economy.\
\
-Default Juice

16 March 2025


# A New Social Contract: Trusting God to Trustless Money

### **My People** <a href="#heading-my-people" id="heading-my-people"></a>

My dad called me recently to tell me he will be installed as the bishop for the local branch of the Mormon church in the neighborhood I grew up in.

I was raised in a deeply [Mormon](https://www.youtube.com/watch?v=51L4-HfR8_g) household by immigrants with no extended family in America. I knew I could trust the intentions of other Mormons because they subscribed to a similar belief in cosmological accountability. The members of our local congregation felt like an extension of our family.

With all the benefits that came with the community, I never made an explicit “choice” to opt-in, I just chose not to opt-out. I was anxious about exploring my own beliefs and often suppressed my ability to branch out and reason about my experiences independently.

The internet was a revelation for me in this sense, full of different kinds of emergent communities and virtual ecosystems for me to discover, entering and exiting freely. MMORPG’s like Runescape and Maplestory had guild systems and functioning economies where people could work together and have fun. Facebook, Twitter and Instagram were young products with significantly less network density where I could make friends and interact with them across space and time. I was inspired by the internet’s ability to bring strangers together, allowing them to self-govern and coordinate based on the values of the participants.

These online interactions influenced how I perceived my real-world communities, making me increasingly aware of the constraints associated with my religion. During college, I found that I didn’t feel satisfied by the belief set of my Mormon community anymore, namely:

1. requirement to trust an unverifiable, cosmologically endowed authority
2. and a high social cost for exiting or having divergent views.

After a painful process of disintegration with the community, it dawned on me that moving to Silicon Valley after college might help me find a community of like-minded individuals who wanted to create new internet experiences reminiscent of those of my youth. I got an offer to start a job at a large technology company after school, packed my bags and didn’t look back.

### **Disillusioned until Ethereum** <a href="#heading-disillusioned-until-ethereum" id="heading-disillusioned-until-ethereum"></a>

I learned almost immediately that my peers weren’t necessarily there because they believed in the potential of the internet to facilitate community. The majority of my peers were almost equally religious as my Mormon community, just devoted to a different God: career and wealth. Much of our conversation centered around maximizing total compensation, how to get more visibility, and how to position yourself for a promotion.

A friend suggested I look into cryptocurrencies. I was highly skeptical. I was interested in internet technology, not scams and get rich quick schemes! I generally believed people who worked on cryptocurrencies had low integrity and were the exact type of people I was trying to avoid. She encouraged me to dig deeper and learn more about the underlying technology.

Within the first week of perusing Crypto Twitter, I found the Loot project on Ethereum. I had no idea what was going on, but the NFT reminded me of games I had played on the internet as a kid. The art for the token was a simple text-based rendering of metadata stored on-chain and used a similar naming convention to the MMORPG’s I had played.

<figure><img src="https://images.mirror-media.xyz/publication-images/Wv4PxyliNgExdg1HBnaES.png" alt="" height="429" width="715"><figcaption></figcaption></figure>

I landed in the Discord server and saw strangers on the internet working together to build projects on top of the NFT’s. People were creating and airdropping ERC-20 tokens to holders, contracts that allowed users to mint art in various styles based on their token, and websites specifically designed for token holders of “Divine Robe”.

For a few weeks, I was in rapture. I looked through one NFT project after another, continually taken in by active communities of people who didn't know one another organizing to support their tokens.

As I dove deeper, a troubling pattern emerged - every NFT project had a similar economic structure: 8000 NFT PFPs with various rarity traits in a collection distributed randomly with extremely mid art, and no real desire to create significant use cases beyond usage of a profile picture on Twitter or Discord. The price of the token was totally disassociated from the actual substance of the online community. Were all of these projects scams? I wasn’t hopeful of any of their potential to succeed in the long-term.

Feeling discouraged, I consulted [Cypherpunk](https://en.wikipedia.org/wiki/Cypherpunk) literature to learn what Ethereum and Bitcoin were all about.

### **God Protocols?** <a href="#heading-god-protocols" id="heading-god-protocols"></a>

My perspective of the world shifted dramatically when I left the religion I grew up in; I began to see the religion as a form of social promise or contract, based on trust in an ultimate authority figure, God, to mediate interactions and enforce rules. I also realized that money and economics, which in many ways form the foundation of social life, also rely on social contracts that currently depend on placing ultimate authority in the State to ensure fairness and create opportunities for collaboration at scale.

Reading [the God Protocols by Nick Szabo](https://nakamotoinstitute.org/library/the-god-protocols/) and other documents helped me understand that open network protocols running on the internet have the potential to radically alter economic and social contracts by eliminating the requirement of trust in a third-party authority altogether.

Trust in an ultimate authority who has the ability to manipulate the rules of engagement at their discretion without leaving an option for individuals to exit compromises the ability for individuals to engage with one another fruitfully because:

1. individuals run the risk of getting rug-pulled
2. the process under which the third-party is governed is unclear and opaque, often left to the judgement (and corruption) of the few individuals in power

Because the internet allows for the easy creation of communities unbounded by space, it lowers the costs of entry and exit, and in turn provides a stronger filtering mechanism for like-minded individuals to gather.

I consider myself extremely lucky to be alive now, when computers have become performant enough for decentralized computer networks like Ethereum and Solana to provide the backbone for experimental economic mechanisms which are transparent, verifiable, and execute deterministically, outcompeting antiquated social contracts that require trust in any third-party and opening the door for a host of new social applications.

### **Enter Beanstalk** <a href="#heading-enter-beanstalk" id="heading-enter-beanstalk"></a>

A friend sent me [the Beanstalk Whitepaper](https://bean.money/beanstalk.pdf), and I quit my job shortly after reading it. Beanstalk embodied precisely the principles I sought—transparent, verifiable, and deterministic economic rules without opaque central control. Its vision of low volatility money as a social contract governed by an open network inspired me deeply.

I was fascinated by the idea of an immutable debt structure. Debt is fundamentally a social phenomenon and a type of social contract. Because the protocol lives on Ethereum, the market to auction off the debt is open and transparent, the terms of engagement under which the debt is to be repaid are verifiable and the way the system advances the interest rate of debt is deterministic. A sufficiently decentralized set of pseudonymous creditors meant was no way for any party to use power to change the terms of the debt contract.

Dependence on third-parties in other currency models creates an explicit economic cost, most easily recognized by nation-states issuing debt to back a currency or when a business owns a network protocol that issues a stablecoin. In the first case, the state gets access to an infinite well of capital available at the expense of the currency's holders, and in the second, the business has to honor its own legal structure to produce a profit for its shareholders and has unilateral control over the smart contract. In the first case, excess demand for the currency flows to those who can borrow the most, and in the second case, excess demand for the currency flows to the equity value of the business.

Beanstalk was an attempt to tackle a fundamental social contract –money– and make the economic mechanisms which govern it transparent, verifiable and deterministic, without a third-party, while redistributing economic excess back to the users of the currency.

Beanstalk stood in stark contrast to the NFT euphoria I was exploring prior; I saw a real attempt at utilizing the properties of Ethereum to create a new social contract. I held hope about the future of Beanstalk and what it represented to me; a step closer to a world where social contracts run on the internet without requiring an ultimate guarantor.

### **Pinto Demands an Opportunity at Life** <a href="#heading-pinto-demands-an-opportunity-at-life" id="heading-pinto-demands-an-opportunity-at-life"></a>

Beanstalk was hacked due to a governance exploit in April 2022. I was devastated like many others who believed in Beanstalk. Yet, the protocol had not failed due to a flaw in its economic design. Some time after the effort to recapitalize Beanstalk, it became clear that the market had crossed beyond a threshold of overwhelming debt to create new bids for protocol debt.

Pinto is a [fork](https://en.wikipedia.org/wiki/Fork_\(software_development\)) of Beanstalk that extends its ideas and includes various improvements to the security and economic efficiency of the protocol. Despite the governance exploit and resulting overwhelming debt burden of Beanstalk, the underlying design principles remain compelling and important. To conclusively determine if the protocol’s open, deterministic and verifiable debt mechanism can sustainably align incentives to create and scale low volatility money, the economic model demands another opportunity at life.

I don’t know if Pinto can generate enough creditworthiness to become a new currency which displaces collateralized stablecoin models and nation-state credit-based currencies, but I believe it is important to try.

I believe a decentralized, pseudonymous group of creditors and value providers all around the world can work together to create stable value on the internet.

An infinite design space awaits us in displacing opaque social contracts which require trust in ultimate authority with new ones that run on the internet in a transparent, verifiable, and deterministic way.

Pinto is a step in the right direction.

–Ryan Ham

24 March 2025


# Bug Hunting, Number Crunching

I use data analytics to guide the Pinto experiment and have fun doing it.

The year was 2022. Someone close introduced me to a “decentralized credit-based stablecoin protocol on Ethereum.” At the time, I did not know what any of these words meant, but the person described the Beanstalk project to me with great passion and excitement, having a strong confidence in the fundamentals of its economic model. Plus, I saw the field was offering a 50x return, so I was enticed to participate.

Initially I saw crypto as a speculation casino, and I didn’t know anything about DeFi or smart contracts. As I began learning more, I found the vision behind decentralized technologies to be very aligned with my personal values; financial privacy and control are very important to me. I don’t want others to be aware of my financial activities, nor am I comfortable having a centralized custodian managing or holding my wealth and potentially restricting my access to it. Today, cryptocurrencies are most broadly used for speculation rather than real economic activity, but over time I came to believe this to be more a reflection on the nascence of the technology than an indication I should write them off altogether. Much remains to be built before blockchain technology can be truly revolutionary in a financial context.

As my familiarity with the specifics of Beanstalk grew, so did my curiosity. The emphasis on the experimental nature of the protocol was compelling; the complexity of the ecosystem surrounding the Bean token introduced game-like elements which influenced the price of the token through factors beyond supply and demand. Individual participants could profit by actively contributing to the stability of the system. There was a clearly communicated sense of uncertainty as to whether the project would succeed or fail, and yet a clear vision as to the real and powerful consequences if it were to succeed. A leviathan-free currency similar to Bitcoin but without the same price volatility would enable a whole new set of economic activity that could not be censored.

Ultimately, the experiment was violently disrupted in the April exploit. I was a mere bystander throughout the Replant process as the Beanstalk Farms contributors scrambled to get the protocol back online. By this point I had gotten more familiar with the project and my interest in it had grown; because the code was open sourced and my background is in software development, I began digging into the code for fun. Knowing nothing about developing on the EVM, I enjoyed learning more about a tech stack that was unfamiliar to me while simultaneously deepening my understanding of the protocol.

My natural attention to detail enabled me to identify a couple unnoticed bugs in the protocol's operation, so I reported them via Immunefi. It was clear I had a lot of value I could add to the project, and had a deep personal interest and stake in its success, so I expressed a desire to join the team shortly after having reported these bugs. Some time passed, and eventually the Beanstalk 2024 budget passed and I was offered the opportunity to join as the data expert.

Since then, the experiment has evolved to Pinto, and I continue to enjoy my role in the lab, providing as many data insights as I can to help the community understand the protocol and assure it runs as intended. Participation in and improvement of the system is far easier with more information available, as the market can then properly react to current conditions. The data is all onchain across many thousands of transactions, but it’s not possible to make sense of what is happening in real time by simply looking through a blockchain explorer; robust monitoring systems are required to ingest data sensibly and evaluate their impacts across Pinto's numerous features.

As both the Beanstalk and Pinto protocols have operated over time, there have been cases where unexpected outputs have been encountered, such as rounding errors or incorrect stalk assignments, that have been missed in audits but were caught by my data analytics. In an ideal world, these errors would never occur, but they have, and being able to identify them in the natural course of my work has saved thousands in unpaid bug bounties.

Everything I do to improve the security, efficacy or correctness of the system is uniquely satisfying, and I take a lot of pride in the contributions I have made here. My strengths are brought out when working on this project, and I'm grateful to use them in contributing toward a vision of financial freedom.

Today, there remains much uncertainty as to what the future holds for decentralized currencies. But it’s clear to me that a decisive winner will emerge in the coming years and decades, and a decentralized economy will exist. Will the dominant currency be Pinto? I don’t know, but I’m committed to continue using my skills to give our experiment the best chance of success.

I can't think of a better one to run.

-Pinto Pirate (fka Soil King)

1 April 2025


# Treading into the DeFi Dark

I pursued software because I believed I could build incredible things. I won’t give up now.

I was looking into the optimization of integrated circuits as part of an undergrad research program. Three years of my hardware engineering degree had been completed and I was exploring what I would do after completing my studies. One of my responsibilities within the research team was to tweak some simple bash scripts we were going to use for the data pipeline. At the time, I had minimal experience and minimal interest in software development. Writing the first script was tedious; I was constantly pestering my peers for help understanding the existing systems and getting stuck deciphering the cryptic syntax of Bash. But once that first script was finished, *it just worked*. It performed as intended and could do it repeatedly for anyone on the team. I had created something of value in a fraction of the time it would take to bring an integrated circuit into reality. I realized that I had the potential to build infinitely more using software than hardware and I fell straight into the rabbit hole. I began focusing my time on building tangentially-related software tooling and by the end of the summer, my computer had become a labyrinth of homebrew scripts automating every step of the work. I was intoxicated by the potential of bringing my imagination into reality so quickly and at such scale. I knew I needed to pivot completely and see where programming would take me.

I finished grad school a few years later and was excited to officially begin a career as a software engineer at a well known robotics company. Unfortunately, my experience at work contrasted deeply with the hopes I had about software as a student. Instead of rapidly iterating high-value features, I found myself building esoteric tools for opaque client contracts. Engineers had no say in product direction, and when frustrations arose, leadership passed down placations gutted of any substance by HR and legal teams. My peers indicated this experience was not unique — it was simply how the industry worked. The thought of staying the course and spending the next few decades fulfilling vague corporate obligations was so dispiriting I left the company and the industry altogether.

A few months later, I stumbled into crypto Twitter. I had no real understanding of what crypto was or what it was trying to solve — but when I found its thought leaders, particularly those in the Ethereum ecosystem, I became absorbed. The corporate bloat had been stripped away and replaced by a meritocracy filled with geeks leading simply by virtue of caring enough about the technology to be early. Everyone was encouraged to build anything and had a chance to garner adoption through sheer novelty. The most exciting projects were not corporations tucked away in an office somewhere dropping incremental iterations, but tiny teams of engineers that lived online, built in the open, and created things that had never been imagined before. Most strikingly, a nobody like me could pick up a conversation with the people actively creating the tech I was using. It was the wild west in the best way. I was hooked.

I found myself digging deeper into DeFi because its utility was often easy for me to see. I was fascinated by the new tools I had access to; studying each new protocol was like solving a new puzzle.

When I discovered Beanstalk, my imagination cracked open. The protocol was seemingly generating millions of dollars of value from nothing, democratizing financial power typically reserved for central governments behind closed doors. Highly skeptical, I joined the Discord and started asking hard questions. I was sure I would be kicked out for challenging the model and doubting the intentions of the team, yet to my surprise the founders responded to my questions directly. They did not demand I justify my inquiries, but simply answered and encouraged me to join the upcoming voice call so I would have a chance to expound on my concerns.

I was unlocked. It was the biggest puzzle I had come across yet and I had access to all the information I needed to solve it. My understanding of the system was only limited by how far down the rabbit hole I was willing to go. My curiosity was insatiable, each day leading me a little deeper. Within a month I was an active contributor, putting up middleware code and helping others onboard to the ecosystem. At first I only wanted to learn how to play the game, but over time I came to understand the fundamental need for a decentralized and scalable stablecoin: abandoning the dollar for volatile assets entirely is not viable, yet relying on centralized stablecoins compromises the entire decentralized EVM stack.

Unfortunately, in April 2022, Beanstalk was targeted by a governance exploit and all user funds were extracted before the system could scale. Development on the Beanstalk model continued, but for all intents and purposes the experiment had been abruptly halted. The team dedicated themselves to trying to restart Beanstalk and repay user funds. Although this was well intentioned, it carried an incredible opportunity cost — for the following two and a half years nobody was iterating on the algorithmic stablecoin problem. The collapse of UST had turned off most of the industry from the idea altogether and the one team still willing to try was locked up trying to make their users whole.

In the years since, the industry ethos of experimentation has worn down. Each new protocol launch is a repackaging of another with a slightly optimized yield strategy. Value extraction is the industry standard and the general assumption upon deployment of new tokens. An air of suspicion surrounds anything that appears too different from the incumbent blue chip protocols.

Pinto launched in November of last year and stands in defiance of this trend. It is trying something that has never succeeded before and that no one can be 100% sure is possible. There is no external expertise or history to reference, and no certainty about what happens next — the only way to find out is to take the leap. Working on Pinto feels like the raw progress I imagined when I was first introduced to software development. Each day Pinto steps into previously uncharted territory and demonstrates how far we can push decentralized technology. The experiment is public and open for us all to contribute towards a better financial system.

Algorithmic stablecoins are not an easy pitch. There is a collective taboo borne from trauma of past failures, which has caused the space to lose its stomach for experimentation and fiercely discourage further attempts. The industry has largely given up, but the fundamental problem has not gone away. Pinto is a push back against 'good enough' — it openly continues to experiment and will bring the industry one step closer to the scalable and decentralized money that we need.

\--natto

28 april 2025

<br>


# Crypto Casino to Sustainable Farming

To build something that lasts, I'm prepared for the long haul.

It was December 2017—I was studying for my calculus final at the university library when I ran into a close friend. He said, "Bro, this thing called Bitcoin just hit $19k. My bags are fat right now. You gotta get in this crypto thing." Easy money? Say less. I registered for a Binance account on the spot, skipped the "overpriced" BTC and bought XRP, XLM, and TRON.

Well, you know how the rest of the story goes. $19k was the peak. Within days, my portfolio—and my ego—were in free fall, leaving me with credit card debt I couldn't pay off with my $12/hour college job. I swore off crypto for good.

Fast-forward three years, and the next cycle was booming. News headlines screamed "Bitcoin just hit $50k!" and "9-year-old makes $1M trading NFTs!" everywhere. But I was smarter than that—I wasn’t going to be burned twice. A couple of months went by before someone close to me urged me to read the Bitcoin whitepaper. To my surprise, it fascinated me.

Bitcoin aligned strangers through math and economics—no banks, no gatekeepers, just code and self-interest securing value. Trustless verification felt revolutionary: proof that well‑crafted incentives could coordinate global consensus. That was absolutely beautiful.

Soon after discovering Bitcoin, Ethereum captivated me further, expanding my view of what decentralized technologies could achieve. Smart contracts turned blockchains from passive ledgers into active economies. While Bitcoin was elegance in scarcity, Ethereum embodied possibility in composability—it didn’t just let you send and receive value; it let you create it.

I found myself speed-running every new ‘innovation’ the space could throw at me: yield farms promising ridiculous APYs, NFT projects spawning faster than browser tabs, and OHM forks launching on every chain. The tech still felt like magic, but the culture felt like Vegas. Then, tucked between the slot machines, I stumbled upon Beanstalk.

Much like Bitcoin, Beanstalk felt designed from first principles. It seemed to create a genuine economic model, carefully engineered incentives, and a design that echoed the same intellectual honesty that first drew me to Bitcoin. No flashing APY banners, just a whitepaper-level spec, code on-chain, and catchy farming metaphors. In a sea of noise, it felt like I had stumbled onto something *real*.

Beanstalk’s Silo rewarded participants for staying, while the Field created organic demand for lenders. It was economic elegance, not hype. With Ethereum as the infrastructure layer, scalable and censorship-resistant tokens representing stable value seemed like the next innovation needed to enable practical, on-chain economies. I Sowed my first couple plots and waited patiently.

While I waited, I joined an NFT‑infra startup—brilliant team, breakneck shipping—but NFTs, beyond identity and community, weren’t convincing. We were building fast, but I began to ask myself, “Was I working on something meaningful to me?” The longer I sat with it, the clearer it became: I don’t just want to write code—I want to work on systems grounded in clear economic incentives and built from first principles.

The morning of the Beanstalk governance exploit, my stomach dropped. Watching the liquidity spiral through Tornado Cash felt like watching a friend flat-line. But once the emotions settled, I was able to separate my emotions from analysis.

The breach wasn’t a failure of the model’s economics, and that distinction mattered to me. I had the sense that under the right conditions and with enough time, Beanstalk—or something like it—could thrive and scale to become the de facto low-volatility money used across DeFi. Unlike collateralized stablecoins like USDC, it didn’t require massive reserves or introduce systemic counterparty risk. It could grow organically and scale infinitely while staying true to the core principles of the space.

I started by submitting a couple PRs to get the UI back online. Casual commits snowballed into full‑time work. Reading the contracts, I saw exactly how the protocol checked and measured its own vitals—liquidity, demand for Soil, price, and debt levels—then tweaked incentives for system participants. As long as one person believed, the system could breathe. I wasn’t just reading code; I was watching an engine self-regulate in real time. Every new insight deepened my conviction: *this* was the first-principles tech I’d been yearning to contribute to.

But what really sealed it for me was the people. Not only were they some of the sharpest minds I’d worked with, but they also cared—about the future, the design, and each other. That kind of alignment is rare.

The exploit prevented Beanstalk from reaching its full potential in its infancy. Pinto gives us a second chance to do it right. Starting from Season 1 with a beefed-up model (including all the improvements made since Beanstalk's original launch) and the same commitment to first-principles design, Pinto represents more than a fork. It’s an opportunity to prove this model can scale sustainably.

Over the last couple years, I’ve learned that patience here isn’t measured in days or weeks, but years—the only tempo at which a new monetary system can take root. As the protocol earns creditworthiness, paying back lenders through what may be violent cycles of contraction and expansion, long-term participants will come. It’s a multi-year, multi-cycle arc, and the model is built to embrace that pace.

This isn’t just about rebuilding. It’s about fulfilling the long-term vision: creating Leviathan-free, low-volatility money that can make the promise of Bitcoin work for the world. I look forward to seeing it through.

\--burr

9 june ‘25


# Pinto Roadmap \[Coming Soon]


# Values and Properties

Pinto combines the values of Ethereum with the properties of USD. Below are definitions of each, and how Pinto implements them.

[The Values of Ethereum](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#the-values-of-ethereum)

* [Censorship Resistance](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#censorship-resistance-pinto-is-designed-to-be-maximally-resistant-to-censorship)
* [Trustlessness](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#trustlessness-pinto-is-building-fiat-currency-free-from-the-risk-of-arbitrary-money-printing-and-int)
* [Permissionlessness](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#permissionlessness-anyone-with-an-internet-connection-and-funds-on-the-ethereum-network-can-particip)
* [Fairness](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#fairness-the-pinto-printer-is-designed-to-be-free-from-capture)

[The Properties of USD](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#the-properties-of-usd)

* [Scalable](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#scalable-pinto-can-grow-infinitely-to-meet-market-demand-for-trustless-low-volatility-currency)
* [Low Volality](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#low-volatility-pinto-seeks-to-minimize-the-volatility-of-its-value-through-thoughtful-incentives-ins)
* [Medium of Exchange](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#medium-of-exchange-prioritizing-low-volatility-and-yield-over-upward-price-movement-makes-pinto-the)
* [Unit of Account](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/60/why-pinto/pintos-values#unit-of-account-low-volatility-and-algorithmic-distribution-of-new-mints-make-pinto-the-optimal-cryp)

## The Values of Ethereum

### Censorship Resistance — ***Pinto is designed to be maximally resistant to censorship*****.**

**Censorship Resistant:** resilient to the prevention of valid actions from being executed reliably.

Censorship can take the form of:

1. **Communication failures**

   **Communication:** information sharing
2. **Availability failures**

   **Availability:** accessibility and operational readiness
3. **Liveness failures**

   **Liveness:** eventual progress and completion of all valid operations
4. **Integrity failures**

   **Integrity:** correct completion of operations

While Pinto trades against a variety of value which is subject to censorship, the currency itself is designed to be free from censorship. Due to the lack of censorship resistant value on chain (besides ETH), Pinto must manage the risk of censorship by minimizing the concentration of risk of censorship by any one party. Instances where some of the value Pinto trades against is censored, Pinto's price and liquidity would fall, but the integrity of the protocol as a whole would be maintained.

The current distribution of underlying liquidity is split amongst:

* ETH, which is censorship resistant.
* cbETH, cbBTC and USDC, all of which are censorable by Circle/Coinbase.
* WSOL, which is censorable by Wormhole.

Future upgrades to the [Deposit whitelist](/resources/contracts#current-deposit-whitelist) will incentivize [Converting](/pinto-mechanics/silo-the-perfect-complement-to-credit/converts-changing-price-from-within) assets censorable by Circle/Coinbase into assets censorable by other entities, further decentralizing the risk of censorship within the protocol.

A future blacklist mitigation mechanism will extend the censorship resistance of the protocol by pushing the risk of holding censorable value within the protocol onto the holders of that value, instead of the protocol as a whole, by automatically freezing the Pinto in the censored pool. In this case, even if one of the non-Pinto assets in a Pinto liquidity pool is censored, while total liquidity would decrease, the value in all the other pools and pure Pinto would be protected. This design will safeguard the health of the protocol and encourage participants to favor Depositing value that increases overall censorship resistance.

### Trustlessness — Pinto is building fiat currency free from the risk of arbitrary money printing and interest rate manipulation.

**Trustlessness:** reliability is assured through autonomy, incorruptibility, and verifiability rather than trust.

* **Reliability:** consistent and correct performance.
  * Reliable systems function as expected over time under both normal and adverse conditions.
* **Autonomy:** rule compliance guaranteed by internal mechanisms.
  * A system is autonomous if its rules are upheld by protocol design and crypto-economics without arbitrary or subjective judgement.
* **Incorruptibility:** resistance to unauthorized change.
  * Incorruptible systems prevent rules from being manipulated and tampered with. Change occurs only through explicitly defined mechanisms and authorized processes, ensuring the system's integrity cannot be compromised.
* **Verifiability:** the ability to independently validate correctness.
  * A system is verifiable to a participant if they can confirm correctness without trusting any party. Verification is typically enabled by transparency, reproducibility, or cryptographic proofs.

Pinto functions autonomously according to verifiable rules and parameters, which the Pinto Community Multisig (PCM) [upgrades transparently](/appendix/upgradability) to improve the protocol. Two weeks after the protocol reaches 500M supply, the PCM will forfeit governance of Pinto, with the exception of fixing security vulnerabilities and bugs. In its place, a permissionless fork system will enable continued improvements while protecting participants from having the code underlying their currency ever changed without their consent.

### Permissionlessness — Anyone with an internet connection and funds on the Ethereum network can participate in Pinto.

**Permissionlessness:** the absence of approval requirements for participation.

**Permissioned:** the quality of requiring approval for participation.

Note: Barriers of strict technical capacity do not constitute permissions (*e.g.,* internet connection, gas payment).

Pinto is open for anyone to participate.

### Fairness — The Pinto printer is designed to be free from capture.

**Fair:** treating all parties impartially according to agreed upon rules and standards.

In a fair market, informed participants act freely and compete on a playing field with the following properties:

* existing competitive advantages are difficult to entrench. 'Capture' is difficult, restricted to product or strategy alpha rather than privileged access or anti-competitive techniques.
* while participants can spend to achieve certain advantages over others, each additional marginal increase in advantage over other participants has increasing marginal costs.
* latency and information asymmetry are minimal.

Pinto functions according to explicitly defined rules. While Pinto rewards older and larger [Deposits](/resources/glossary#deposit) with more mints, the competitive advantage of older Deposits decreases over time and larger Deposits cost more for each marginal unit of value Deposited. [Tractor](/pinto-mechanics/toolshed/tractor-automating-the-farm) makes autonomous execution available to every participant, independent of technical savvy, and minimizes information asymmetry within the constraints of the EVM.

### Open-Source — From code to plain language write-ups, Pinto is accessible to everyone.

**Open Source:** software that is freely available for anyone to:

1. run;
2. study and modify;
3. redistribute in original and modified form.

The protocol is [completely open-source](https://github.com/pinto-org), and tremendous effort has gone into defining it and putting it into context, from rigorous technical documentation (*i.e.*, [the whitepaper](https://pinto.money/pinto.pdf)) to plain language [explainers](https://docs.pinto.money/).

## The Properties of USD

### Scalable — Pinto can grow infinitely to meet market demand for trustless low-volatility currency.

**Scalable:** competitive volatility and carrying costs can be sustained at arbitrary supply.

Collateralized stablecoins are limited by the amount of available collateral. Due to the lack of crypto-native collateral, collateralized stablecoins have been forced to sacrifice Ethereum's values and use centralized collateral in order to scale to meet demand. Instead of collateral, Pinto uses credit, which is infinitely scalable and network-native, enabling Pinto to grow to meet arbitrary demand without compromising on Ethereum's values.

### Low Volatility — Pinto seeks to minimize the volatility of its value through thoughtful incentives instead of trying to maintain a perfect peg.

**Low Volatility:** purchasing power varies minimally over time.

The stablecoin trilemma states that a stablecoin cannot be stable, scalable and decentralized. Pinto strikes the optimal balance within this trilemma by sacrificing perfect stability in favor of low volatility, thereby enabling it to scale to meet arbitrary demand without sacrificing the benefits of decentralization – which is not an end in and of itself – namely trustlessness, permissionlessness, censorship resistance and fairness.

### Medium of Exchange — Prioritizing low volatility and yield over upward price movement makes Pinto the optimal crypto-native Medium of Exchange.

**Medium of Exchange:** an asset widely accepted as payment, enabling trade without direct barter.

Pinto has the unique combination of being low in volatility and generating native yield, which makes an optimal medium of exchange between various types of value. [sPinto](/pinto-mechanics/toolshed/spinto-composing-pinto-with-defi), the fungible yield-bearing ERC-20 wrapper of Pinto Deposits, offers the ability to integrate Pinto into existing DeFi primitives and distribute yield to liquidity providers with minimal friction.

### Unit of Account — Low volatility and algorithmic distribution of new mints make Pinto the optimal crypto-native Unit of Account for loans.

**Unit of Account:** a monetary standard used to price and compare value.

Unlike centralized fiat currencies, in which new currency is printed and distributed arbitrarily, often devaluing the wealth of the respective system's participants and the purchasing power of each unit of the currency, Pinto autonomously distributes newly minted currency directly to its holders. Combined with its native volatility-minimization mechanisms, the protocol creates a currency designed to serve as a unit of account for value and loans of value.


# Mechanics Overview

Pinto uses dynamic incentives to oscillate its price across its value target of $1.

The Farm is the Pinto ecosystem. Anyone can become a Farmer by interacting with Pinto.

The Farm has four primary components: the Silo, Field, Sun and Toolshed. Each component independently implements mechanisms that each contribute to protocol maintenance.

The Silo is the protocol’s liquid deposit facility. The Silo offers passive yield opportunities to farmers for Depositing Pinto and other whitelisted assets. Deposits earn a portion of all Pinto minted. The Silo is designed to minimize the frequency and veracity of bank runs. For more information about the Silo, see [The Silo: The Perfect Complement to Credit](/pinto-mechanics/silo-the-perfect-complement-to-credit)

The Field is the protocol’s lending facility. The Field offers yield opportunities to farmers for lending Pinto to the protocol. All Pinto lent to the protocol are burned to reduce supply. Lenders are repaid on a first in, first out basis whenever Pinto is minted. For more information about the Field, see [The Field: The Most Innovative Lending Facility In Crypto](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto)

The Sun is the protocol’s autonomous timekeeping mechanism. The Sun offers payment to farmers for participating in timekeeping and ensuring regular code execution. Time on the farm is kept in Seasons, which last approximately 1 hour. For more information about the Sun, see [The Sun: The Source of Life on the Farm](/pinto-mechanics/sun-the-source-of-life-on-the-farm).

The [Toolshed](/pinto-mechanics/toolshed) offers a suite of tools to Farmers for efficient use of Pinto and other protocols on Base. Nothing in the Toolshed is directly related to protocol maintenance.


# Silo: The Perfect Complement to Credit

The Pinto Deposit facility

Pinto fundamentally derives its value and scalability from its [creditworthiness](/why-pinto/credit-vs-collateral). However, creating stability in perpetuity is a significantly more complex problem than simply issuing debt in a sustainable fashion. The Silo, Pinto’s Deposit facility, handles everything from bank run minimization to yield distribution, volatility dampening and liquidity management.

The Silo consists of multiple interconnected layers of incentives that each play a part in protocol maintenance. This short document provides a high level overview of each component of the Silo and how it contributes. Subsequent documents go into detail to explain why each component is designed the way it is.

## **The Silo: Pinto’s Liquid Deposit Facility**

Anyone can [Deposit](/resources/glossary#deposit) and [Withdraw](/resources/glossary#withdraw) value from the Silo at any time. There are two types of tokens that can be Deposited in the Silo, Pinto and Liquidity Pool (LP) tokens – which are half Pinto and half non-Pinto – on the [Deposit Whitelist](/resources/glossary#deposit-whitelist). Value Deposited in the Silo earns a portion of all Pinto mints.

The Silo uses the following incentive mechanisms to complement the Field to create low volatility money with competitive carrying costs:

* [The Stalk System](#the-stalk-system) for bank run minimization and yield distribution;
* [Converts](#converts) for the efficient use of existing liquidity for peg maintenance;
* [The Seed Gauge](#the-seed-gauge) for the management of the distribution of liquidity; and
* [The Convert Bonus and Penalty System](#the-dynamic-convert-bonus-and-penalty-system) to complement the Seed Gauge and Converts for fine tuned peg maintenance.
* [The Flood](#the-flood) to minimize growth when the protocol is of growing too quickly due to inorganic demand.

### [**The Stalk System**](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism)

The Stalk System has two primary roles: minimizing bank runs and distributing yield.

Any time someone Deposits value into the Silo, their Deposits receive [Stalk](/resources/glossary#stalk) and [Seeds](/resources/glossary#seeds) corresponding to the Pinto Denominated Value (PDV) and asset Deposited. Stalk entitles Deposits to a pro-rata portion of all future Pinto mints, and Seeds yield more Stalk every Season (\~1 hour).

All Deposits are subject to a Germination Period upon their creation, currently set to 1 full Season, during which they are not entitled to earn a portion of Pinto mints. The Germination Period is designed to eliminate the potential to earn Pinto mints without holding exposure to the system by Depositing, calling the [`gm`](/resources/glossary#gm) function to trigger the start of the next Season and the distribution of Pinto mints, and then Withdrawing the Deposited value and the yield earned in a single transaction, thereby earning yield without risk.

Upon Withdrawal from the Silo, all Stalk, Seeds and Stalk accumulated from Seeds of the Withdrawn value are forfeited, thereby creating opportunity cost for leaving during a bank run and coming back later.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2Fj9qY8UPIvjosLDhW8gFL%2Fimage.png?alt=media&amp;token=daa15110-4a0f-42b7-a23d-4ba3720e925a" alt=""><figcaption></figcaption></figure>

*For a deeper dive into the Stalk System, read more* [*here*](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism)*.*

### [**Converts**](/pinto-mechanics/silo-the-perfect-complement-to-credit/converts-changing-price-from-within)

Converts enable holders of Deposited assets to change their exposure within the Silo without forfeiting Stalk.

When Deposited Pinto is Converted into Deposited LP tokens, the ratio of Pinto to non-Pinto in the liquidity pool the Pinto was Converted into increases, thereby decreasing the price of Pinto. Conversely, when Deposited LP tokens are Converted into Deposited Pinto, the ratio of Pinto to non-Pinto in the liquidity pool the Pinto was Converted from decreases, thereby increasing the price of Pinto. Converts between Pinto and LP tokens enable Depositors to actively contribute to peg maintenance by buying Pinto when the price is below its value target and selling Pinto when the price is above, using value already in the Silo.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FWmJkeE2bV9x5uEWw5MUX%2Fimage.png?alt=media&amp;token=07a08c59-170e-435d-b739-1ca30dcdb559" alt=""><figcaption></figcaption></figure>

Deposited LP tokens can also be Converted to other Deposited LP tokens in a similar fashion. LP → LP Converts do not necessarily affect the price of Pinto, but do affect the distribution of liquidity.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FnVRkz0c9RoCDCX4nFFOi%2Fimage.png?alt=media&amp;token=56008000-1abc-40ee-ae9d-31f87b5bd14f" alt=""><figcaption></figcaption></figure>

The Silo incentivizes (disincentivizes) Converts by adjusting the Seeds rewarded to a given Deposit type and awarding (applying) a Stalk Bonus (Penalty).

*For a deeper dive into Converts, read more* [*here*](/pinto-mechanics/silo-the-perfect-complement-to-credit/converts-changing-price-from-within)*.*

### [**The Seed Gauge**](/pinto-mechanics/silo-the-perfect-complement-to-credit/optimizing-liquidity-distribution-via-the-seed-gauge-system)

The Seed Gauge has two dimensions: the ratio of Seeds between Deposited Pinto and Deposited LP tokens, and the distribution of Seeds among Deposited LP tokens.

Pinto autonomously adjusts the relative Seed allocation between Deposited Pinto and Deposited LP tokens to incentivize changes in their proportion within the Silo, thereby increasing or decreasing the price of Pinto without altering the overall liquidity in the protocol. In particular, Pinto uses the [Crop Ratio](/resources/glossary#crop-ratio) to set the ratio between the number of Seeds for 1 Deposited Pinto compared with 1 Deposited PDV of the LP token with the most Seeds.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2Ff3tunUkPM8Y9o7sKayVr%2Fimage.png?alt=media&amp;token=3fd38b00-7a13-4798-9977-a5295f2bd58a" alt=""><figcaption></figcaption></figure>

Pinto also autonomously adjusts the ratio of Seeds among the various Deposited LP tokens to incentivize the value Pinto trades against to be distributed as desired by the protocol. The [optimal distribution](/resources/contracts#current-deposit-whitelist) of liquidity is defined via protocol governance and the protocol autonomously increases (decreases) the Seeds allocated to LP tokens that are underweight (overweight) compared with the optimal distribution.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FgEz9b8TR1jEZucpIUNcj%2Fimage.png?alt=media&amp;token=ff85c2fd-27e5-45d4-9bec-ae5a99e160c8" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2Fq6pPxIpKUEbScdSqph0p%2Fimage.png?alt=media&amp;token=d75dfde3-6517-4c5a-a764-678a925b810a" alt=""><figcaption></figcaption></figure>

*For a deeper dive into The Seed Gauge, read more* [*here*](/pinto-mechanics/silo-the-perfect-complement-to-credit/optimizing-liquidity-distribution-via-the-seed-gauge-system)*.*

### [**The Dynamic Convert Bonus and Penalty System**](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives)

The Dynamic Convert Bonus and Penalty System is the newest component of the Silo and remains a work in progress. It allows the Silo to fine-tune the incentives to perform a given Convert within the Silo by awarding (or applying) a Stalk Bonus (Penalty), enabling more granular peg maintenance than is possible merely with the Seed Gauge.

There are four subcomponents to the system: [Dynamic Convert Up Bonus](/resources/glossary#dynamic-convert-up-bonus), [Dynamic Convert Down Penalty](/resources/glossary#dynamic-convert-down-penalty), [Convert Up Penalty](/resources/glossary#convert-up-penalty-stalk-penalty) and [Convert Down Bonus](/resources/glossary#convert-down-bonus-stalk-bonus). Whether a bonus is awarded or a penalty is applied depends on the state of the protocol and direction Converted.

To date, only the Convert Down Penalty is live. This was implemented first because of the overwhelming preference demonstrated by participants to hold Deposited LP tokens over Deposited Pinto resulted in the protocol spending the majority of its time below the value target, even when the price was often very close to it.

The next subcomponent to go live in the coming weeks will be the Convert Up Bonus, which will complement the Convert Down Penalty to create more regular oscillations across the value target in instances where the price is relatively stable and close to the value target and the protocol has a healthy amount of liquidity.

A Convert Up Penalty and Convert Down Bonus can be implemented in the future once data indicate such subcomponents would make meaningful contributions to peg maintenance.

*For a deeper dive into the Dynamic Convert Bonus and Penalty System, read more* [*here*](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives)*.*

### [**The Flood**](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-flood-biblical-returns-to-prevent-pump-and-dumps)

The Flood is the Silo's way to cool the protocol down when it is at risk of overheating. Algorithmic stablecoins are highly reflexive: when the protocol is growing, the returns generated for participating in the protocol attract more demand, which leads to more growth, etc. Often, a major growth cycle is followed by high levels of outflows from the protocol, leading to significant downside volatility.

The Flood is designed to minimize inorganic demand when the protocol is growing excessively by minting additional Pinto and selling the extra Pinto directly on the market. The proceeds of the Flood are distributed to Deposits in the Silo before it started to Rain – the protocol indicator that the protocol may Flood soon.

The Flood has demonstrated efficacy at minimizing excessive growth in both [Beanstalk](https://bean.money) and Pinto's early days.

*For a deeper dive into the Flood, read more* [*here*](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-flood-biblical-returns-to-prevent-pump-and-dumps)*.*

### **In Summary**

The Silo has multiple layers of incentives, each with a meaningful role to play in peg maintenance. The Stalk System creates the foundation, minimizing the duration and magnitude of bank runs by creating an opportunity cost for leaving and coming back, and rewarding Depositors with Pinto mints according to the amount, type and duration of their Deposit.

Converts allow Depositors to seamlessly respond to price action and the Seed Gauge using value already Deposited in the Silo. The Seed Gauge allows the protocol to autonomously incentivize Converts towards the value target and ideal liquidity distribution by adjusting the relative incentives to hold any particular assets in the Silo.

The Convert Bonus and Penalty System allow the protocol to fine-tune the incentives – or disincentives – to Convert, given the state of the protocol, to complement the Seed Gauge and maximize the efficacy of the peg maintenance mechanism.

Lastly, the Flood dampens excessive growth when the protocol is at risk of overheating due to its highly reflexive nature.

Together, these mechanisms foster peg maintenance and liquidity management by aligning Depositor incentives with the well-being of the protocol.

*Go on to the next documents to learn more about the components of the Silo, or* [*jump ahead to read about the Field.*](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto)


# The Stalk System: DeFi's First Bank Run Minimization Mechanism

One of the two primary problems that an algorithmic stablecoin must solve is how to minimize bank runs.

Bank runs are inevitable: because there is always less liquidity than value in the system, there is no way for every participant to exit the system without the value of their assets decreasing. The more people who leave, the less value available for others to do the same. Therefore, if some people leave, it can scare others into leaving as well, kicking off a bank run.

In other words, algorithmic stablecoins are highly reflexive. When the going is good, people pile in to participate in the yield generated by the growth of the protocol. But, when the momentum shifts in the opposite direction, [a trickle can quickly turn into a rapid outflow.](/why-pinto/terrable-design-lessons-from-terras-collapse-on-the-path-to-a-scalable-network-native-moe-and-uoa)

Therefore, a properly designed algorithmic stablecoin must have a highly effective and anti-reflexive bank run minimization mechanism.

### **To Run, or Not to Run**

That is the question every holder of an algo stable faces once a bank run starts. In order to survive, the protocol must create sufficient incentives for people to stay.

The main incentive algo stables are able to offer participants is yield in the form of more currency, which increases supply. However, during a bank run the protocol is trying to reduce supply, not increase it. If it increases the supply during a bank run, it will only exacerbate the run.

**The key insight of the Stalk System is that while the protocol cannot mint more currency during the bank run, it&#x20;*****can*****&#x20;offer higher yields in the future when the protocol is minting for those that stuck around during the run.**

In more traditional economic terms, the Stalk System creates an explicit opportunity cost of future mints for people that participate in the bank run and then rejoin the system later.

### **Stalk System 101: Stalk and Seeds**

The Stalk System uses two assets, [Stalk](/resources/glossary#stalk) and [Seeds](/resources/glossary#seeds), to create this opportunity cost. Stalk entitles users to a pro rata portion of all mints. Seeds yield more Stalk every hour.&#x20;

Upon [Deposit](/resources/glossary#deposit), Depositors receive Stalk based on the Pinto Denominated Value (PDV) of the Deposit, and Seeds based on the asset Deposited and the PDV of the Deposit.

The opportunity cost for participating in bank runs is created because upon [Withdrawal](/resources/glossary#withdraw), all Stalk and Seeds, including Stalk accumulated from Seeds, associated with the Deposit are burned.

During a bank run, Depositors must decide between staying put to keep all of the Stalk from Seeds they have accumulated since they initially Deposited – and continuing to earn Stalk until the printing resumes – or leaving and burning their Stalk that has accumulated from Seeds during the duration of their Deposit.

### **Anti-Reflexivity**

An effective bank run minimization scheme must be anti-reflexive: the deeper into the bank run the protocol gets, the more the bank-run minimization scheme must incentivize staying put.

In the case of the Stalk System, as other Depositors Withdraw from the protocol and burn their Stalk, the marginal benefit of each remaining Depositor's Stalk from Seeds increases because it represents a larger and larger portion of the total Stalk.

### **Shorter Bank Runs**

The Stalk System is designed such that if a Depositor decides to participate in the bank run, they are incentivized to run as soon as possible, because their Stalk from Seeds are worthless to them anyways.

This naturally segregates participants into two categories: bank runners that leave immediately once a bank run starts, and long term Depositors that stick around.

While this leads to short periods of high volatility during which short term holders leave the system, it has the benefit of ending the bank run sooner so the system can then swiftly return to its value target. In other words, given that bank runs are inevitable, the protocol creates the conditions to get them over with and then efficiently return to a healthier state.

### **Fair to New Participants**

The original Stalk System had a fixed number of Seeds for each asset on the Deposit Whitelist, which had a drawback: it was essentially impossible for newer Deposits to ever catch up to the Stalk of older Deposits of similar size. This problem made it unattractive for new Deposits to enter the system, and was exacerbated during extended periods without any mints, which is exactly when the system wants to attract new Deposits most.

The solution was to upgrade the Stalk System to include a parameter in the protocol – currently set to 6 months – that makes it such that a new Deposit with an average number of Seeds per PDV will catch up to the average Stalk accumulated from Seeds per PDV across all Deposits, at the time of the new Deposit, in that time frame.

Properly setting this parameter is a balancing act. If the time to catch up is set too high, then it discourages new Deposits; if it is set too low, then the opportunity cost created by the Stalk System may be insufficient to discourage participation in bank runs.

In practice, this solution dramatically decreases the friction for new Deposits to enter the system, more equitably distributes new supply when the protocol is growing and facilitates more decentralized ownership.

### **Silo Rewards** <a href="#silo-rewards" id="silo-rewards"></a>

{% hint style="info" %}
The following reward types are all abstracted away as Claimable Pinto, Stalk and Seeds in the [Pinto UI](https://pinto.money/).  Any time you claim one of these in the Pinto UI, you claim all of them.
{% endhint %}

Maximizing the various forms of yield accrued in the Silo, which are explained here, requires active claiming:

Earned Pinto are Pinto that have been paid to a Stalkholder since the last Season the Stalkholder claimed (Planted) them. Upon Plant, Earned Pinto become Deposited Pinto.

Earned Stalk are Stalk earned from Earned Pinto. Earned Stalk automatically contribute to Stalk ownership and do not require any action to claim them.

Grown Stalk is the Stalk earned from Seeds. Grown Stalk does not contribute to Stalk ownership until it is claimed (Mown). Mow can be called on its own, and it is also called at the beginning of any Silo interaction (Depositing, Withdrawing, Converting, Planting, etc.). Throughout the Pinto documentation, Mown Stalk is often referred to as "Stalk accumulated from Seeds".

Plantable Seeds are Seeds earned in conjunction with Earned Pinto. Plantable Seeds must be Planted in order to grow Stalk.

### **In Summary**

Bank runs are unavoidable for algorithmic stablecoins, but they can be managed. Pinto’s Stalk System does this by turning reflexivity on its head: those who exit realize an opportunity cost in the event of the protocol's future success, while those who stay see their share of future mints grow. This design shortens bank runs, rewards long-term participants, and ensures new entrants can still compete for yield, making the system more resilient and equitable over time.


# Converts: Changing Price from Within

In order to prevent value from being extracted from the protocol, Pinto rarely takes any action in the open market (*e.g.*, buying and selling). Instead, it creates and regularly adjusts incentives to encourage participation in protocol maintenance.

At a high level, there are three primary incentive structures in place within the protocol.

1. The [Stalk System](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism) creates an incentive to Deposit value into the Silo and leave that value Deposited.
2. The [Field](/resources/glossary#field) creates an incentive to lend to the protocol to reduce supply.
3. The [Convert System](/pinto-mechanics/silo-the-perfect-complement-to-credit/converts-changing-price-from-within) layers additional incentives on top of the Stalk System to incentivize participation in protocol maintenance with value that is already Deposited in the Silo.

### What is a Convert?

Simply put, [Converts](/resources/glossary#convert-1) take one form of value Deposited in the [Silo](/resources/glossary#silo) and *Convert* it into another form of value Deposited in the Silo.

Converts don’t change the overall liquidity in the Silo, but can change the price of Pinto or the distribution of the liquidity. The effects of a given Convert on the state of the protocol depend on the type of Convert.

There are four types of Converts within the Silo.

1. [LP → Pinto Convert](#lp-pinto-convert-i.e.-convert-up)
2. [Pinto → LP Convert](#pinto-lp-convert-i.e.-convert-down)
3. [LP → LP Convert](#lp-lp-convert)
4. [Lambda → Lambda Convert](#lambda-lambda-convert)

### **Primer on AMMs**

If you already understand [automated market makers](https://blog.uniswap.org/what-is-an-automated-market-maker) (AMMs), feel free to skip ahead to [LP → Pinto Convert (*i.e.*, Convert Up)](#lp-pinto-convert-i.e.-convert-up).

The price of Pinto is derived from the value that it trades against in various 2-sided AMM liquidity pools (LPs). The most basic way to understand pricing in 2-sided LPs is that at all times, half of the value in the pool is Pinto, and half of the value in the pool is the non-Pinto asset that Pinto trades against.

Therefore, in order to derive the USD price of Pinto from a liquidity pool, the number of the non-Pinto asset multiplied by its USD price is divided by the number of Pinto.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FeUh8ooESc4xSTvQA3Wgw%2Fimage.png?alt=media&amp;token=f85a593a-0d74-4f12-9649-5b24ff3978b9" alt=""><figcaption></figcaption></figure>

Anyone can buy Pinto from and sell Pinto to Pinto LPs at any time. When someone buys Pinto, they add non-Pinto assets to the pool and receive Pinto in return, resulting in the price going up. Conversely, when someone sells Pinto, they add Pinto to the pool and receive non-Pinto assets in return, resulting in the price going down.

Anyone can provide liquidity to Pinto LPs. When one adds liquidity to an LP, one receives an LP token that represents pro-rata ownership of all the liquidity in the LP. At any time, one can redeem one's LP for the underlying liquidity in the pool. Liquidity can be added or removed in (1) equal proportions to the value already in the pool (*i.e.*, a 2-sided deposit or withdrawal), (2) just one of the assets in the pool (*i.e.*, a 1-sided deposit or withdrawal) or (3) any proportion in between.

In practice, a 1-sided deposit into the pool has an identical outcome to trading the single asset into the proportion of assets in the pool, and then adding 2-sided liquidity. Similarly, a 1-sided withdrawal has an identical outcome to withdrawing 2-sided liquidity and then trading one of the assets into the other.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FXYozt9lRorTmrfWuTELU%2Fimage.png?alt=media&amp;token=30118e6f-7947-49f3-9197-c68b0a5b21a8" alt=""><figcaption></figcaption></figure>

For more information about Pinto's AMM's refer to the [Pinto Whitepaper](https://pinto.money/pinto.pdf#page=47).

### **LP → Pinto Convert (*****i.e.*****, Convert Up)**

During an LP to Pinto Convert, a one-sided withdrawal of Pinto is made from the liquidity pool, and the Pinto that are received are left [Deposited](/resources/glossary#deposit) in the Silo as pure Pinto (*i.e.*, not in any pool).

For the individual Depositor that Converted, the exposure of their Converted assets changed from LP (*i.e.*, half Pinto and half non-Pinto) to 100% Pinto. For the protocol, the total amount of liquidity remains constant.

However, while the liquidity in the system is constant, the price of the Pinto in the liquidity pool increases as a result of the LP → Pinto Convert because of the removal of Pinto from the pool.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2Fi42kTK37GaiaWS1JId4F%2Fimage.png?alt=media&amp;token=7390f07b-4f80-42c9-835f-f68a05b59dfe" alt=""><figcaption></figcaption></figure>

Depositors who Convert the price of Pinto back to $1 make money.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FZFe9MI7L0Z6qu93JtZ8D%2Fimage.png?alt=media&amp;token=db9d8817-1ceb-4335-9fbe-45ccbaabd628" alt=""><figcaption></figcaption></figure>

### **Pinto → LP Convert (*****i.e.*****, Convert Down)**

Pinto → LP Converts are the mirror of LP → Pinto Converts.

During a Pinto → LP Convert, a one-sided Deposit is made with Pinto that was already in the Silo into the liquidity pool selected by the Convertor.

For the individual Depositor that Converted, the exposure of their Converted assets changed from 100% Pinto to LP (*i.e.*, half Pinto and half non-Pinto). Similarly to LP → Pinto Converts, the amount of liquidity in the system remains constant.

Opposite from LP → Pinto Converts, the price of Pinto in the liquidity pool decreases as a result of the Pinto → LP Convert because of the addition of Pinto into the pool.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FAFRhas2rcGbOAiaWbmW0%2Fimage.png?alt=media&amp;token=3573f6e4-e41d-478b-922d-ebbb15f82f19" alt=""><figcaption></figcaption></figure>

### **LP → LP Convert**

During an LP → LP Convert, a two-sided withdrawal is made from the source liquidity pool, the non-Pinto portion is sold into another non-Pinto asset, and a two-sided deposit is made into the destination liquidity pool. All three parts of the LP → LP Converts occur atomically.

For the individual Depositor that Converted, the exposure of their Converted assets changed from having the non-Pinto element of the source liquidity pool to the non-Pinto element of the destination liquidity pool. The same has occurred for the protocol.

LP → LP Converts do not change the overall amount of liquidity in the protocol, nor do they affect the price of Pinto (except for very small loss in value due to slippage from the sale of one non-Pinto asset into another).

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2F4rMusvEAC2brEb6qsw4q%2Fimage.png?alt=media&amp;token=d7204d42-6440-44da-a560-f852281198e1" alt=""><figcaption></figcaption></figure>

### **Lambda → Lambda Convert**

Due to volatility in the price of Pinto and non-Pinto assets in liquidity pools, the Pinto Denominated Value (PDV) of a Deposit can change over time. Lambda → Lambda Converts reevaluate the PDV of a Deposit to update its Stalk and Seeds.

There are technically two types of these Converts: Lambda → Lambda Converts and Anti Lambda → Lambda Converts. For simplicity, neither are explicitly available on the [pinto.money](https://pinto.money) UI.

Lambda → Lambda Converts allow a Depositor to update the PDV of her Deposit and combine multiple Deposits of the same asset into a single Deposit. Lambda → Lambda Converts never decrease the PDV of a Deposit, and they happen automatically when farmers claim Stalk.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FlegrshvNU6Fb3ToweYqD%2Fimage.png?alt=media&amp;token=4e36d1d3-29aa-4373-be2f-b18084277d5e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2F8DY8nKsozPZIj1JpoHOW%2Fimage.png?alt=media&amp;token=d4a18f26-8d66-460a-9a2f-83591fa5e5df" alt=""><figcaption></figcaption></figure>

Anti Lambda → Lambda Converts ensure maximum efficiency of the protocol by enabling anyone to eliminate a Deposit’s excess PDV. Anti Lambda → Lambda Converts remove the negative incentive that would otherwise prevent Depositors from Converting if it caused the PDV of their Deposit to be reevaluated lower. These Converts do not happen automatically. Instead, they exist as public functions at the protocol level that can be called permissionlessly by anyone on-chain at any time, instead of imposing excess computation on the protocol to regularly check and update the PDV of every Deposit.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FH7x8VfA2zINVsTQq6b4M%2Fimage.png?alt=media&amp;token=79903d2d-3684-4e77-b604-aedf515f2126" alt=""><figcaption></figcaption></figure>

### Why Might Someone Convert

There are a variety of incentives to Convert at any given time. Some of the incentives are created by the protocol while some naturally occur due to the nature of the system.

#### **Seeds**

Seeds yield more Stalk over time. The protocol changes the numbers of Seeds allocated to different Deposited assets each Season based on the current distribution of value Deposited in the Silo compared with the optimal distribution of liquidity.

Farmers are incentivized to Convert from one Deposited asset to another due to the difference in Seeds between the assets. By Converting, farmers can increase their Seeds to earn more Stalk over time, thereby increasing the portion of mints they receive when the protocol grows.

#### **Change Asset Exposure**

In addition to optimizing the number of Seeds, Converting allows a Depositor to change their exposure to various assets within the Silo.

Depositors holding LP tokens have Pinto exposure and exposure to a non-Pinto asset. Converting from LP to Pinto enables them to increase their Pinto exposure and decrease their exposure to the non-Pinto asset.

Conversely, Converting from Pinto to LP enables the Depositor to decrease their Pinto exposure.

Converting from LP to LP enables the Depositor to change their non-Pinto asset exposure depending on market conditions.

#### **Price (*****i.e.*****, Buy Low and Sell High)**

An individual Depositor Converting from LP to Pinto is effectively buying Pinto. Because LP → Pinto Converts are only allowed when the price of Pinto is below its value target, LP → Pinto Convertors are effectively buying Pinto when the price is low.

Similarly, an individual Depositor Converting from Pinto to LP, is effectively selling Pinto. Because Pinto → LP Converts are only allowed when the price of Pinto is above its value target, Pinto → LP Convertors are effectively selling Pinto when the price is high.

In short, Converts to and from Pinto allow Depositors to buy low and sell high, respectively, actively making money as they participate in protocol maintenance.

#### **Stalk Bonus (SOON)**

With the introduction of the Stalk Bonus, Pinto will start to offer a Stalk Bonus for performing Converts that improve the health of the protocol.

Once this system is live, an efficient Stalk maximization strategy will have to factor in the potential to earn a Stalk Bonus for Converting in addition to optimizing for the maximum number of Seeds.

### Why Might Someone Not Convert

#### **Waiting For Better Prices**

Given the ability to buy low and sell high, if a Depositor believes that the Pinto price is going to move further away from the value target, it may be in their interest to wait for a better price before they Convert.

#### **PDV Reevaluation**

At the time of a Convert, the PDV of the Deposit is reevaluated. In instances where the PDV of an LP Deposit has decreased since the last time the PDV was updated, the loss of Stalk and Seeds due to updating the PDV may discourage Depositors from Converting.

Anti Lambda → Lambda Converts were introduced to minimize the instances where PDV reevaluation is a disincentive for Depositors to Convert.

#### **Waiting For a Bigger Stalk Bonus (SOON)**

Similarly to how a Depositor might wait for better prices to Convert – or in the instance of the Field, wait for higher [Temperatures](/resources/glossary#temperature) to [Sow](/resources/glossary#sow) – Depositors may wait for a bigger Stalk Bonus to Convert.

#### **Stalk Penalty**

Certain Converts (*e.g.*, Pinto → LP if price < 1.005, LP → Pinto if price > 1) are discouraged by the protocol via a Stalk Penalty of 100% of Stalk accumulated from Seeds. Depositors may not Convert to avoid this penalty.

In instances where price > 1.005, the Stalk Penalty changes dynamically depending on how many Seasons the time-weighted average price has been above the value target. Similar to the Stalk Bonus, Depositors may wait to Convert for the penalty to decrease.

### **In Summary**

Pinto rarely intervenes in the market directly through forced sales – it shapes incentives to encourage participants to actively contribute to protocol maintenance. Converts are one of Pinto’s three core incentive mechanisms, allowing Depositors to shift between different assets within the Silo without changing overall liquidity, and rewarding participants for their contributions in the form of additional Stalk and Seeds.


# Optimizing Liquidity Distribution via the Seed Gauge System

In order to minimize the potential for manipulation and value extraction, Pinto does not directly control the value [Deposited](/resources/glossary#deposit) in the protocol. Instead, it creates incentives to encourage individual participants to collectively oscillate the Pinto price across the value target and align the distribution of Deposited value with the protocol's explicitly stated [optimal distribution](/resources/contracts#current-deposit-whitelist).

[Seeds](/resources/glossary#seeds) yield more [Stalk](/resources/glossary#stalk) every [Season](/resources/glossary#season) (*i.e.*, each hour). Stalk entitles Depositors to a portion of future Pinto [mints](/responding-to-state/minting) based on their pro rata ownership at the time of minting. By changing the distribution of Seeds among whitelisted assets in the Silo, Pinto incentivizes Depositors to change their exposure.

There are two dimensions over which the distribution of value within the Silo is evaluated: Pinto vs LP, and the distribution of LP tokens.

### **Pinto vs LP: The Crop Ratio**

The Crop Ratio is the ratio between the number of Seeds per Pinto and 1 Pinto Denominated Value (PDV) of the LP token on the Deposit Whitelist with the highest number of Seeds. The Crop Ratio enables the protocol to adjust the distribution of Seeds between Pinto and LP tokens Deposited in the Silo.

A Crop Ratio of 50% means the top LP (by number of Seeds) receives half as many Seeds per 1 PDV as 1 Pinto. At 100%, it receives the same number; at 200%, it receives twice as many, and so on.

By using the LP with the highest number of Seeds as a proxy for all LP tokens on the Deposit Whitelist, the protocol is able to directly control the attractiveness of holding Pinto vs any LP token. This enables the protocol to clearly incentivize Converts between Pinto and LP tokens.

When the protocol wants more [Converts](/resources/glossary#convert-1) from Pinto to LP, it increases the Crop Ratio. Conversely, when the protocol wants more Converts from LP to Pinto, it decreases the Crop Ratio. At the beginning of each Season, the protocol changes the Crop Ratio based on its desire to change the distribution of Deposits between Pinto and LP.

The protocol has parameters for a Minimum and a Maximum Crop Ratio. The current Minimum Crop Ratio is set to 50%, and the current Maximum Crop Ratio is set to 200%.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FOcPTyyl2favfZqqXaVQi%2Fimage.png?alt=media&amp;token=a59eff01-99b4-441a-b14b-94271d6540da" alt=""><figcaption></figcaption></figure>

Previously, the Maximum Crop Ratio was set to 100% such that the protocol never incentivized holding Pinto in the Silo more than all LP tokens. However, due to the overwhelming preference demonstrated by Depositors to hold LP tokens over Pinto, the Maximum Crop Ratio was changed to 150% and then 200%. A future upgrade to the protocol may remove this Maximum Crop Ratio altogether.

For specific information on how the protocol changes the Crop Ratio at the beginning of each Season, see the [Crop Ratio Changes](/responding-to-state/crop-ratio-changes).

### **LP Distribution: Seed Gauge Points**

Amongst LP tokens on the Deposit Whitelist, the distribution of Seeds in a given Season is proportional to the Seed Gauge Points allocated to each asset.

Seed Gauge Points are an internal protocol metric adjusted for each whitelisted asset at the beginning of each Season based on the actual distribution of LP tokens within the Silo compared with the optimal distribution. The further the actual distribution is from the optimal distribution, the more aggressively the Seed Gauge Points are changed. Anyone can see the [Pinto Dune](https://dune.com/pintomoney/pinto) to view the current vs. optimal LP allocations and distribution of Gauge Points.

If the Pinto denominated value (PDV) of an LP token as a portion of the total PDV of LP within the Silo is within 10% of its optimal distribution, its Seed Gauge Points remain constant. If it is more than 10% but less than 33% above (below) its optimal distribution, its Seed Gauge Points decrease (increase) by 1 point. If it is more than 33% but less than 67% above (below) its optimal distribution, its Seed Gauge Points decrease (increase) by 3. If it is more than 67% above (below) its optimal distribution, its Seed Gauge Points decrease (increase) by 5.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FPI3HzTOIDf5DjtqIp7WD%2Fimage.png?alt=media&amp;token=90bf93c2-3cc3-4b6a-9bb4-e58f93dfb28d" alt=""><figcaption></figcaption></figure>

By letting the number of Seed Gauge Points allocated to each LP token fluctuate freely, the protocol is able to respond flexibly to market conditions (*e.g.*, Depositors’ preferences with respect to LP token exposure, changes in the value of non-Pinto assets in the liquidity pools) to continuously incentivize the actual distribution of LP tokens in the Silo to approach the optimal distribution, which is ⅓ value in each of the three whitelisted pools.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FLcUz1PZmzGT0pw5mlzJ7%2Fimage.png?alt=media&amp;token=3a9f3713-0019-48dd-9bca-8d38c3c3d8fc" alt=""><figcaption></figcaption></figure>

### **The Seed Gauge, Step by Step**

At the beginning of each Season, the number of Seeds allocated to each asset on the Deposit Whitelist is recalculated. Pinto takes the following steps to calculate the appropriate number of Seeds for each asset.

First, the protocol sets the total number of Stalk for the Season. For more information on how the protocol calculates the total Seeds, see ["Time to Catch Up" in the Stalk System](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism#fair-to-new-participants) or the [Pinto whitepaper](https://pinto.money/pinto.pdf#page=11).

Next the protocol adjusts the Crop Ratio and Seed Gauge Points.

Finally the protocol calculates the Seeds for each asset in a given Season by solving a system of equations such that the Crop Ratio and Seed Gauge Points distribution, as well as the total number of Stalk are all honored.

Thus, the Seed Gauge dynamically adjusts the incentives to hold various Deposits in the Silo in response to the protocol's and participants' preferences.


# Dynamic Convert Bonus and Penalty System: Fine-Tuned Convert Incentives

[Converts](/resources/glossary#convert-1) are how Pinto is able to change its price without inflows or outflows from the protocol. Pinto never Converts on behalf of Depositors, but instead incentivizes (or disincentivizes) them to Convert (or not) to maximize their yield.

[Converts 'up'](https://docs.pinto.money/pinto-mechanics/silo-the-perfect-complement-to-credit/pages/bjU6ziPBuovGx2pfQ8Uw#lp-pinto-convert-i.e.-convert-up) increase the price of Pinto by removing Pinto from Deposited LP tokens and Converting them into Deposited Pinto. [Converts 'down'](https://docs.pinto.money/pinto-mechanics/silo-the-perfect-complement-to-credit/pages/bjU6ziPBuovGx2pfQ8Uw#pinto-lp-convert-i.e.-convert-down) decrease the price of Pinto by adding Deposited Pinto into liquidity pools, Converting them into Deposited LP tokens. For a more comprehensive overview of Converts, see ["Converts: Changing Price from Within”](/pinto-mechanics/silo-the-perfect-complement-to-credit/converts-changing-price-from-within).

Prior to the creation of the Dynamic Convert Bonus and Penalty System, the primary two protocol-native incentives to Convert were to maximize [Seeds](/resources/glossary#seeds) – which yield more [Stalk](/resources/glossary#stalk) over time – and one's Deposited value. Pinto uses the [Seed Gauge System](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/pinto-mechanics/silo-the-perfect-complement-to-credit/optimizing-liquidity-distribution-via-the-seed-gauge-system) to change the Seeds allocated to Deposited Pinto and the various Deposited LP tokens, thereby incentivizing Converts between Pinto and LP Tokens, and among LP tokens.

The Dynamic Convert Bonus and Penalty System offers additional Stalk as an instantaneous bonus for performing Converts the protocol wants, or imposes an instantaneous Stalk penalty in order to disincentivize Converts the protocol does not want. Only Stalk accumulated from Seeds is subject to the Convert Penalty. The Dynamic Convert Bonus and Penalty System is currently limited to Converts between Pinto and LP tokens. A future expansion could offer a bonus or impose a penalty for LP to LP Converts.

There are four elements to the Dynamic Convert Bonus and Penalty System:

* [Dynamic Convert Down Penalty](#dynamic-convert-down-penalty)
* [Dynamic Convert Up Bonus](#dynamic-convert-up-bonus)
* [Convert Up Penalty](#convert-up-penalty)
* [Convert Down Bonus](#convert-down-bonus)

Because farmers have demonstrated a preference to hold LP Deposits over Pinto Deposits (*i.e.*, a preference to Convert down), development of the Dynamic Convert Bonus and Penalty System has focused on the Dynamic Convert Down Penalty and Dynamic Convert Up Bonus. The Convert Up Penalty and Convert Down Bonus, on the other hand, have not yet been expanded beyond their initial static implementations.

### **Dynamic Convert Down Penalty**

Historically, the Dynamic Convert Down Penalty was 100% if the price was less than its value target of $1, meaning that the Converted Deposits lost 100% of Stalk accumulated from Seeds, and 0% if the price was greater than its value target. What typically occurred was that as soon as the price of Pinto exceeded $1, farmers would almost instantly Convert Pinto to LP, thereby lowering Pinto's price to the value target.

This had the effect of almost always preventing mints following a value target cross. On the one hand, this behavior preserved liquidity quite aggressively by minimizing mints (and therefore sell pressure) unless there was significant new demand for Pinto. On the other hand, this minimized mints so much that it had been exceedingly difficult for the protocol to grow its way out of a debt cycle. Particularly during these early stages of the protocol, it is likely that some growth, even in the absence of significant new demand, is healthy for the protocol.

Accordingly, two dynamic elements have been added to the Dynamic Convert Down Penalty. First, the Dynamic Convert Down Penalty is now 100% if (1) the price is below a threshold called the "Penalty Price," which is currently set to 1.005 and (2) there has been an insufficient number of Pinto minted to start decreasing the penalty. The number of Pinto that must be minted in order for the penalty to decrease is a function of the longest period of time the protocol has spent below its value target since the last time there was a sufficient number of mints to decrease the penalty.

Once either the Penalty Price threshold or the threshold for the number of mints required to decrease the penalty has been exceeded, the protocol starts to decrease the penalty until the protocol logs a Season in which the time-weighted average price (TWAP) is below the value target by increasing a metric called the Blight Factor.

The Blight Factor is designed to find the penalty at which there is sufficiently low friction for Converts down to bring the price to its value target such that the protocol logs a Season with the TWAP < 1, and then oscillate the penalty across that value such that the TWAP oscillates across the value target every other Season. The Blight Factor ranges from 0 to 12, where 0 corresponds to a 100% penalty and 12 corresponds to a 0% penalty. When active, the Blight Factor is increased (decreased) by 1 each Season that the TWAP > 1 (< 1).

The Dynamic Convert Down Penalty is a function of the Blight Factor and the [Liquidity to Supply Ratio (L2SR)](/resources/glossary#liquidity-to-supply-ratio-l2sr). The Dynamic Convert Down Penalty decays exponentially as the Blight Factor increases, and is scaled down linearly as the L2SR decreases from its Excessively Low threshold to 0.

To minimize excessive minting as a result of the disincentive to Convert created by the Dynamic Convert Down Penalty, if the price is above the [Excessively High Price threshold](/responding-to-state/classifying-state#decentralized-price-oracle), the penalty decreases to 0%. If a Convert down causes the price to cross below the Excessively High Price threshold, the penalty is applied to the Pinto Denominated Value (PDV) that was Converted below the threshold.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2F7VRg5D3QdPDyV8GRIEyQ%2Fimage.png?alt=media&amp;token=a89376e3-f455-4ed4-a444-e9ad839bcd24" alt=""><figcaption></figcaption></figure>

Because newer Deposits have less Stalk, the Dynamic Convert Down Penalty affects newer Deposits less, and does not affect newly minted Deposits at all. Therefore, in practice, newly minted Pinto can still be Converted down free of penalty.

### **Dynamic Convert Up Bonus**

The upcoming Dynamic Convert Up Bonus follows a similar structure as the [Temperature](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/classifying-state/temperature) and [Cultivation](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance) Systems in the Field.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FmAHd6dbqMP0COXwwlkUr%2Fimage.png?alt=media&amp;token=e85d50fc-abcb-484c-aa1b-78b11822d8a3" alt=""><figcaption></figcaption></figure>

Similarly to how the Maximum Temperature responds to the state of the protocol and the change in demand for [Soil](/resources/glossary#soil) over the previous two [Seasons](/resources/glossary#season), the Convert Bonus per PDV changes in response to the state of the protocol and the change in demand for Converts over the previous two Seasons.

Similarly to how the number of Soil starts small and ramps up to meet demand once discovered at a given Maximum Temperature, the number of Pinto denominated value (PDV) able to receive a Convert Bonus during any given Season starts small and ramps up to meet demand once discovered at a given Convert Bonus per PDV.

Similarly to how the [Cultivation Temperature](/resources/glossary#cultivation-temperature) is used to prevent the circumstance where the protocol gets “stuck” with the [Cultivation Factor](/resources/glossary#cultivation-factor) going up and the Maximum Temperature going down one Season, followed by the Cultivation Factor going down and the Maximum Temperature going up the subsequent Season – in a loop – such that the actual demand for Soil at a given Temperature cannot be matched, the Dynamic Convert Up Bonus per PDV High Mark is logged and used as a reference when changing the Convert Bonus Factor.

When the time weighted average delta Pinto over a Season is positive, the Convert Bonus per PDV resets to 0. This creates an incentive to Convert Up as soon as the Convert Bonus per PDV is high enough for a farmer to Convert.

For a more thorough understanding of the Dynamic Convert Up Bonus mechanism, consult [“The Cultivation System: Optimal Soil Issuance”](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance) and then refer to the diagram above to compare the two systems. For the sake of brevity, the entire explanation of the system has been omitted from this document.

### **Convert Up Penalty**

There is a 100% Stalk Penalty for Converting Up if the price of Pinto is above its value target, and a 0% Stalk Penalty for Converting Up if the price of Pinto is below its value target.

### **Convert Down Bonus**

There is currently no Stalk Bonus for Converting Down under any circumstance.

### **In Summary**

Converts have the power to adjust the price of Pinto by adding and removing Pinto to and from liquidity pools without inflows or outflows from the protocol. The Dynamic Convert Bonus and Penalty System enables the protocol to fine-tune the incentives for farmers to oscillate the Pinto price across its $1 value target.

The Dynamic Convert Down Penalty decreases exponentially as Pinto spends more time above its value target, and decreases linearly as the L2SR decreases. The Dynamic Convert Up Bonus follows a similar mechanism to the Field’s Temperature and Cultivation Systems to find the minimum Bonus per PDV Converted at which the market is willing to Convert, and dynamically scale the PDV of Converts that are eligible for a bonus to meet demand. There is either a 100% Stalk Penalty or 0% Stalk Penalty for Converting Up depending on whether the Pinto price is above or below its value target. There is no Stalk Bonus for Converting Down.


# The Flood: Biblical Returns to Prevent Pump and Dumps

*This document provides a deep dive into the Flood's design and mechanics. For a concise specification, see* [*Flood*](/responding-to-state/flood)*.*

As an open source and deterministic protocol, Pinto avoids performing any open market operations (*e.g.*, buying and selling) in order to minimize the potential for value to be extracted from it. Instead, it creates incentives to encourage individual participants to take actions that align with the preferences of the protocol. However, there is one exception to this rule: the Flood.

Like all algorithmic stablecoins, Pinto is highly reflexive. When the protocol is growing, the yield generated by the mints that are intended to decrease the price have the potential to attract more participants, which in turn creates more yield, which attracts more participants, etc. This positive feedback loop can be highly advantageous to the protocol, particularly in instances where it is paying off large amounts of outstanding debt. When it does so, the protocol can radically improve its health and demonstrate creditworthiness that can serve to create long term sustainability.

However, when the protocol does not have much outstanding debt, sustaining an aggressive positive feedback loop can actually cause the protocol more harm than good. In most cases, rapid growth will almost always be followed by a sharp contraction in demand. This results from the fact that a significant portion of the demand for Pinto during the positive feedback loop is likely short term oriented yield farmers who are indifferent to the protocol and its long term success (*i.e.*, inorganic demand). When the printing stops, that capital swiftly leaves. The larger the positive feedback loop, the larger the contraction.

The problem leading to excessive positive feedback loops is that there is minimal incentive to sell Pinto when the protocol is growing significantly. Therefore, Pinto requires a mechanism to stun momentum once the protocol has sufficiently deleveraged and flush out inorganic demand.

The Flood is designed to reward long term holders that were [Deposited](/resources/glossary#deposit) in the Silo before the pump started, and dampen the benefit for short term yield farmers that exacerbate the pump – and therefore the ensuing dump. Throughout [Beanstalk](https://bean.money) and Pinto’s histories, particularly during their early days, the Flood has been crucial to maintain value in the systems.

### **Flood Dynamics**

During a Flood, in addition to the normal Pinto printed as a function of the time-weighted average delta of Pinto across [whitelisted liquidity pools](/resources/glossary#deposit-whitelist) (which don't guarantee Pinto is sold and its price is lowered), the protocol mints additional Pinto and sells them directly on the open market, bringing the price of Pinto back to its value target and effectively resetting the positive feedback loop. The proceeds from the sale of Pinto are distributed to [Stalk](/resources/glossary#stalk) holders. Additionally, up to 0.1% of the total supply of Pinto worth of [Pods](/resources/glossary#pods) become [Harvestable](/resources/glossary#harvestable-pods), flooding the market with additional potential sell pressure. This extra minting and dumping of Pinto by the protocol occurs every [Season](/resources/glossary#season) until the time weighted average delta Pinto over the course of a Season is negative, thereby ending the Flood.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FhwnPaSOg2jedd9yGKKkQ%2Fimage.png?alt=media&amp;token=20d0fa81-f79b-48af-8894-01a4d9b40305" alt=""><figcaption></figcaption></figure>

A Flood creates two conditions that make it unattractive for new Deposits to enter the system unless they are long term oriented.

1. The proceeds from the Flood are distributed to Depositors who entered *before* it started to [Rain](/resources/glossary#rain), so newer Deposits only earn yield from the normal inflation resulting from the time weighted average shortage of Pinto in the pools. Therefore, until the Flood ends, the yield received by newer Deposits is significantly less than the yield earned by older Deposits.
2. Because the protocol dumps Pinto and distributes the proceeds to older Deposits, Deposits during a Flood essentially pay a hefty entry tax to older Deposits.

The attentive reader may be wondering why all yield during a flood doesn’t get distributed to the older Deposits. Such a rule would entirely eliminate demand for Pinto during a Flood, instead of limiting the demand to long term oriented Depositors.

### **To Flood Or Not To Flood**

Depositors don’t indicate whether they are here for the long term or not when they Deposit. Moreover, just because some Depositors are merely hunting yield, it may still be preferable for the system to grow and decrease its debt level to demonstrate creditworthiness.

As a credit based system, the debt level of the protocol is the primary indicator of its health. The question is how Pinto can identify when it is healthier to let the protocol grow according to its normal peg maintenance mechanism, and when it should intervene to slow down growth.

The primary determinant Pinto uses to gauge how aggressively it wants to grow is the Pod Rate – the debt to supply ratio of the protocol. When the [debt level is excessively low](/responding-to-state/classifying-state#debt-level) and the time weighted average price is over its value target, it starts to Rain. If it Rains for more than one consecutive Season, it starts to Flood. At any debt level higher than the excessively low threshold, the protocol would rather grow and pay down its debt than to Flood and stop the growth. But below this threshold, the protocol Floods.

### **Why Redistribute the Proceeds?**

A question that is often asked about the Flood is why the protocol distributes the proceeds of non-Pinto assets from the sale of Pinto instead of holding onto the assets. The answer is simple: the value of Pinto derives from the [creditworthiness of the protocol, not collateral](/why-pinto/credit-vs-collateral). If the protocol started to accumulate holdings of non-Pinto, it would effectively be a partial collateralization of the currency, thereby compromising the integrity of its value proposition. It is worth noting that becoming partially collateralized was one of the fatal mistakes made by Terra/Luna, which blew up shortly after its reserve was created.

### **In Summary**

The Flood has successfully been used by the protocol to minimize inorganic demand for Pinto during periods where the debt level is excessively low. During a Flood, the protocol mints additional Pinto, sells it on the open market to bring the price back to its value target and distributes the proceeds from the sale to Deposits that were already in the Silo before it started to Rain. Extra Pods also Harvest during a Flood. Thus, Pinto is able to cool itself off when it is at risk of overheating and create the conditions for slower, steadier, and healthier forms of growth.


# Field: The Most Innovative Lending Facility In Crypto

The Pinto credit facility

*This document provides a high-level intuition for the Field and its design. For a basic explanation of key terms, see* [*The Field (Simply Put)*](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-field-simply-put)*.*

### Creating a Competition to Lend to Pinto

One of the two primary problems that an algorithmic stablecoin must solve is how to reduce supply in an efficient fashion without compromising the utility of the currency (*e.g.*, through rebasing).

Every time the price of the stablecoin is too low, there is excess supply on the market. The protocol needs a way to remove supply from the market in order to return the price to its value target.

Pinto uses the Field – its protocol-native credit facility – to efficiently attract lenders and reduce supply.

Pinto must offer an interest rate high enough that a prospective lender views it in her interest to lend to the protocol and is incentivized to lend immediately rather than wait for a higher interest rate.

There are two key components to incentivizing a prospective lender to do so: the first is to create risk for waiting, and the second is to minimize the benefit of waiting.

The first component is achieved through the introduction of a novel debt structure: Pods. Pods become redeemable for Pinto 1:1 when Pinto issues new supply in response to excess demand (*i.e.*, the price being too high) on a first in, first out (FIFO) basis.

The FIFO structure introduces risk for potential lenders who wait to lend to the protocol because others may do so first, getting in line and thereby increasing the supply growth needed for the later lender to be paid back.

Even if the interest rate for lending to the protocol may increase in the future, offering a better return on an absolute basis, if the risk due to the potential increase in the number of Pods that must become redeemable before their loan will be paid back is greater than the potential benefit of a higher interest rate, lenders are incentivized to lend to the protocol.

### The Field Process

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FghVYOVVAxvxG4RqGrrws%2Fimage.png?alt=media&amp;token=30ab98b7-2c1f-424e-8cf3-bf3182652005" alt=""><figcaption></figcaption></figure>

1. Pinto are Sown (lent) in exchange for Pods.
2. Pods become Harvestable Pods (redeemable for Pinto) on a FIFO basis when the protocol mints new Pinto according to the target maintenance mechanism.
3. Harvestable Pods can be Harvested (redeemed) into Pinto.

### **Setting the Interest Rate Properly**

The second component to properly incentivizing lending to the protocol is to minimize the marginal benefit of waiting to lend to the protocol.

Pinto needs a way to efficiently find the minimum interest rate at which it can attract lenders. On the one hand, the protocol wants to attract lenders in a timely fashion, so it is incentivized to raise the interest rate quickly to discover demand.

However, the faster the protocol raises the interest rate, the higher the benefit each potential lender receives for waiting to lend to the protocol. Counterintuitively, raising the interest rate too quickly actually delays lender participation and results in worse loan terms for the protocol.

Therefore, the efficient way for the protocol to raise the interest rate during periods of time in which the protocol struggles to attract lenders is to do so slowly and steadily. Generally, the protocol would rather experience longer periods of time below its value target in order to pay a lower interest rate to its lenders – and therefore more sustainably borrow from the market – than to rapidly raise the interest rate in a misguided attempt to quickly attract lenders.

### **Fine-Tuning the Field: Efficient Borrowing in Practice**

The Field includes three mechanisms to optimize its lending: autonomous interest rate adjustments, dynamic debt issuance to minimize instances where the protocol offers more debt than there is demand for and an auction to minimize the interest rates paid by the protocol to borrow.

At the beginning of each Season (\~1 hour) Pinto [changes the Maximum Temperature](/responding-to-state/temperature-changes), the maximum interest rate it is willing to offer lenders during that [Season](/resources/glossary#season). The Maximum Temperature is a function of the [current state](/responding-to-state/classifying-state) of the protocol (*i.e.*, price, debt level and liquidity level) and the change in demand for debt over the previous two Seasons.

Soil represents the number of Pinto the protocol is willing to borrow in exchange for Pods at any given time. If the protocol offers more Soil than there is demand for, the market may perceive the protocol as less creditworthy. The protocol uses the [Cultivation System](/resources/glossary#cultivation-system) to keep the number of Soil available to a minimum until there is demand for it, at which point the protocol ramps up the supply of Soil to match demand.

The first 10 minutes of each Season is called the Morning Auction, during which the Temperature – the interest rate the protocol is currently willing to offer to lenders – ramps up from 1% of the Maximum Temperature to the Maximum Temperature logarithmically. This ensures the protocol minimizes the interest rate it pays every Season.

The combination of these three mechanisms with the FIFO structure of Pods enables the Field to operate in a highly efficient manner.

*For a deeper dive into the Cultivation System, read more* [*here*](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance)*.*

### Economics

Pinto is credit based and only fails if it can no longer attract creditors. A reasonable level of debt, a strong credit history and a competitive interest rate attract creditors.

Pinto never defaults on debt (although in the event of Pinto no longer attracting creditors, the loan maturity date would become infinitely far in the future – see [Disclosures](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/18/appendix/disclosures)). The protocol is willing to issue Pods every Season.

### **In Summary**

Pinto's Field combines a novel debt structure with three distinct mechanisms to create a competition between lenders to efficiently reduce supply without undermining the currency’s utility. Pods, redeemable on a FIFO basis, introduce risk to waiting and incentivize lenders to act immediately. The protocol raises interest rates slowly and steadily in response to the state of the system and changes in demand for Soil, minimizing the benefit of waiting and allowing the protocol to discover the lowest sustainable rate at which lenders will participate. The protocol dynamically ramps up the available supply of Soil to match demand, minimizing instances where it offers Soil in excess of demand for it, and conducts an auction every Season to minimize its cost to attract lenders. Together, these features ensure supply is reduced in the maximally sustainable fashion.

*Go on to the next documents to refresh on the Field's key terms and then read more about the Cultivation System, or* [*jump ahead to read about the Sun*](/pinto-mechanics/sun-the-source-of-life-on-the-farm)*.*


# The Field (Simply Put)

*This document provides a basic explanation of the Field and its key terms. For a deeper dive, read* [*The Field: The Most Innovative Lending Facility in Crypto*](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto)*.*

### Field

The Pinto credit facility.

The Pinto target maintenance mechanism requires a way to decrease the supply of Pinto when the price is too low. The protocol uses credit to borrow Pinto and burn them, thereby removing them from the supply.

The Field is a permissionless market for lending Pinto to the protocol. Anytime there is Soil in the Field, anyone can lend Pinto to the protocol (*i.e.*, Sow) in exchange for Pods, the protocol-native debt asset.

The [Temperature](#temperature) at the time Pinto was Sown determines the number of Pods received. Pods become Harvestable (redeemable) for 1 Pinto each on a FIFO basis.

The protocol conducts a Dutch auction for Pods during the first 10 minutes of each Season (*i.e.*, the Morning). The Soil and Temperature change throughout the Morning according to the [target maintenance mechanism](/pinto-mechanics/mechanics-overview).

### **Soil** <a href="#soil" id="soil"></a>

Anytime the protocol is willing to issue debt, there is Soil available in the Field. Soil represents the number of Pinto that the protocol is currently willing to borrow.

When Pinto are Sown, the protocol burns them, permanently removing the Sown Pinto from the Pinto supply. For example, if there's 10 Soil available and 10 Pinto are Sown, the Soil supply becomes 0 and 10 Pinto are removed from the Pinto supply. If the market is in some sort of equilibrium, Pinto are bought to be Sown, which drives the Pinto price upward towards its value target.

When TWA∆P (the sum of the time weighted average shortages or excesses of Pinto across liquidity pools on the [Minting Whitelist](/responding-to-state/minting#current-minting-whitelist)) ≥ 0, the Soil supply decreases logarithmically during the Morning and is a function of the [Maximum Temperature](https://docs.pinto.money/target-maintenance/temperature). When TWA∆P < 0, the Soil supply is set by the Cultivation System. For more information about the Cultivation System, see [The Cultivation System: Optimal Soil Issuance](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance).

### **Pods** <a href="#pods" id="pods"></a>

Pinto are Sown (lent) in exchange for Pods, the protocol-native debt asset. Loans are issued with a fixed interest rate, known as Temperature, and an unknown maturity date.

The number of Pods received from 1 Sown Pinto is determined by the Temperature at the time of Sowing. Newly issued Pods accumulate in the back of the Pod Line. The front of the Pod Line receives a portion of Pinto mints as outlined in [Shipping Routes](https://docs.pinto.money/farm/sun#shipping-routes).

Pods become Harvestable Pods that can be Harvested (redeemed) for 1 Pinto each on a First In, First Out ([FIFO](https://docs.pinto.money/resources/glossary#fifo)) basis. There is no penalty for waiting to Harvest Pods.

Pods are tradeable on the [Pod Market](https://docs.pinto.money/farm/toolshed/pod-market). Pods can also be transferred to another address directly.

### **Temperature** <a href="#temperature" id="temperature"></a>

The Temperature is the interest rate for Sowing Pinto in the Field. At 500% Temperature, 1 Pinto can be Sown in exchange for 6 Pods. Once those Pods become Harvestable, they can be Harvested in exchange for 6 Pinto.

The protocol [changes the Maximum Temperature](https://docs.pinto.money/target-maintenance/temperature) it is willing to offer each Season at the beginning of each Season according to the target maintenance mechanism.

[During the Morning](https://docs.pinto.money/target-maintenance/temperature#morning) of each Season, the Temperature is the result of a Dutch auction, where the Temperature increases logarithmically from 1% of the Maximum Temperature to the Maximum Temperature over the course of 10 minutes. During times of short-term excess demand for Soil, the Morning results in the protocol paying significantly less to attract creditors.


# The Cultivation System: Optimal Soil Issuance

**This document assumes familiarity with the Field and associated terms. For an introduction, see** [**The Field: The Most Innovative Lending Facility In Crypto**](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto)**.**

One of the most difficult problems in the history of credit based algorithmic stablecoins has been determining how much debt the protocol should be willing to issue given the circumstances.

Offering in excess of what the market demands sends a negative signal that the protocol is not being viewed as creditworthy. Offering less than the protocol wants to borrow and there is demand for means the protocol is not borrowing from the market efficiently. Pinto’s response to this dilemma is to start small and ramp up the number of [Soil](/resources/glossary#soil) available to meet demand.

This document is intended to provide a high level intuition for Soil issuance rather than a detailed explanation of how it functions in practice. For such a description, see the [Pinto whitepaper](https://pinto.money/pinto.pdf#page=23).

### **Elements of the Cultivation System**

The Cultivation System determines Soil issuance every [Season](/resources/glossary#season) relative to the maximum number of Soil the protocol would be willing to issue given its current state and infinite demand for Soil. It has three elements: the Cultivation Factor, the Cultivation Temperature, and two manipulation resistant thresholds to determine whether Soil sold out or almost Sold out in the previous Season.

The Cultivation Factor is a scalar from 0.01 to 1 that determines the number of Soil the protocol is willing to issue, where 1 means the protocol issues the maximum Soil.

The Cultivation Temperature is the [Maximum Temperature](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-field-simply-put#temperature) from the last Season in which Soil either sold out entirely or almost sold out and [demand for Soil](/responding-to-state/classifying-state#demand-for-soil) was steady or increasing. It is used to prevent instances where the protocol gets stuck oscillating the Maximum Temperature downward and the Cultivation Factor upward, and the Maximum Temperature upward and the Cultivation Factor downward.

### **The Cultivation System In Action**

The simplest way to understand the Cultivation System is to observe how it ramps up Soil issuance to meet newfound demand after a period of zero demand for Soil. Prior to the discovery of new demand for Soil, the Cultivation System is at rest: the Cultivation Factor will remain at 0.01, such that there is a very small number of Soil available, the Maximum Temperature will rise each Season in an attempt to find new demand at higher interest rates, and the Cultivation Temperature is irrelevant. Once the interest rate at which demand for Soil is discovered, the Cultivation System kicks in, ramping up Soil issuance to meet the demand and setting a new Cultivation Temperature to prevent the erroneous oscillation mentioned above.

This chart gives a step by step flow of the logic of the Cultivation System in action. The rest of the document will explain the reasoning behind each step in the process.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FxaYxvX484lWLej5wABVv%2Fimage.png?alt=media&amp;token=c2154579-e242-421e-9c56-f6cfd037369b" alt=""><figcaption></figcaption></figure>

Step 1: Did Soil ‘Sell Out’?

Once the demand for Soil exceeds the threshold that determines it was sold out, the Cultivation Factor increases and the Cultivation Temperature is set at the current Maximum Temperature unless demand for Soil is decreasing. The reason to increase the Cultivation Factor is simple: given that the protocol is trying to borrow, if Soil sold out, the protocol should offer more the following Season.

Note: the mechanism that adjusts the Maximum Temperature each Season is independent from the Cultivation System but typically decreases (and never increases) it in the instance where Soil sold out.

Step 2: If Soil Did Not ‘Sell Out’, Did It ‘Mostly Sell Out’?

If the number of Soil sold exceeds the 'mostly sold out' threshold, but does not exceed the ‘sold out’ threshold, the number of Soil available was very close to demand. Lowering the Cultivation Factor in this instance would likely result in a Soil supply lower than demand. Therefore, the Cultivation Factor is kept constant.

The Cultivation Temperature is set to the current Maximum Temperature unless demand for Soil is decreasing.

Step 3: If Soil Did Not ‘Sell Out’ Or ‘Mostly Sell Out’, Was Demand For Soil Increasing, Steady or Decreasing?

If Soil neither ‘sold out’ nor 'mostly sold out', there was excess Soil available relative to demand. If the demand for Soil is increasing or steady compared with the prior Season but still not meeting the threshold for being mostly sold out, the protocol can decrease the Cultivation Factor so there is less Soil available the next Season without offering too little Soil to meet demand. This minimizes instances where there is demand for Soil but the protocol offers more than the market is willing to purchase.

This step handles the case where a new [Tractor](/pinto-mechanics/toolshed/tractor-automating-the-farm) order enters the market with a lower maximum demand for Soil per Season than the 'mostly sold out' threshold at a lower Temperature than the Cultivation Temperature. In this instance, the protocol should lower the Cultivation Factor to scale supply of Soil down to match the demand at the lower Temperature.

Step 4: Is the Current Maximum Temperature Lower Than the Cultivation Temperature?

If Soil neither ‘sold out’ nor 'mostly sold out' and demand for Soil is decreasing, that means that the protocol is offering too much Soil and should consider decreasing the Cultivation Factor. However, before it does so, the protocol checks whether the current Maximum Temperature is less than the Cultivation Temperature. This check prevents the case where there is demand for Soil at a given Temperature, but because the demand for Soil increased over the prior two Seasons, the Maximum Temperature decreased such that the demand for Soil in the Tractor order was not met.

In this instance, the protocol would effectively get “stuck” with the Cultivation Factor going up and the Temperature going down in one Season, thus logging decreasing demand, and causing the Cultivation Factor to go down and the Temperature to go up in the following Season, leading to excess demand. In this case the Cultivation Factor would never increase to match demand for Soil, resulting in the protocol perpetually under-issuing Soil.

### **In Summary**

The Cultivation System is one of the most complex components of Pinto, refining the Field to closely match Soil issuance with demand, thereby minimizing instances where Soil supply is significantly greater than demand and maximizing Pinto's creditworthiness. Pinto uses the Cultivation Factor to ramp up the Soil supply, and the Cultivation Temperature to track the most recent Maximum Temperature when Soil last sold out or almost sold out and demand was not decreasing, preventing the protocol from getting stuck in a state where it issues less Soil than there is demand for.

FAQ: Why does the Cultivation Temperature get set if the Soil 'sold out' or 'mostly sold out' AND demand for Soil is steady or increasing, and not just if Soil 'sold out' or 'mostly sold out'?

The protocol could safely set the Cultivation Temperature by merely checking whether Soil ‘sold out’ or ‘mostly sold out’. However, there is an edge case where there is potential for slight manipulation where someone could cause demand for Soil to decrease even if Soil ‘mostly sold out’ such that the Maximum Temperature, and therefore Cultivation Temperature would increase, which means that the protocol may keep the Cultivation Factor higher for slightly longer. By checking whether demand for Soil is increasing or steady before setting the Cultivation Factor at the current Maximum Temperature, the protocol is slightly more prudent with its Soil issuance.


# Sun: The Source of Life on the Farm

The Pinto timekeeping mechanism.

The Sun is the native timekeeping mechanism fueling Pinto’s autonomous adjustments, giving order and life to the protocol. The protocol requires a way to automatically trigger and pay for protocol adjustments. The Sun handles both of these requirements.&#x20;

### **Timekeeping**

Time in the Pinto protocol is measured in Seasons. Every Season lasts \~1 hour. Pinto uses Base blocks as a proxy for time. Due to the consistent time between Base blocks, the protocol can accurately calculate the time based on the Base block number. Once the Base block number has eclipsed the threshold indicating the passage of the top of the next hour, anyone can call the `gm()` function to trigger the Sunrise that begins the next Season.

The first Season began when Pinto was deployed on November 19, 2024 at 17:00 UTC.

### **Incentivizing The Sunrise**

In order to incentivize the `gm()` function call while minimizing the cost to the protocol for each Sunrise, the protocol offers a reward in the form of newly minted Pinto for successfully triggering the Sunrise. The award starts at 1 Pinto and increases by 1.0201% for each successive block beyond the threshold that elapses without a successful `gm()` call, ensuring that the protocol pays as little as possible without the Sunrise occurring more than a short period of time after the top of each hour.

### **Changes to the Protocol**

Upon each Sunrise, the protocol:

1. Increments the Season counter;
2. Calculates TWA∆P, the sum of the time weighted average shortages or excesses of Pinto across liquidity pools on the [Minting Whitelist](/responding-to-state/minting#current-minting-whitelist);
3. Updates the [Maximum Temperature](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto#fine-tuning-the-field-efficient-borrowing-in-practice);
4. Updates the [Crop Ratio](/responding-to-state/crop-ratio-changes);
5. Updates the [Gauge Points](/pinto-mechanics/silo-the-perfect-complement-to-credit/optimizing-liquidity-distribution-via-the-seed-gauge-system#lp-distribution-seed-gauge-points);
6. Updates the [Silo](/pinto-mechanics/silo-the-perfect-complement-to-credit) to issue Stalk that grows from Seeds;
7. Starts or stops the [Rain](/resources/glossary#rain), if applicable;
8. Starts or stops the [Flood](/responding-to-state/flood), if applicable;
9. Sets the supply of [available Soil](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-field-simply-put#soil);
10. Mints Pinto based on TWA∆P to the appropriate [Shipping Routes](/responding-to-state/minting#shipping-routes); and
11. Awards Pinto to the address that successfully called the `gm()` function.

The Sun powers the constant dynamism of Pinto, enabling the protocol to autonomously respond to market conditions quickly and cheaply.


# Toolshed

The Toolshed offers a suite of permissionless tools for Farmers to efficiently use Pinto and other protocols on Base. Nothing in the Toolshed is directly related to protocol maintenance.

[sPinto](/pinto-mechanics/toolshed/spinto-composing-pinto-with-defi) is the fungible ERC-20 wrapper for Pinto Deposits, which adhere to the ERC-1155 semi-fungible standard. sPinto is designed to make integrating the Pinto printer into DeFi seamless.

[Tractor](/pinto-mechanics/toolshed/tractor-automating-the-farm) is an intents protocol that enables farmers to efficiently farm Pinto without constant manual activity.

The [Pod Market](/pinto-mechanics/toolshed/pod-market) is a secondary market for Pods, Pinto’s native debt asset.

The [Depot](/pinto-mechanics/toolshed/depot) is a protocol for composing complex interactions across multiple protocols on Base in a single transaction.

[Farm Balances](/pinto-mechanics/toolshed/farm-balances) enable farmers to hold assets not currently Deposited in the Silo in their account within the protocol.\
\
*Go on to the next documents to learn more about the Toolshed, or* [*jump ahead to read about the Field.*](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto)


# sPinto: Composing Pinto with DeFi

The [Pinto printer](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/why-pinto/pinto-prints-for-the-people) has the potential to be one of the most powerful forces in crypto. However, there is a major friction point to connect the printer with the rest of DeFi: [Silo Deposits](/resources/glossary#deposit) are not fungible.

Due to the need for the protocol to minimize bank runs, the [Stalk System](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/pinto-mechanics/silo-the-perfect-complement-to-credit/the-stalk-system-defis-first-bank-run-minimization-mechanism) introduces the element of time to index Deposits, which necessitates its use of the ERC-1155 semi-fungible token standard. In other words, Deposits are treated differently based on the time since they were Deposited in the Silo.

However, DeFi protocols currently run almost exclusively on the ERC-20 fungible token standard and rarely support ERC-1155 tokens. Therefore, holders of Pinto were unable to earn prints while using Pinto in other DeFi protocols, limiting the utility of Pinto.

### **Enter sPINTO**

sPinto is a permissionless yield-bearing version of Pinto that wraps ERC-1155 Pinto Deposits in an ERC-20 fungible token, thereby enabling the composition of the Pinto printer with DeFi.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2Fm0s6lbITl0ORgsrwKQQa%2Fimage.png?alt=media&amp;token=d26e47c0-e9a8-46d0-97d6-d25c4f5f1f9b" alt=""><figcaption></figcaption></figure>

Any holder of Pinto Deposits can Wrap their Pinto into sPinto. The number of sPinto received upon Wrapping is proportional to the increase in Deposited Pinto in the sPinto contract resulting from the Wrap.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FlkZUfkINftxTfnZoxraB%2Fimage.png?alt=media&amp;token=a4bf47e7-7ac8-4329-93a4-7c3982787456" alt=""><figcaption></figcaption></figure>

Any holder of sPinto can Unwrap their sPinto into Pinto Deposits. Unwraps receive the Deposits with the lowest amount of Stalk held by the sPinto contract at the time of Unwrap.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FnWGJfV1n6ZdMU71Or5xv%2Fimage.png?alt=media&amp;token=49a5e878-964b-4939-b233-4923525e8cd6" alt=""><figcaption></figcaption></figure>

sPinto is non-rebasing, meaning that when Pinto prints, the number of sPinto holders own remains constant, but the number of Pinto the sPinto can be Unwrapped for increases.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FS3ijDNVHVKvxSpBzch4d%2Fimage.png?alt=media&amp;token=c60a7eb0-09da-4d44-b029-e6f58b34b790" alt=""><figcaption></figcaption></figure>

### **Lessoned Learned From Root**

Because Deposits have different numbers of [Stalk](/resources/glossary#stalk) per Pinto Denominated Value (PDV), the system needs a method to create fungibility upon Wrapping, and determine how much Stalk per PDV to distribute upon Unwrapping. If a Depositor Wraps Deposits with less Stalk per PDV than the contract has on its Deposits, either the contract has to give them a fungible asset with less PDV or more Stalk per PDV than that of the Deposits they just added.

Upon Wrapping in Root, the ERC-20 Wrapper of Beans in the [Beanstalk](https://bean.money) ecosystem, if the ratio of Stalk per PDV (formerly BDV) on the [Deposits](/resources/glossary#deposit) Wrapped is less than the ratio of Stalk per PDV of Deposits in the Root contract, Root haircuts the number of Root which Depositors receive.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2Fae7d6bpSlxZeYOFB1ypC%2Fimage.png?alt=media&amp;token=66b64ae0-e6b4-4721-9708-8d480750dde8" alt=""><figcaption></figcaption></figure>

Upon Unwrapping, Root allows holders to receive Deposits with Stalk that have up to the average Stalk per PDV in the contract at the time of Unwrapping. In practice, this creates a tremendous disincentive for newly Deposited value to be Wrapped into Root because it effectively confiscates some portion of the value immediately upon Wrapping.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2Fxvuqn3L33DPHRSP1HiCi%2Fimage.png?alt=media&amp;token=a6495ad6-a461-48a6-9dbb-3013f9987c75" alt=""><figcaption></figcaption></figure>

To put all Wrapped Deposits into the same fungible token without a haircut of PDV on value Wrapped with less Stalk per PDV than the contract has, sPinto awards such assets with a Stalk bonus instead. To prevent Stalk theft, sPinto distributes the Deposits with the lowest Stalk per PDV at the time of Unwrapping. In the instance where someone is leaving the system entirely, they will not care about the lower amount of Stalk. The combination of a Stalk bonus to Wrap newer Deposits and a small friction to Unwrap makes sPinto attractive to use and sticky, marking a significant improvement over the Root model.

### **sPinto x Flood**

A [Flood](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/1/pinto-mechanics/silo-the-perfect-complement-to-credit/the-flood-biblical-returns-to-prevent-pump-and-dumps) distributes non-Pinto rewards to Deposits based on their Stalk. Because the sPinto contract cannot attribute different rewards to different sPinto without breaking its fungibility, when a [Flood](/resources/glossary#flood) occurs, the sPinto contract claims the non-Pinto rewards and uses the proceeds to buy more Pinto. sPinto checks the Pinto price in every Well (liquidity pool) in which it received assets and swaps up to 10% of each of its non-Pinto assets into Pinto. The swap trigger price is capped at $1.02 and must be within a manipulation resistant range in order to minimize the contract from overpaying for Pinto and from being manipulated given its programmatic purchasing of Pinto. This structure maximizes the Pinto underlying each sPinto.

### **Downsides of sPinto**

sPinto holders make two primary sacrifices in exchange for fungibility. First, sPinto holders may not receive as much Stalk as if they were holding Deposited Pinto directly in the Silo because as new Pinto Deposits with less Stalk than the average Stalk per Pinto enter the sPinto contract, the number of Stalk per Pinto decreases for all sPinto holders. Second, sPinto holders are not able to [Convert](/resources/glossary#convert-1), and thereby realize opportunity cost for holding sPinto in the form of the potential to increase their PDV and receive a [Stalk Bonus](/resources/glossary#convert-down-bonus-stalk-bonus).

### Upgradability <a href="#upgradability" id="upgradability"></a>

sPinto is an upgradable contract, owned by the PCM.

### Security <a href="#security" id="security"></a>

sPinto is part of the Pinto bug bounty program on [Immunefi](https://immunefi.com/bug-bounty/pinto/information/) - bounty hunters are encouraged to submit bug reports regarding sPinto even before it’s formally added to the program. sPinto has been audited by Cantina and EgisSec. You can read the full audit reports here:

* <https://github.com/Egis-Security/audits/blob/main/reports/SiloedPinto.pdf>
* <https://cantina.xyz/portfolio/c7410678-05f5-4dc3-bdbd-976d11738bcd>

### **In Summary**

sPinto is designed to let people combine the most lucrative feature of algorithmic fiat money – prints paid directly to those who Deposit in the system – with simultaneous use of their Pinto in other DeFi protocols. sPinto solves the problems of Root, and will likely play an essential role in the widespread adoption of Pinto throughout crypto so it can save Ethereum from its overwhelming dependence on centralized stablecoins.

Users can wrap Pinto or Pinto Deposits into sPinto [here](https://pinto.money/wrap).


# Tractor: Automating the Farm

Pinto is the most dynamic system in DeFi, and there is no close second. Accordingly, farming the protocol optimally requires constant account maintenance.

Tractor is a trustless, P2P intents protocol that allows farmers to delegate specific actions without surrendering custody of and discretion over their assets. Tractor empowers users beyond merely permissioning how many tokens a given contract can spend on one's behalf – which is standard EVM functionality – to specify which actions a party can take and incentivize a 'Tractor operator' to perform those predefined actions on their behalf in exchange for a tip.

Tractor not only empowers farmers to use the protocol optimally, it enables the protocol to implement novel incentive mechanisms that further improve its efficiency in ways that would otherwise be impractical without the dramatic decrease in friction for users created by Tractor.

### **Motivating Example: Cultivation System**

The number of available Soil represents the number of Pinto the protocol is willing to borrow from the market. Selling out of Soil regularly, even in small quantities every Season (\~1 hour), is much better for long term sustainability than selling none or a small number of Soil most of the time and large numbers once in a while.

Creditworthiness is a social phenomenon. Pinto offering more debt than the market is willing to purchase has negative effects on the perceived creditworthiness of the protocol, increasing the interest rate the protocol needs to pay to attract creditors. Furthermore, long gaps between loans makes it very difficult for the protocol and the market to properly price its debt, further raising interest rates.

Historically, Beanstalk and Pinto both fell into the category of having too much available Soil combined with infrequent but large loans, leading to excessively high interest rates on loans.

The[ Cultivation System](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance) was a Pinto Improvement which dramatically decreased the number of Soil available in any given Season, until there was demand for all the Soil that was available at a given interest rate. After demand was demonstrated in a given Season, the number of Soil would ramp up each following Season, until the supply of Soil reached the demand for Soil, at which point the number of available Soil would stay relatively constant until demand increased or decreased. This change dramatically reduced the number of instances where there was significantly more supply of Soil than there was demand.

However, the Cultivation System made it such that in order to lend a significant number of Pinto to the protocol, lenders had to lend to the protocol in relatively small quantities consistently over numerous Seasons. This created a significant degree of friction to lend to the protocol: it required being online every Season to lend because if supply wasn't met, the protocol would decrease the number of available Soil in response to the lack of demand. Therefore, while the Cultivation System enabled the protocol to rapidly respond to demand for Soil, without an easy way for farmers to express their demand every Season, the effectiveness of the Field was greatly diminished.

### **Enter Tractor**

About 6 weeks after the deployment of the Cultivation System, the first Tractor use case was implemented: a Soil order book that enables farmers to sign a Tractor 'Blueprint' to lend Pinto at a minimum interest rate (among other parameters), allowing Tractor operators to fill their orders by Sowing on their behalf.

Prior to the implementation of the Soil order book, the Maximum Temperature, the highest interest rate offered by the protocol for loans each Season, was increasing perpetually, posing a risk to the long term sustainability of the protocol. After Tractor was implemented, the Maximum Temperature immediately started to drop from its high of \~1400% at the time Tractor was implemented to a healthier range around 750%. It has since dropped further to \~650%.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FTgOPGOnas1HPojRmf89l%2Fimage.png?alt=media&amp;token=051d1912-7dfe-4941-a1ff-679e53b4a36e" alt=""><figcaption></figcaption></figure>

### **Tractors Everywhere**

After the successful rollout of the first use of Tractor, development is actively taking place to bring the power of automation to everything farmers do on the Farm. The following are brief descriptions of new Tractor Blueprints that are in the pipeline.

#### Mow, Plant and Harvest

Pinto requires active claiming in order to maximize yield. In the Silo, Stalk that Grows from Seeds must be Mown in order to start earning a portion of Pinto mints. Additionally, in order for the Seeds associated with newly minted Pinto paid to Silo Depositors to start growing Stalk, they must be Planted. In the Field, when Pods become Harvestable (redeemable into Pinto), they must be Harvested and Deposited in the Silo in order to start earning additional yield. In the near future, a blueprint for Mowing Stalk, Planting Seeds and Harvesting Pods and Depositing the Pinto yielded, respectively, will go live, enabling farmers to maximally compound the yield they earn from the protocol without being behind their keyboards.

#### Dynamic Convert Bonus + Order Book

After the success of the Cultivation System and Soil order book in the Field, a similar system is being implemented in the Silo to support a [Dynamic Convert Bonus](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives). Through the Dynamic Convert Bonus, Pinto will be able to more granularly and strongly incentivize Converts that it desires in order to aid peg maintenance. The design for the Convert Bonus will follow the same model as the Field, starting with a small number of PDV worth of Converts eligible for a bonus and then increasing to meet demand. A Tractor Blueprint will support a Convert order book based on the price of Pinto, change in Seeds as a result of Converting and the Stalk bonus per PDV Converted.

#### Lending from Outside the Silo

The first Tractor Blueprint only enabled automated lending with Deposits already existing in the protocol. A forthcoming complementary Blueprint will support lending to the protocol using assets external to the Silo.

#### Seed Gauge Optimization

The number of Seeds awarded to the various asset types Deposited in the Silo is adjusted every Season to incentivize the alignment of the distribution of value in the Silo with its optimal distribution. A Tractor Blueprint will enable Depositors to automatically adjust their Silo Deposit distribution to maximize their Seeds, and therefore the yield they accrue from the protocol.

### **In Summary**

As the most dynamic system in DeFi, Pinto requires regular and active management of positions in order to maximize yield. Tractor empowers farmers to optimally manage their positions without having to execute transactions on a regular basis. Through the decrease in friction associated with Tractor, a new design space for peg maintenance has been opened up, enabling more fine-tuned and sustainable incentives. The number of use cases supported by Tractor will increase in the coming months.


# Pod Market

The Pod Market is a peer-to-peer marketplace that allows [Pods](/resources/glossary#pods) to be bought and sold in a trustless fashion without trading fees. The Pod Market creates liquidity for Pods through an onchain order book.

Sellers can list Pods or fill open Pod Orders placed by buyers.

Buyers can order Pods or fill open Pod Listings placed by sellers.

### **Pod Listings** <a href="#pod-listings" id="pod-listings"></a>

Pods from Pinto [Sown](/resources/glossary#sow) in a single transaction form a [Plot](/resources/glossary#plot). Anyone with a Plot can list a whole or partial Plot for sale in exchange for Pinto. This is known as a Pod Listing. Pod Listings have the following inputs:

| Pod Listing Inputs       | Example                          |
| ------------------------ | -------------------------------- |
| Plot                     | Place in Line: 140M, Pods: 4,000 |
| Position within the Plot | 2,000 to 4,000                   |
| Price per Pod            | 0.80 Pinto                       |
| Expiration               | 30M Pods                         |

#### *Plot*

Farmers may own multiple Plots. Plots are identified by their place in the Pod Line.

#### *Position within the Plot*

As Pods are Harvested on a First In, First Out (FIFO) basis, if less than a whole Plot is listed, the seller must choose which Pods within the Plot to list. A seller can list any contiguous set of Pods within a Plot. If only a portion of a Plot is listed, the seller must choose which subset of Pods within that Plot are for sale. In the example above, the last 2,000 Pinto in the Plot are Listed, while the first 2,000 (i.e. Pods 0 thru 2,000) remain in the seller’s possession.

#### *Price per Pod*

The sale price of each Pod, denominated in Pinto.

#### *Expiration*

The number of Pods that can [Harvest](/resources/glossary#harvest) before the expiration of the Pod Listing. Setting this input to 30M Pods would remove this Pod Listing from the Pod Market once 30M Pods are Harvested after the creation of the Pod Listing.

A Pod Listing can be cancelled at any time until it is entirely filled. Plots can only be listed in a single Pod Listing at a time. Pod Listings are automatically cancelled if the owner of the Plot transfers or re-lists any Pods in the Plot.

A Pod Listing can be entirely or partially filled at any time by a buyer. If the Pod Listing is partially filled, the rest of the Pod Listing remains listed.

The following metrics are displayed in the Pinto UI to give farmers a better understanding of the Listings on the market.

#### *Pod Score*

The return on a given Plot divided by the Plot's Place in Line. The formula is defined below:&#x20;

$$
PodScore = \frac{\frac{1}{Price Per Pod}}{Place In Line} \* 1e12
$$

The Pod Score may be used by farmers to gauge the relative attractiveness of a given Plot Listing. For example, given 2 Plots:&#x20;

* 0.25 Pinto / Pod, 10M Place in Line
* 0.50 Pinto / Pod, 4M Place in Line

The latter has a better risk/return profile, given that the former would need 2.5x more Pintos to be minted, yet only yields 2x more than the former. This is reflected in the higher Pod Score (400k vs 500k).

#### Effective Temperature

The Temperature in which the Field would need to offer to give the same yield as the Listing at the given price. The formula is defined below:

$$
{Effective Temperature} = \frac{1}{Price Per Pod} - 1
$$

For example, a Listing where the Price Per Pod is 0.50 is equivalent to Sowing in the Field at a Temperature of 100% (assuming the same Place in Line).

### **Pod Orders** <a href="#pod-orders" id="pod-orders"></a>

A Pod Order is an offer to buy Pods at a given price, before a given place in the Pod Line. Any seller may fill a Pod Order by selling Pods according to the terms of the Pod Order.

Anyone with Pinto can Order Pods by creating a Pod Order. Pod Orders have the following inputs:

| Pod Order Inputs                       | Example    |
| -------------------------------------- | ---------- |
| Maximum number of Pods to be purchased | 4,000 Pods |
| Price per Pod                          | 0.80 Pinto |
| Maximum place in the Pod Line          | 140M       |

#### *Maximum number of Pods to be purchased*

Because Pod Orders can be partially or entirely filled at any time by a seller, a Pod Order defines the maximum number of Pods the buyer would like to purchase at a given price.

#### *Price per Pod*

The price to be paid for each Pod, denominated in Pinto.

#### *Maximum place in the Pod Line*

A Pod Order with a maximum place in the Pod Line of 140M could be filled by any Pods with a position in the Pod Line of 140M or earlier. In general, Pods closer to the front of the Pod Line are more valuable, as they become Harvestable for Pinto sooner due to the FIFO Harvest schedule.

A Pod Order can be cancelled at any time until it is filled. To facilitate instant clearance, Pinto are locked in a Pod Order until it is entirely filled or cancelled. If the Pod Order is partially filled, the rest of the Pod Order remains listed.


# Depot

Complex interactions with Base-native protocols can be tedious, cumbersome and expensive. The\
Depot facilitates complex, gas-efficient interactions with other Base-native protocols in a single\
transaction. The Depot contains [Pipeline](https://evmpipeline.org).

Pipeline allows anyone to perform an arbitrary series of actions in the EVM in a single transaction by using [0xb1bE0001f5a373b69b1E132b420e6D9687155e80](https://basescan.org/address/0xb1bE0001f5a373b69b1E132b420e6D9687155e80) as a sandbox for execution.

The following functions can be called via Pipeline:

* `pipe(...)`
* `multiPipe(...)`
* `advancedPipe(...)`


# Farm Balances

Farm Balances are assets stored on the Farm that are not Deposited in the Silo or locked in Pod\
Orders. Farm Balances enable the protocol to store any ERC-20 token on behalf of a user.

All interactions with the protocol that use a user’s ERC-20 tokens can use tokens from both Farm and Wallet Balances.


# Classifying State

Pinto faces the fundamental limitation that it cannot fix the Pinto price at its value target of $1, but instead must encourage widespread participation in target maintenance through protocol-native financial incentives. Low volatility is a function of how regularly the price of 1 Pinto oscillates across its target and the magnitude of price deviations from it.

The protocol has eight direct target maintenance tools available:

1. Increase the [Pinto supply](/responding-to-state/minting);
2. Change the [Soil supply](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance);
3. Change the [Temperature](/responding-to-state/temperature-changes);
4. Change the [Crop Ratio](/responding-to-state/crop-ratio-changes);
5. Change the [Convert Down Penalty per PDV](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives#dynamic-convert-down-penalty);
6. Change the [Convert Up Bonus per PDV](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives#dynamic-convert-up-bonus)&#x20;
7. Change the [Convert Up Bonus Capacity](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives#dynamic-convert-up-bonus); and
8. Sell Pinto ([Flood](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-flood-biblical-returns-to-prevent-pump-and-dumps)).

At the beginning of every [Season](/resources/glossary#season), Pinto evaluates its position (i.e., price, debt level and liquidity level) and current state (i.e., direction and acceleration) with respect to ideal equilibrium, and dynamically adjusts the Pinto supply, Soil supply, Temperature, Crop Ratio, Convert Down Penalty per [PDV](/resources/glossary#pinto-denominated-value-pdv), Convert Up Bonus per PDV, and Convert Up Capacity to move closer to ideal equilibrium.

### **Ideal Equilibrium** <a href="#ideal-equilibrium" id="ideal-equilibrium"></a>

The protocol is in ideal equilibrium when the Pinto price, debt level and liquidity level are all at their optimal levels. In practice, this requires that four conditions are met:

1. The price of Pinto is regularly oscillating around its value target;
2. The debt level is optimal;
3. The liquidity level is optimal; and
4. Demand for [Soil](/resources/glossary#soil) is steady.

In order to return to ideal equilibrium, the protocol affects the supply of and demand for Pinto in response to the Pinto price, the debt level, the liquidity level and changing demand for Soil. It does so by adjusting the Pinto supply, Soil supply, Temperature, Crop Ratio, Convert Down Penalty per PDV, Convert Up Bonus per PDV, and Convert Up Capacity.

Pinto supply increases primarily affect the Pinto price. Soil supply impacts the Pinto supply and the debt level. Temperature changes primarily affect demand for Soil. Crop Ratio changes primarily affect demand for Conversions between Pinto and LP token Deposits.

In order to make the proper adjustments, the protocol reassesses the states of the Pinto, Soil and Convert markets at the beginning of each Season.

In practice, maintaining ideal equilibrium is impossible. Deviations from ideal equilibrium are normal and expected. As the protocol grows, the durations and magnitudes of deviations are expected to decrease.

### **Price Level** <a href="#decentralized-price-oracle" id="decentralized-price-oracle"></a>

Pinto's core objective is to oscillate the price of Pinto above and below its $1 target. The protocol infers the liquidity and time weighted price of 1 Pinto by calculating TWA∆P.

The protocol can be in 3 different states with respect to its price (not including optimal):

* Reasonably low price: Price < $1
* Optimal price: Price = $1
* Reasonably high price: $1 < Price ≤ $1.025
* Excessively high price: Price > $1.025

The protocol also uses a Penalty Price, currently set to $1.005, to determine the appropriate Stalk penalty to apply to Convert Downs.

### **Debt Level** <a href="#debt-level" id="debt-level"></a>

The Pod Rate represents the protocol debt level relative to the Pinto supply. The Pod Rate is often used as a proxy for the protocol's health. If the Pinto supply is 1000 and there are 2000 [Pods](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto#pods), the Pod Rate is 200%.

The protocol defines a handful of Pod Rate ranges that it uses as an input to determine how to change the Temperature:

* Excessively low debt: Pod Rate < 3%
* Reasonably low debt: 3% ≤ Pod Rate < 15%
* Optimal level of debt: Pod Rate = 15%
* Reasonably high debt: 15% < Pod Rate ≤ 25%
* Excessively high debt: 25% < Pod Rate ≤ 100%
* Extremely high debt: Pod Rate > 100%

### Liquidity Level <a href="#liquidity-level" id="liquidity-level"></a>

The Liquidity Rate represents the protocol liquidity level relative to the Pinto supply. The Liquidity Rate is a useful indicator of the protocol's health.

In the context of the Liquidity Rate, liquidity is defined as the sum of the USD values of the non-Pinto assets in each pool on the [Deposit Whitelist](/resources/contracts#current-deposit-whitelist). If there is $8M of non-Pinto liquidity in pools on the Deposit Whitelist and the Pinto supply is 16M, the Liquidity Rate is 50%.

The protocol can be in 4 different states in relation to its Liquidity Rate:

* Excessively low liquidity: Liquidity Rate < 12%;
* Reasonably low liquidity: 12% ≤ Liquidity Rate < 40%;
* Optimal level of liquidity: Liquidity Rate = 40%
* Reasonably high liquidity: 40% < Liquidity Rate ≤ 80%; or
* Excessively high liquidity: Liquidity Rate > 80%.

### **Direction** <a href="#direction" id="direction"></a>

The current state of Pinto is in part determined by the direction of change with respect to ideal equilibrium.

The direction of change of the protocol with respect to ideal equilibrium is considered either toward or away from ideal equilibrium, based on the current debt level and price.

When P > 1 (more specifically, when TWA∆P > 0), debt is paid back. Therefore, if there is more debt than optimal, the protocol is moving toward the ideal equilibrium. If there is less debt than optimal, the protocol is moving away from the ideal equilibrium.

When P ≤ 1, debt can only increase or remain constant. Therefore, if there is more debt than optimal, the protocol is moving away from ideal equilibrium. If there is less debt than optimal, the protocol is moving toward ideal equilibrium.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FFEO6nytb21TNeDE0w5Tk%2Fimage.png?alt=media&amp;token=600d46ce-c29e-444f-80b2-0918d6f13333" alt=""><figcaption></figcaption></figure>

### **Demand for Soil** <a href="#demand-for-soil" id="demand-for-soil"></a>

Demand for Soil is a factor in the acceleration of Pinto with respect to ideal equilibrium, which affects Maximum Temperature changes. Demand for Soil is considered decreasing, steady or increasing.

* The number of Sown Pinto each Season (​$$u\_t$$) indicated demand for Soil over the course of that Season.
* The rate of change in the number of Sown Pinto each Season (Delta Demand) is calculated as the number of Sown Pinto in the previous Season ($$u\_{t−1}$$​) divided by the number of Sown Pinto two Seasons ago ($$u\_{t-2}$$​).

Based on this ratio of the number of Sown Pinto over the prior two Seasons, or Delta Demand:

* If Delta Demand < 95%, demand for Soil is decreasing.
* If 95% ≤ Delta Demand < 105%, demand for Soil is steady.
* If 105% ≤ Delta Demand, demand for Soil is increasing.

However, when Pinto is Sown in all Soil in a Season (defined as the lower of 50 Soil or  <5% Soil remaining), the Delta Demand ratio is not used. Instead, the protocol checks the following conditions to determine the current demand for Soil:

* After a Season in which not all Soil was Sown, if all Soil was Sown in the previous Season, demand for Soil is increasing.
* When all Soil is Sown in consecutive Seasons, the difference in time it takes for all Soil to be Sown over the previous two Seasons (where $$s\_{t-2}$$ and $$s\_{t-1}$$ are the times in which all but Soil was Sown in Seasons $$t-2$$ and $$t-1$$, respectively) can provide a more accurate measurement:
  * If all Soil was Sown in the first 20 minutes of the previous Season (*i.e.*, $$s\_{t-1} < 20$$ minutes), demand for Soil is increasing.
  * If all Soil was not Sown in the first 20 minutes of the previous Season, the protocol compares $$s\_{t-2}$$ and $$s\_{t-1}$$.
    * If it took more than 5 minutes longer for all Soil to be Sown in Season $$t-1$$ than Season $$t-2$$ (*i.e.*, $$s\_{t-1} - s\_{t-2} > 5$$ minutes), demand for Soil is decreasing.
    * If it took more than 5 minutes longer for all Soil to be Sown in Season $$t-2$$ than Season $$t-1$$ (*i.e.*, $$s\_{t-2} - s\_{t-1} > 5$$ minutes), demand for Soil is increasing.
    * Otherwise, demand for Soil is steady.

### **Acceleration** <a href="#acceleration" id="acceleration"></a>

The current state of the protocol with respect to ideal equilibrium is in part determined by the acceleration of change.

The acceleration of the protocol affects the magnitude of Maximum Temperature changes and is considered decelerating, steady or accelerating based on price and the demand for Soil.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/lnPGa1oF3Accv1UC4X0i/CleanShot%202025-04-07%20at%2016.46.08@2x.png" alt=""><figcaption></figcaption></figure>

### **Current State** <a href="#current-and-optimal-state" id="current-and-optimal-state"></a>

Based on a combination of the protocol's direction and acceleration, the protocol has six potential current states:

* Accelerating away from ideal equilibrium;
* Accelerating toward ideal equilibrium;
* Steady away from ideal equilibrium;
* Steady toward ideal equilibrium;
* Decelerating away from ideal equilibrium; and
* Decelerating toward ideal equilibrium.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/fwQRcTY5crzWK1T9el4q/CleanShot%202025-04-07%20at%2016.54.46@2x.png" alt=""><figcaption></figcaption></figure>

### Optimal State

The protocol's optimal state is that which moves it toward ideal equilibrium in the healthiest fashion, given the current position.

When the debt level is excessively high or low, an optimal state is accelerating toward ideal equilibrium. When the debt level is reasonably high or low, an optimal state is either steady or decelerating toward ideal equilibrium.

<figure><img src="https://2611268211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FE6o3oJ1UvNLq82fMCMG5%2Fuploads%2FBCTbnyLNSP4qYO3pSvXr%2Fimage.png?alt=media&amp;token=f4a61905-df90-489a-846c-52b40197a531" alt=""><figcaption></figcaption></figure>


# Temperature Changes

The Temperature is the interest rate for Sowing Pinto.

At the beginning of each [Season](/resources/glossary#season), the protocol changes the Maximum [Temperature](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-field-simply-put#temperature) depending on its position ([price](/responding-to-state/classifying-state#decentralized-price-oracle) and [debt level](/responding-to-state/classifying-state#debt-level)) and current state ([direction](#direction) and [acceleration](#acceleration)) with respect to its [ideal equilibrium](/responding-to-state/classifying-state#ideal-equilibrium).

The Temperature increases logarithmically during the [Morning](#morning) (first 10 minutes) of each Season according to a Dutch auction from 1% of the Maximum Temperature to the Maximum Temperature.

Considering the current state and the debt level, the protocol adjusts the Maximum Temperature to move toward the optimal state.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/jx4xU8NcrT2cpwQzVUuu/CleanShot%202025-05-05%20at%2018.30.45.png" alt=""><figcaption></figcaption></figure>

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/9Zq9ZfkbgtgTnOY9w0Jg/CleanShot%202025-05-05%20at%2018.30.51.png" alt=""><figcaption></figcaption></figure>

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/TqzYMA7FWydYcAxF87mD/CleanShot%202025-05-05%20at%2018.30.58.png" alt=""><figcaption></figcaption></figure>

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/k3944cNNzS0J3DEjR4eM/CleanShot%202025-05-05%20at%2018.31.08.png" alt=""><figcaption></figcaption></figure>


# Crop Ratio Changes

*To read more about the Crop Ratio in context, see* [*Optimizing Liquidity Distribution via the Seed Gauge System*](/pinto-mechanics/silo-the-perfect-complement-to-credit/optimizing-liquidity-distribution-via-the-seed-gauge-system)

The Crop Ratio is the ratio of the [Seeds](/resources/glossary#seeds) per [PDV](/resources/glossary#pinto-denominated-value-pdv) reward between Deposited Pinto and the Deposited LP token with the most Seeds (which is determined by the LP token with the highest Gauge Points per PDV).

In order to adjust the Crop Ratio, in practice the protocol adjusts a scalar (the Crop Scalar, $$L$$) between 0 and 1, where 0 results in the minimum Crop Ratio ($$Y$$) and 1 results in the maximum Crop Ratio ($$Z$$). Therefore, the target maintenance mechanism can adjust the Crop Ratio independently of the minimum and maximum values (which are currently set to 50% and 200%, respectively).

$$
CropRatio = Y + L(Z - Y)
$$

At the beginning of each [Season](/resources/glossary#season), the protocol changes the Crop Scalar depending on its position ([price](/responding-to-state/classifying-state#decentralized-price-oracle), [debt level](/responding-to-state/classifying-state#debt-level) and [liquidity level](/responding-to-state/classifying-state#liquidity-level)) with respect to its [ideal equilibrium](/responding-to-state/classifying-state#ideal-equilibrium).

Considering the current state and the liquidity level, the protocol adjusts the Crop Scalar to move toward the optimal state.

In any Season where it is [Raining](/resources/glossary#rain), the Crop Scalar becomes 0 and the Crop Ratio is set to 33.33%.&#x20;

### Excessively Low Liquidity Rate <a href="#excessively-low-l2sr" id="excessively-low-l2sr"></a>

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/IF76ksbcRACC5iOyIQcF/CleanShot%202025-05-05%20at%2019.10.44.png" alt=""><figcaption></figcaption></figure>

No matter the liquidity level, when the price is excessively high, the protocol should maximally incentivize Converting to LP Deposits by aggressively decreasing the Crop Ratio.

When the Liquidity Rate is excessively low, in all cases, the protocol should be similarly aggressive in incentivizing Converts to LP Deposits by quickly reaching the minimum Crop Ratio.

### Reasonably Low Liquidity Rate <a href="#reasonably-low-l2sr" id="reasonably-low-l2sr"></a>

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/7HU8hRjVKhGqohU5wErN/CleanShot%202025-05-05%20at%2019.11.04.png" alt=""><figcaption></figcaption></figure>

When the Liquidity Rate is reasonably low and Pod Rate is low, the protocol should be similarly aggressive in reaching the minimum Crop Ratio given that, at the margin, the protocol would rather take on debt than lose liquidity. When the Liquidity Rate is reasonably low and Pod Rate is high, the protocol should gradually increase the Crop Ratio when P > 1 (to incentivize Conversions above peg) and gradually decrease it when P ≤ 1 (to incentivize Conversions below peg).

### Reasonably High Liquidity Rate <a href="#reasonably-high-l2sr" id="reasonably-high-l2sr"></a>

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/RRa5VKVxkJIIn8ccnHtR/CleanShot%202025-05-06%20at%2019.18.31@2x.png" alt=""><figcaption></figcaption></figure>

When the Liquidity Rate is reasonably high and P < 1, the protocol should similarly gradually increase the Crop Ratio to incentivize Converting from LP Deposits to Pinto Deposits, and vice versa when P > 1.

### Excessively High Liquidity Rate <a href="#excessively-high-l2sr" id="excessively-high-l2sr"></a>

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/M1Vz5fYhu0BdMtWnhfTh/CleanShot%202025-05-05%20at%2019.14.34.png" alt=""><figcaption></figcaption></figure>

When the Liquidity Rate is excessively high, the protocol should be more willing to accept a loss of liquidity rather than an increase in debt level at the margin. Therefore, it should adjust the Crop Scalar just as it does when L2SR is reasonably high, except it can be slightly more aggressive when P < 1 and the Pod Rate is high.


# Flood

*This is a concise specification of the Flood. For a deep dive into the Flood's design and mechanics, see* [*The Flood: Biblical Returns to prevent Pump and Dumps.*](/pinto-mechanics/silo-the-perfect-complement-to-credit/the-flood-biblical-returns-to-prevent-pump-and-dumps)

The Pinto protocol sells newly minted Pinto on the open market during long run increases in demand for Pinto when [increasing the Pinto supply](/responding-to-state/classifying-state#bean-supply), [lowering the Maximum Temperature](/responding-to-state/temperature-changes) and [lowering the Crop Ratio](/responding-to-state/crop-ratio-changes) have not crossed the Pinto price over its value target.

At the beginning of a [Season](/resources/glossary#season) where TWA∆P > 0 and [Pod Rate](/responding-to-state/classifying-state#debt-level) < 3% (Excessively Low), it is Raining. At the beginning of a Season in which it Rains, the [Crop Ratio](/responding-to-state/crop-ratio-changes) is set to 33.33%. If at the beginning of a Season it continues to [Rain](/resources/glossary#rain) and the cumulative ∆P > 0, it Floods.

At the beginning of a Season during a Flood, the protocol mints additional Pinto and sells them directly in pools on the [Flood Whitelist](/responding-to-state/flood#current-flood-whitelist) with the highest Pinto price at the end of the previous Season until the [liquidity weighted](/resources/glossary#liquidity-weight) price is $1.&#x20;

At the beginning of each Season in which it Floods, up to 0.1% of the Pinto supply worth of [Pods](/resources/glossary#pods) that grew from Pinto Sown before it began to Rain become [Harvestable](/resources/glossary#harvestable-pods).

In total, during a [gm](/resources/glossary#gm) call in which it Floods, the following Pinto are minted:

1. Cumulative ∆P at the end of the previous Season, which are minted and sold directly in pools on the Flood Whitelist;
2. Up to 0.1% of the Pinto supply worth of Pods;
3. TWA∆P per the [target maintenance mechanism](/responding-to-state/classifying-state) (as with non-Flood gm calls); and
4. The gm reward (as with non-Flood gm calls).

Proceeds from the sale are distributed to [Stalkholders](/resources/glossary#stalkholders) at the beginning of Season in proportion to their Stalk holdings when it began to Rain (i.e., [**Stalk**](/resources/glossary#stalk) **minted after it began to Rain does not contribute towards ownership of the Flood proceeds**).&#x20;

#### **Current Flood Whitelist**

<table><thead><tr><th width="269">Name</th><th>Base Address</th></tr></thead><tbody><tr><td><a href="https://pinto.exchange/#/wells/8453/0x3e11001cfbb6de5737327c59e10afab47b82b5d3">PINTO:WETH Well</a></td><td><a href="https://basescan.org/address/0x3e11001CfbB6dE5737327c59E10afAB47B82B5d3">0x3e11001CfbB6dE5737327c59E10afAB47B82B5d3</a></td></tr><tr><td><a href="https://pinto.exchange/#/wells/8453/0x3e111115a82df6190e36adf0d552880663a4dbf1">PINTO:cbETH Well</a></td><td><a href="https://basescan.org/address/0x3e111115A82dF6190e36ADf0d552880663A4dBF1">0x3e111115A82dF6190e36ADf0d552880663A4dBF1</a></td></tr><tr><td><a href="https://pinto.exchange/#/wells/8453/0x3e11226fe3d85142b734abce6e58918d5828d1b4">PINTO:cbBTC Well</a></td><td><a href="https://basescan.org/address/0x3e11226fe3d85142B734ABCe6e58918d5828d1b4">0x3e11226fe3d85142B734ABCe6e58918d5828d1b4</a></td></tr><tr><td><a href="https://pinto.exchange/#/wells/8453/0x3e1133ac082716ddc3114bbefeed8b1731ea9cb1">PINTO:USDC Well</a></td><td><a href="https://basescan.org/address/0x3e1133aC082716DDC3114bbEFEeD8B1731eA9cb1">0x3e1133aC082716DDC3114bbEFEeD8B1731eA9cb1</a></td></tr><tr><td><a href="https://pinto.exchange/#/wells/8453/0x3e11444c7650234c748d743d8d374fce2ee5e6c9">PINTO:WSOL Well</a></td><td><a href="https://basescan.org/address/0x3e11444c7650234c748D743D8d374fcE2eE5E6C9">0x3e11444c7650234c748D743D8d374fcE2eE5E6C9</a></td></tr></tbody></table>


# Minting

At the start of each [Season](/resources/glossary#season), Pinto deterministically mints new Pinto and distributes them to farmers. Minting Pinto serves two purposes: incentivizing timekeeping and target maintenance price.

Pinto are minted to incentivize timekeeping as a function of how long after the earliest time the [`gm`](/resources/glossary#gm) function could be called to begin the next Season. For more information on how many Pinto are minted to incentivize the `gm` function call, see the [Pinto whitepaper](https://pinto.money/pinto.pdf#page=7).

Pinto are minted to facilitate peg maintenance as a function of the TWA∆P, the time weighted average shortage or excess of Pinto across all liquidity pools on the Minting Whitelist over the previous Season. The newly minted Pinto are distributed deterministically along various Shipping Routes.

### Current Minting Whitelist

<table><thead><tr><th width="236">Contract</th><th>Base Address</th></tr></thead><tbody><tr><td>PINTO:cbETH LP</td><td><a href="https://basescan.org/address/0x3e111115A82dF6190e36ADf0d552880663A4dBF1">0x3e111115A82dF6190e36ADf0d552880663A4dBF1</a></td></tr><tr><td>PINTO:cbBTC LP</td><td><a href="https://basescan.org/address/0x3e11226fe3d85142B734ABCe6e58918d5828d1b4">0x3e11226fe3d85142B734ABCe6e58918d5828d1b4</a></td></tr><tr><td>PINTO:USDC LP</td><td><a href="https://basescan.org/address/0x3e1133aC082716DDC3114bbEFEeD8B1731eA9cb1">0x3e1133aC082716DDC3114bbEFEeD8B1731eA9cb1</a></td></tr></tbody></table>

### **Shipping Routes**

Shipping Routes determine how Pinto mints based on TWA∆P are distributed to different components of the system. Mints for the gm reward and [Flood](https://docs.pinto.money/target-maintenance/flood) are distributed independent of Shipping Routes.

If Pinto allocated to a particular Shipping Route exceed the maximum Pinto that Shipping Route can handle (*i.e.*, there are no more [Unharvestable Pods](/resources/glossary#harvestable-pods) in the Field), the excess Pinto are distributed to the other Shipping Routes in proportion to their allocations. The Silo Shipping Route can handle an infinite number of Pinto mints per Season.

Pinto was deployed with an initial mint of 1000 Pinto. Thereafter, Pinto mints based on TWA∆P at the start of each Season are distributed as follows:

Between a supply of 1000 and 1 billion Pinto:

* 48.5% to [Pods](/resources/glossary#pods) at the front of the [Pod Line](/resources/glossary#pod-line);
* 48.5% to [Stalkholders](/resources/glossary#stalkholders) in the [Silo](/resources/glossary#silo); and
* 3% to the [Pinto development budget contract](/resources/contracts#misc).

After a supply of 1 billion Pinto until [old Beanstalk holders are recapitalized](/appendix/beanstalk-obligations):

* 48.5% to Pods at the front of the Pod Line;
* 48.5% to Stalkholders in the Silo; and
* 3% to old [Beanstalk](https://bean.money) holders.

After old Beanstalk holders are recapitalized:

* 50% to Pods at the front of the Pod Line; and
* 50% to Stalkholders in the Silo.


# Coming Soon


# Beanstalk Obligations

This document has been uploaded to Arweave \[TBA]

***

Pinto is a fork of [Beanstalk](https://bean.money). As part of honoring the obligations created by the April 2022 Beanstalk governance exploit, Pinto allocates a portion of future mints to repay former Beanstalk participants. Repayment is based on a snapshot of Beanstalk state at Ethereum L1 block [21223086](https://etherscan.io/block/21223086) / Arbitrum block [276160746](https://arbiscan.io/block/276160746) (November 19, 2024), corresponding to the Pinto Diamond deployment on Base at block [22622854](https://basescan.org/block/22622854).

### Eligibility

Farmers who held any of the following assets on Beanstalk at the time of the snapshot are eligible:

* [Unripe Beans](https://docs.bean.money/almanac/farm/barn#unripe-assets) or [Unripe LP](https://docs.bean.money/almanac/farm/barn#unripe-assets) (Silo deposits)
* [Fertilizer](https://docs.bean.money/almanac/farm/barn#fertilizer) (Barn Raise participants)
* [Pods](https://docs.bean.money/almanac/farm/field) (Field lenders)

Pinto does not allocate any mints for Beans or liquid LP tokens held on Beanstalk at the time of the snapshot.

To check specific balances, connect the wallet that held assets on Beanstalk to the [Beanstalk Obligations](https://pinto.money/beanstalk) page on the Pinto interface.

### Asset Types

After the Pinto supply exceeds 1 billion, [3% of mints](https://docs.pinto.money/responding-to-state/minting#shipping-routes) are allocated to repaying old Beanstalk debt holders across three asset types:

| Asset                 | Description                                                                                      | Action                   |
| --------------------- | ------------------------------------------------------------------------------------------------ | ------------------------ |
| Beanstalk Silo Tokens | ERC-20 tokens representing recapitalized Unripe asset value (also referred to as Ripening Pinto) | Claim earned Pinto       |
| Beanstalk Fertilizer  | ERC-1155 tokens mirroring the Beanstalk Fertilizer system                                        | Rinse fertilized Pinto   |
| Beanstalk Pods        | Pods in a separate Beanstalk Pod Line                                                            | Harvest Harvestable Pods |

### Distribution

Beanstalk Silo Token holders, active Beanstalk Fertilizer holders, and Beanstalk Pod holders each receive 1/3 of the Pinto mints allocated to repaying old Beanstalk holders (1% of mints each).

If there is no active Beanstalk Fertilizer, Beanstalk Silo Token holders and Beanstalk Pod holders each receive 1/2 of Pinto mints allocated to repaying old Beanstalk holders (1.5% of mints each).

If there are neither active Beanstalk Fertilizer nor Beanstalk Silo Tokens remaining, Beanstalk Pod holders receive 100% of the Pinto mints allocated to repaying old Beanstalk holders (3% of mints).

Once all outstanding Beanstalk Fertilizer, Beanstalk Silo Tokens, and Beanstalk Pods are fully repaid, the 3% of mints previously allocated to honoring Beanstalk debt is distributed to Pinto participants under its normal model: 50% to [Pods](https://docs.pinto.money/resources/glossary#pods) and 50% to [Stalkholders](https://docs.pinto.money/resources/glossary#stalkholders).

### Supply Threshold

Before the Pinto supply reaches 1 billion, 3% of mints are directed to the [Pinto development budget contract](https://docs.pinto.money/resources/contracts#misc). After the supply exceeds 1 billion Pinto, the 3% allocation transitions from the development budget to Beanstalk debt repayment.

Repayment depends on continued protocol growth and minting. See [Disclosures](https://docs.pinto.money/appendix/disclosures) for risk factors.

### Contract Accounts

Some Beanstalk holders were contract accounts (such as multisig wallets or DeFi protocols) that may not exist at the same address on Base. Assets belonging to these accounts are held in a Contract Payback Distributor that supports multiple claiming methods.

### Contracts

Beanstalk Silo Token and Fertilizer repayments are managed by dedicated contracts. Pod repayments are handled directly by the Pinto protocol through a separate repayment Field (Field ID 1).

All payback contracts use the [TransparentUpgradeableProxy](https://docs.openzeppelin.com/contracts/5.x/api/proxy#TransparentUpgradeableProxy) pattern. Users interact with the Proxy address; the Implementation address contains the contract logic. A shared Proxy Admin controls upgrade authorization.

| Contract                     | Type           | Base Address                                                                                                          |
| ---------------------------- | -------------- | --------------------------------------------------------------------------------------------------------------------- |
| Beanstalk Silo Payback       | Proxy          | [0x525C94754C51946a7a3B72580Ce0DF36922E1E64](https://basescan.org/address/0x525C94754C51946a7a3B72580Ce0DF36922E1E64) |
| Beanstalk Silo Payback       | Implementation | [0xDbb10C0cE795FFd3A4003CF0EcC849b25a788EB1](https://basescan.org/address/0xDbb10C0cE795FFd3A4003CF0EcC849b25a788EB1) |
| Beanstalk Barn Payback       | Proxy          | [0x68bDbb0402a3Ca89C7C4af8e41C021635102d158](https://basescan.org/address/0x68bDbb0402a3Ca89C7C4af8e41C021635102d158) |
| Beanstalk Barn Payback       | Implementation | [0x5bb2b891496F9f4db1467755eDc240329EA08E2C](https://basescan.org/address/0x5bb2b891496F9f4db1467755eDc240329EA08E2C) |
| Contract Payback Distributor | Proxy          | [0xbA941Af3292c49b585f4EC5C8164c1dfc893EEdC](https://basescan.org/address/0xbA941Af3292c49b585f4EC5C8164c1dfc893EEdC) |
| Contract Payback Distributor | Implementation | [0xED3Ead9D8b6E57f666E60ccf833f3ed1Be2Dd4c0](https://basescan.org/address/0xED3Ead9D8b6E57f666E60ccf833f3ed1Be2Dd4c0) |
| Proxy Admin                  | —              | [0xE5A707d49968937C860762fB256CE9dC7B1370F0](https://basescan.org/address/0xE5A707d49968937C860762fB256CE9dC7B1370F0) |


# Beanstalk Fertilizer

Beanstalk [Fertilizer](https://docs.bean.money/almanac/farm/barn#fertilizer) was originally purchased during the Barn Raise to fund Beanstalk's recapitalization after the April 2022 exploit. Holders of Fertilizer on Beanstalk received equivalent ERC-1155 tokens on the Beanstalk Barn Payback contract. Each Fertilizer token is identified by a unique ID that corresponds to its target Beans Per Fertilizer (BPF) threshold.

### Sprouts and Humidity

Each Fertilizer token has a Humidity, which represents the interest rate associated with that Fertilizer when it was originally purchased. Sprouts represent the Pinto remaining to be earned before a Fertilizer token is fully repaid:

> Sprouts = Balance × max(0, Fertilizer ID − Current BPF)

As the protocol distributes Pinto to the Beanstalk Barn Payback contract, the global BPF increases. As BPF rises, Sprouts decrease and Fertilized Pinto (the claimable amount) increases.

### How Fertilization Works

Each [Season](https://docs.pinto.money/resources/glossary#season), when the Pinto supply exceeds 1 billion and the [time-weighted average price](https://docs.pinto.money/responding-to-state/minting) of Pinto is above $1, a portion of newly minted Pinto is distributed to the Beanstalk Barn Payback contract. These Pinto increase the BPF proportionally across all Active Fertilizer (Fertilizer whose ID has not yet been reached by the current BPF).

When BPF reaches or exceeds a Fertilizer ID, that Fertilizer is considered fully fertilized and is removed from the active set. Remaining Pinto are then distributed across the smaller pool of still-Active Fertilizer, accelerating the repayment of subsequent Fertilizer IDs.

Any Pinto that cannot be evenly distributed in a given Season are carried over as a remainder and included in the next Season's distribution.

### Rinsing

Rinsing is the process of claiming Fertilized Pinto. To Rinse, visit the [Beanstalk Obligations](https://pinto.money/beanstalk) page on the Pinto interface and click **Rinse** in the Beanstalk Fertilizer section. Fertilized Pinto accumulates automatically and can be Rinsed at any time. Rinsed Pinto are sent to the Farmer's wallet.

### Transferring

Beanstalk Fertilizer tokens can be transferred to another address by clicking **Send** in the Beanstalk Fertilizer section. When Fertilizer is transferred, any accumulated Fertilized Pinto for both the sender and the recipient is automatically claimed to their respective Farm Balances before the transfer occurs. The recipient then begins earning from the current BPF going forward.

Farmers who hold multiple Fertilizer IDs can transfer them individually or in batches.

### Completion

Once all Fertilizer IDs have been fully fertilized (BPF reaches or exceeds the highest Fertilizer ID), the Beanstalk Barn repayment is complete. Any mints previously allocated to this route are redistributed to the remaining active repayment routes.


# Beanstalk Pods

[Pods](https://docs.pinto.money/resources/glossary#pods) on Beanstalk represented loans to the protocol: Farmers burned Beans in exchange for a claim on future minted Beans. Beanstalk Pod holders received Pods in a separate Beanstalk Pod Line based on a snapshot of the Beanstalk [Field](https://docs.bean.money/almanac/farm/field) at the time of Pinto deployment.

The Beanstalk Pod Line contains approximately 919.77 million Pods and operates independently from Pinto's primary [Pod Line](https://docs.pinto.money/resources/glossary#pod-line): it has its own Harvestable Index and follows the same first-in, first-out ([FIFO](https://docs.pinto.money/resources/glossary#fifo)) redemption order.

### How Pods Become Harvestable

Each [Season](https://docs.pinto.money/resources/glossary#season), when the Pinto supply exceeds 1 billion and the [time-weighted average price](https://docs.pinto.money/responding-to-state/minting) of Pinto is above $1, a portion of newly minted Pinto is allocated to the Beanstalk repayment Field. This advances the Harvestable Index of the Beanstalk Pod Line, converting Unharvestable Pods into [Harvestable Pods](https://docs.pinto.money/resources/glossary#harvestable-pods) on a FIFO basis.

Pods at the front of the Beanstalk Pod Line become Harvestable first. The rate at which Pods become Harvestable depends on how many Pinto are minted and allocated to this route each Season.

### Harvesting

To Harvest, visit the [Beanstalk Obligations](https://pinto.money/beanstalk) page on the Pinto interface and click **Harvest** in the Beanstalk Pods section. Harvesting converts Harvestable Pods into Pinto on a 1:1 basis and sends them to the Farmer's wallet.

Farmers with multiple Plots may have some Plots that are fully Harvestable, some partially Harvestable, and some still Unharvestable, depending on their position in the Beanstalk Pod Line.

### Transferring

Beanstalk Pods can be transferred to another address by clicking **Send** in the Beanstalk Pods section. Farmers can transfer entire Plots or partial Plots by specifying a range within a Plot.

### Trading

Beanstalk Pods can be bought and sold on the [Pod Market](https://docs.pinto.money/resources/glossary#pod-market) by clicking **Buy/Sell** in the Beanstalk Pods section.

### Completion

The Beanstalk Pod repayment is the last route to finish. As the Beanstalk Silo and Beanstalk Fertilizer routes complete, their allocations cascade to the remaining routes, eventually directing up to 3% of all mints to the Beanstalk Pod Line. See the Distribution section for the full cascading logic.


# Beanstalk Silo

Beanstalk Silo Tokens represent recapitalized [Unripe](https://docs.bean.money/almanac/farm/barn#unripe-assets) asset value from Beanstalk. Holders of Unripe Beans received Beanstalk Silo Tokens at a rate of 1 token per Unripe Bean. Holders of Unripe LP received tokens based on the [Bean Denominated Value](https://docs.pinto.money/resources/glossary#pinto-denominated-value-pdv) (BDV) of their Unripe LP if Beanstalk were fully recapitalized at the time of the snapshot.

Beanstalk Silo Tokens are standard ERC-20 tokens with 6 decimals, identified on-chain as `urBDV`. The total supply of Beanstalk Silo Tokens equals the total Pinto owed to holders: once the contract has received that amount in Pinto, the repayment is complete.

### Earning Pinto

Each [Season](https://docs.pinto.money/resources/glossary#season), when the Pinto supply exceeds 1 billion and the [time-weighted average price](https://docs.pinto.money/responding-to-state/minting) of Pinto is above $1, the protocol distributes a portion of newly minted Pinto to the Beanstalk Silo Payback contract. These Pinto are allocated to Beanstalk Silo Token holders proportional to their share of the total token supply.

For example, if a Farmer holds 1% of all Beanstalk Silo Tokens, they earn 1% of the Pinto distributed to the Beanstalk Silo Payback contract each Season.

Earned Pinto (Pinto that has accrued to a holder but has not yet been claimed) accumulates automatically and does not need to be claimed each Season. Farmers can claim their total Earned Pinto at any time.

### Claiming

To claim Earned Pinto, visit the [Beanstalk Obligations](https://pinto.money/beanstalk) page on the Pinto interface and click **Claim** in the Beanstalk Silo section. Claimed Pinto are sent to the Farmer's wallet.

### Transferring

Beanstalk Silo Tokens can be transferred to another address by clicking **Send** in the Beanstalk Silo section. When tokens are transferred, the protocol automatically checkpoints Earned Pinto for both the sender and the recipient, ensuring that accumulated rewards are preserved and no double-counting occurs.

Beanstalk Silo Tokens held as a [Farm Balance](https://docs.pinto.money/resources/glossary#farm-assets) within the Pinto protocol are also counted toward a Farmer's earning share.


# Contract Accounts

Some Beanstalk holders were contract accounts rather than externally owned accounts (EOAs). Because contract accounts do not automatically exist at the same address across different chains, assets belonging to eligible contract accounts are held in the Contract Payback Distributor on Base until they are claimed.

The Contract Payback Distributor holds all three asset types on behalf of eligible contract accounts: Beanstalk Silo Tokens, Beanstalk Fertilizer, and Beanstalk Pods. Only accounts that were initialized in the Contract Payback Distributor during deployment are eligible to claim.

### Claiming Methods

There are three ways for a contract account to claim its assets:

#### Direct Claim

If the contract account exists at the same address on Base, it can call the Contract Payback Distributor directly to claim all assets to a specified receiver address.

#### Cross-Chain Message

Contract accounts on Ethereum L1 can send a cross-chain message via the L1 Contract Messenger to designate a receiver address on Base. The L1 Contract Messenger verifies that the caller is authorized and forwards the designation to the Contract Payback Distributor on Base via the [Base Superchain bridge](https://docs.base.org/base-chain/network-information/bridges#superbridge). Once the receiver is set, the designated address can call the Contract Payback Distributor to claim the original account's assets.

Safe multisig wallets with version 1.3.0 or later support cross-chain replay and are compatible with this method. Farmers with earlier Safe versions should explore the Direct Claim method by redeploying their Safe at the same address on Base.

#### EIP-7702 Delegation

Accounts that support [EIP-7702](https://eips.ethereum.org/EIPS/eip-7702) code delegation can use it to make their EOA behave as a contract account, allowing them to call the Contract Payback Distributor's Direct Claim function. No special EIP-7702 handling is required in the contract; the delegation simply allows the account to execute the claim transaction.

### What Gets Transferred

When a contract account claims its assets, the Contract Payback Distributor transfers:

* **Beanstalk Silo Tokens** (ERC-20) to the receiver's wallet or [Farm Balance](https://docs.pinto.money/resources/glossary#farm-assets);
* **Beanstalk Fertilizer** (ERC-1155) to the receiver's wallet; and
* **Beanstalk Pods** in the repayment Field to the receiver's account.

Each account can only claim once. After claiming, the account is marked as completed and cannot claim again.

### Contracts

| Contract                            | Type           | Address                                                                                                               |
| ----------------------------------- | -------------- | --------------------------------------------------------------------------------------------------------------------- |
| Contract Payback Distributor (Base) | Proxy          | [0xbA941Af3292c49b585f4EC5C8164c1dfc893EEdC](https://basescan.org/address/0xbA941Af3292c49b585f4EC5C8164c1dfc893EEdC) |
| Contract Payback Distributor (Base) | Implementation | [0xED3Ead9D8b6E57f666E60ccf833f3ed1Be2Dd4c0](https://basescan.org/address/0xED3Ead9D8b6E57f666E60ccf833f3ed1Be2Dd4c0) |
| L1 Contract Messenger (Ethereum)    | —              | [0xD2abd9a7E7F10e3bF4376fb03A07fca729A55b6f](https://etherscan.io/address/0xD2abd9a7E7F10e3bF4376fb03A07fca729A55b6f) |


# Upgradability

This document has been uploaded to Arweave [here](https://arweave.net/AaSqPd4AogBeP70DwUb3Y9v--gLCdOpj6hT8qe-fZ7Y).

***

### PCM

**The Pinto Contract Multisig (PCM)** is the owner of the Pinto contract. The PCM has the exclusive and unilateral ability to upgrade Pinto. It is expected that the PCM transfers ownership of Pinto to the null address, relinquishing these abilities from the PCM as soon as it is prudent to do so.

The PCM is deployed using [Safe](https://safe.global/), the most battle-tested multisig contract on Base. Its m-of-n configuration is 5-of-9. PCM Signers are an anonymous and diverse set of Pinto friends and contributors.

The PCM is address [0x2cf82605402912C6a79078a9BBfcCf061CbfD507](https://basescan.org/address/0x2cf82605402912C6a79078a9BBfcCf061CbfD507) on Base:

{% embed url="<https://app.safe.global/transactions/queue?safe=base:0x2cf82605402912C6a79078a9BBfcCf061CbfD507>" %}

### No Governance

Pinto does not have governance. While Pinto is the first Beanstalk fork, additional development must be completed in order to create a generalized fork system that replaces the need for contract upgrades. In the meantime, limited upgrades to Pinto may be implemented by the Pinto Contract Multisig (PCM), the owner of the Pinto contract.

**The PCM will only make changes to Pinto that:**

* Fix bugs or security vulnerabilities (including dewhitelisting an LP token for which the non-Pinto asset has collapsed);
* Change parameters until 2 weeks after the first time the Pinto supply reaches 500M (*e.g.*, Target Seasons to Catch Up, Pod Rate and L2SR thresholds, Deposit Whitelist, optimal LP PDV distribution, etc.);
* Mint Pinto to fund a bug bounty program according to the schedule [outlined below](#bug-bounty-mint-schedule);
* Add a [Shipping Route](/responding-to-state/minting#shipping-routes) that pays back old Beanstalk holders after the Pinto supply reaches 1 billion ([see details here](/appendix/beanstalk-obligations)); or
* Implement a [Fork Migration System](#fork-migration-system).

### **Bug Bounty Mint Schedule**

The PCM will fund a bug bounty program by minting Pinto according to the following schedule:

* Mint 0 Pinto to fund a bug bounty program until the Pinto supply reaches 10M for the first time;
* Mint 500k Pinto to fund a bug bounty program once the supply reaches 10M for the first time;
* Mint Pinto to top up the bug bounty program to 2M Pinto once the supply reaches 25M for the first time;
* Mint Pinto to top up the bug bounty program to 3M Pinto once the supply reaches 50M for the first time;
* Mint Pinto to top up the bug bounty program to 5M Pinto once the supply reaches 100M for the first time;
* Mint Pinto to top up the bug bounty program to 10M Pinto once the supply reaches 250M for the first time;
* Mint Pinto to top up the bug bounty program to 20M Pinto once the supply reaches 500M for the first time; and
* Mint Pinto to top up the bug bounty program to 30M Pinto once the supply reaches 1B for the first time.

The details of the bug bounty program are at the discretion of the PCM. The PCM has the ability to select a separate committee to operate the bug bounty program on its behalf.

The Pinto Immunefi Committee Multisig (PICM) that custodies the Pinto for bug bounties is address [0xA8d8BD1745bA40D8B673f690c26BeB9440372b8f](https://basescan.org/address/0xA8d8BD1745bA40D8B673f690c26BeB9440372b8f?__cf_chl_tk=3FQQwh3N6Ak_fWpNN4WVSieEEGi71OoHdiGAdXAtlKI-1734812745-1.0.1.1-YqRF.sGFA9gCyDmoVfq36wjGWHGHtT2QUUjkvrRHw7M) on Base:

{% embed url="<https://app.safe.global/transactions/queue?safe=base:0xA8d8BD1745bA40D8B673f690c26BeB9440372b8f>" %}

### **Fork Migration System**

#### **Summary**

Implement a Fork Migration System that allows Farmers to migrate assets from one or more Pinto deployments (Source Pinto) to another (a Destination Pinto) under conditions defined by the Destination Pinto.

#### **Context**

Forks and upgrades both allow protocols to be modified:

* Upgrades: Occurs when there is some native mechanism in the software that allows the rules of the existing instantiation of the system to be changed. As there is still only 1 instance of the system, participants are forced into the upgrade.
* Forks: Occurs when a set of participants decide to change the rules of the protocol such that a new instance of the system is created. Each participant has the option to keep using the old system or switch to the new one.

Forks give participants complete agency while upgrades minimize fragmentation.

A powerful property of governance in networks like Bitcoin and Ethereum is that there is a guarantee that the rules of the system will not change without participants opting into the changes. Bitcoin miners who did not update their software to Bitcoin Cash remained on Bitcoin. Ethereum nodes that did not update their software to facilitate the fork that reorganized Ethereum post-DAO hack remained on ETH Classic. When juxtaposed against smart contract upgrades, where the rules can be changed for participants who did not opt into it, social consensus seems preferable for a base money.

Furthermore, because smart contracts do not have a strong relationship with network validators, it is harder for smart contracts to coordinate a reorganization via social consensus in the instance of a flaw (e.g., Ethereum did not reorganize post-2022 Beanstalk exploit). Therefore, even though there is friction in the form of lost network effects, it seems the optimal governance model for smart contracts is to make them non-upgradable and to make migrating to future implementations (or forks) as frictionless as possible such that there can be a Lindy effect around safe implementations to use without slowing down innovation.

While this solution likely creates more overhead for developers to support backward compatibility, it also provides more similar properties for users of smart contracts as it does for users of systems based on social consensus.

#### Problem

*Counting Votes*

It is unclear how to count votes in the fairest way possible. Because of the ability to use infinite addresses, without a unique identity system there is no way to ensure that each participant only votes once.

Therefore, the only viable option for voting in smart contract-based governance for contracts with value stored in them is for the weights in participation in governance to be value-based in some capacity (e.g., the Stalk System). While the Stalk System is designed to dampen the effect of participants with more value in the system, it's imperfect with respect to ownership concentration.

There do not seem to be constructions of on-chain voting systems that are battle-tested with significant value in them, and the primary problem with a DAO-based system is that it allows the majority to force changes (or a lack of changes) on the minority.

*Forks*

As is stands, there is significant friction involved in migrating assets from one Pinto deployment to another version of Pinto. Without a standard interface and system for migrations between forks, any Destination Pinto that would like to accept migrations would have to implement a bespoke solution based on approving the Destination Pinto to spend Farmer's Source Pinto assets.

#### Solution

The Fork Migration System allows Farmers to migrate assets from one or more Source Pinto to a Destination Pinto under conditions defined by the Destination Pinto.


# Disclosures

This document is kept up to date, but a version was uploaded to Arweave prior to the deployment of Pinto [here](https://arweave.net/AZYRdhsRn8FPacI2kh4fw75NeoCmavZ0F4yq0HX2r08).

**Before interacting with Pinto, consider reading the following disclosures.**

Pinto is an experiment and interacting with it involves many risks. Before interacting with Pinto, you should review the relevant documentation to make sure you understand how Pinto works, as well as information about the current state of Pinto. The following disclosures are not exhaustive. The [whitepaper](https://pinto.money/pinto.pdf), this GitBook and participating in discussion in the [Pinto community](https://pinto.money/discord) can help to understand the protocol. Before participating in the protocol, everyone should do their own research, investigation and analysis.

#### **1. PINTO IS AN ITERATION AND FORK OF BEANSTALK. THE PINTO VALUE TARGET MAINTENANCE MECHANISM IS VERY SIMILAR TO BEANSTALK'S, WITH SOME EXCEPTIONS.** <a href="#beanstalk-fork" id="beanstalk-fork"></a>

Pinto was inspired by [Beanstalk](https://bean.money). The performance of Beanstalk and other algorithmic stablecoin\
implementations provided invaluable information that influenced the design of Pinto. A significant\
portion of the Pinto codebase was forked from the Beanstalk codebase. Ultimately, this means that the  target maintenance mechanism and implementation of Pinto closely resemble those of Beanstalk. Both the Pinto and Beanstalk target maintenance mechanisms are experiments and have many risks (see [#4](#no-lender-of-last-resort), [#5](#no-price-guarantee) and [#6](#no-maturity-date-risk)).

A non-exhaustive list of the contract changes made to Pinto since the most recent version of Beanstalk are documented [here](/resources/audits).

#### **2. THERE IS NO MAXIMUM PINTO SUPPLY. THE PINTO SUPPLY CAN GROW INFINITELY THROUGH DEMAND-BASED AND ONE-OFF MINTING.** <a href="#no-maximum-supply" id="no-maximum-supply"></a>

The Pinto supply increases every Season where the liquidity and time weighted average price of 1 Pinto is greater than $1 over the previous Season. Enough Pinto are minted such that if all the newly minted Pinto were sold, the price would return to $1 (with the exception of mints related to the [gm reward](#gm-incentivization-risk) and [Flood](/responding-to-state/flood)). The distribution of new Pinto is documented [here](/responding-to-state/minting#shipping-routes).

The Pinto supply is uncapped and grows as demand for Pinto increases. Pinto can also be minted arbitrarily in a one-off fashion (see [#3](#no-pre-mine)).

More information:

* [Pinto Mint Distribution](/responding-to-state/minting#shipping-routes)

#### **3. PINTO DID NOT HAVE A PRE-MINE OR PRE-SALE. ALL PINTO HAVE BEEN MINTED IN ACCORDANCE WITH EITHER THE MINTING SCHEDULE OR ONE-OFF MINTS PERMITTED IN THE UPGRADABILITY DOCS.** <a href="#no-pre-mine" id="no-pre-mine"></a>

Pinto did not have a pre-mine or pre-sale of any kind. The first 1000 Pinto were minted when the `init` function was called to deploy the protocol. Pinto launched without the need to raise capital.&#x20;

Apart from demand-based minting, Pinto can also be minted in a one-off fashion according to the permitted upgrades in the [Upgradability](/appendix/upgradability) docs.

More information:

* [Permitted Pinto Upgrades](/appendix/upgradability)

#### **4. PINTO RELIES ON THIRD PARTIES TO PROVIDE CREDIT TO RETURN THE PINTO PRICE TO ITS VALUE TARGET. THERE IS NO LENDER OF LAST RESORT.** <a href="#no-lender-of-last-resort" id="no-lender-of-last-resort"></a>

Pinto uses a credit based model, allowing anyone to lend Pinto to the protocol to participate in target maintenance. The protocol burns any Pinto it borrows. As a consequence, the ability of the protocol to return the price of Pinto to its target relies on the availability of willing creditors, which is not guaranteed. The economic design of Pinto fails if it can no longer attract creditors.

More information:

* [Field Documentation](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto)

#### **5. THE PROTOCOL DOES NOT GUARANTEE THE PINTO PRICE. INSTEAD THE PROTOCOL INCENTIVIZES THE REGULAR OSCILLATION OF THE PINTO PRICE ABOVE AND BELOW ITS VALUE TARGET THROUGH PROTOCOL-NATIVE INCENTIVES.** <a href="#no-price-guarantee" id="no-price-guarantee"></a>

Pinto is not collateralized and the protocol offers no guarantee of the value of Pinto. Pinto is in an early stage and various parts of its economic design will continue to be improved through forks (see [Fork Migration System](/appendix/upgradability#fork-migration-system)).

The protocol tries to incentivize the regular oscillation of the Pinto price above and below its target. While the protocol's incentives are designed to return the price of Pinto to its target, the timing of oscillations is indeterminate. The price will almost never be exactly equal to its value target. Crossing the target in the past is no guarantee of it happening again in the future.

More information:

* [Target Maintenance Documentation](/responding-to-state/classifying-state)

#### **6. PINTO-NATIVE DEBT DOES NOT HAVE A MATURITY DATE AND THEREFORE MAY NEVER BECOME REDEEMABLE FOR PINTO.** <a href="#no-maturity-date-risk" id="no-maturity-date-risk"></a>

The protocol borrows Pinto from lenders in exchange for Pods. Pinto loans have fixed interest rates but do not have fixed maturity dates.

Pods are repaid when the time weighted average price of 1 Pinto is greater than $1 over the previous Season, but there is no guarantee this will continue until all Pods become redeemable (see [#4](#no-lender-of-last-resort)).

More information:

* [Economics Documentation](/why-pinto/economic-principles)

#### **7. THE PINTO CONTRACT IS OWNED BY THE PINTO CONTRACT MULTISIG. THE MULTISIG CAN MAKE ARBITRARY CHANGES TO PINTO WITH 5-OF-9 SIGNATURES FROM THE ANONYMOUS SIGNERS. THERE IS NO GUARANTEE THE MULTISIG SOLELY ENACTS THE UPGRADES PERMITTED IN THE UPGRADABILITY DOCS.** <a href="#multisig-risk" id="multisig-risk"></a>

Ownership of the Pinto contract is held by a 5-of-9 multisig known as the Pinto Contract Multisig (PCM). There is no guarantee the PCM solely enacts the upgrades permitted in the [Upgradability docs](/appendix/upgradability).&#x20;

More information:

* [Permitted Pinto Upgrades](/appendix/upgradability)

#### **8. A VULNERABILITY IN ETHEREUM OR BASE COULD RESULT IN A LOSS OF FUNDS. PINTO ASSUMES THE SECURITY OF ETHEREUM AND BASE.** <a href="#network-risk" id="network-risk"></a>

Ethereum is the largest smart contract blockchain by market capitalization, total value deposited, and dollar denominated transaction value. Base is one of the largest Ethereum L2s by TVL. In general, open source networks with large amounts of value on them and long track records indicate security, but there is no guarantee. Pinto assumes the security of Ethereum and Base.

#### **9. A VULNERABILITY IN PINTO EXCHANGE OR ITS COMPONENTS COULD RESULT IN A LOSS OF FUNDS. PINTO ASSUMES THE SECURITY OF PINTO EXCHANGE AND ITS CORRESPONDING COMPONENTS.** <a href="#pinto-exchange-risk" id="pinto-exchange-risk"></a>

Pinto trade in Wells on the [Pinto Exchange](https://pinto.exchange). Well LP tokens are whitelisted in the Silo and used by the protocol to determine how many Pinto and/or Soil to mint. Pinto Exchange and the corresponding components that Pinto uses (the Constant Product 2 Well Function, the Stable 2 Well Function, the Well Implementation, Multi Flow, etc.) were [audited](https://docs.pinto.exchange/resources/audits) (as [Basin](https://basin.exchange)). There is no guarantee that Pinto Exchange or its components are secure. Pinto assumes the security of Pinto Exchange and its corresponding components.

More information:

* [Pinto Exchange Docs](https://docs.pinto.exchange)

#### **10. A VULNERABILITY IN PIPELINE COULD RESULT IN A LOSS OF FUNDS. PINTO ASSUMES THE SECURITY OF PIPELINE.** <a href="#pipeline-risk" id="pipeline-risk"></a>

Through Pinto, users can perform complex, gas-efficient interactions with other Base-native protocols, like Pipeline. Pipeline is a sandbox contract allows anyone to perform an arbitrary series of actions in the EVM in a single transaction.

Pipeline has been [audited](https://github.com/BeanstalkFarms/Beanstalk-Audits?tab=readme-ov-file#ecosystem-reports), but there is no guarantee that Pipeline is secure. Pinto assumes the security of Pipeline.

More information:

* [Pipeline Whitepaper](https://evmpipeline.org/pipeline.pdf)
* [Depot Documentation](/pinto-mechanics/toolshed/depot)

#### **11. THE PINTO PRICE IS DERIVED FROM THE VALUE OF ASSETS IT TRADES AGAINST IN DECENTRALIZED AMMS. THERE IS NO GUARANTEE ANY OF THESE ASSETS RETAIN VALUE.** <a href="#non-pinto-asset-risk" id="non-pinto-asset-risk"></a>

The value of Pinto is derived from the non-Pinto assets (WETH, cbETH, cbBTC, WSOL and USDC) trading against it in decentralized liquidity pools. Each of these assets have their own set of associated risks, unique to the asset. Pinto implicitly assumes risk associated with these assets.

#### **12. BECAUSE PINTO DERIVE THEIR VALUE FROM THE ASSETS THEY TRADE AGAINST, AND NOT COLLATERAL, IT IS NOT POSSIBLE FOR ALL PINTO HOLDERS TO EXIT AT A DOLLAR OF VALUE FOR EVERY PINTO.** <a href="#not-everyone-can-exit-at-a-dollar" id="not-everyone-can-exit-at-a-dollar"></a>

Pinto are not redeemable for any other asset; they can only be traded for another asset that Pinto are trading against. As Pinto holders sell their Pinto, there is less and less value trading against Pinto. Thus, unlike collateralized stablecoins, it is not possible for the Pinto supply to scale down to zero with every Pinto holder getting a dollar of value for every Pinto sold.

#### **13. PINTO REQUIRES TRUSTLESS AND RELIABLE ACCESS TO A MANIPULATION RESISTANT PRICE ORACLE FOR A DOLLAR. PINTO USES A CHAINLINK DATA FEED TO DETERMINE THE PRICE OF A DOLLAR. THERE IS RISK ASSOCIATED WITH CHAINLINK THAT CAN COMPROMISE ITS INTEGRITY AS AN ACCURATE PRICE ORACLE.** <a href="#oracle-risk" id="oracle-risk"></a>

Pinto's core objective is to oscillate the price of a Pinto above and below its $1 target. To do this, the protocol must be able to reliably measure the price of a dollar on-chain without trusting a centralized third-party to provide it. A disruption in the reliability of various Chainlink data feeds could impact Pinto minting, resulting in adverse consequences for the protocol.

More information:

* [Price Oracle Documentation](/responding-to-state/classifying-state#decentralized-price-oracle)

#### **14. PINTO REQUIRES THAT THE GM FUNCTION IS CALLED AT THE TOP OF EACH HOUR ON BASE. FAILURE TO SUCCESSFULLY INCENTIVIZE THE CALLING OF THE GM FUNCTION COULD HAVE AN ADVERSE AFFECT ON THE PROTOCOL'S ABILITY TO OSCILLATE THE PINTO PRICE ABOVE AND BELOW ITS VALUE TARGET.** <a href="#gm-incentivization-risk" id="gm-incentivization-risk"></a>

Pinto and/or Soil are minted upon a successful call of the gm function. The protocol covers the cost of the gm function by awarding the sender of an accepted gm function call with newly minted Pinto. The failure of the protocol to successfully incentivize the calling of gm would effectively result in the failure of the protocol to influence the size of the Pinto supply, and thereby the Pinto price.

More information:

* [Sun Documentation](/pinto-mechanics/sun-the-source-of-life-on-the-farm)

#### **15. THE PINTO CONTRACTS ARE OPEN SOURCE. ANYONE CAN VIEW THE SOURCE CODE AND ATTEMPT TO FIND VULNERABILITIES.** <a href="#open-source-risk" id="open-source-risk"></a>

The Pinto contracts are open source and deployed on Base. There may be bugs, flaws, or other unintended consequences from using open source code to govern irreversible financial transactions on a decentralized network. These issues may lead to a loss of funds if present and discovered by malicious actors.

More information:

* [Pinto on GitHub](https://github.com/pinto-org/protocol)

#### **16. PINTO IS AUDITED BUT AUDITS CANNOT GUARANTEE SECURITY. IT IS ANTICIPATED THAT FUTURE CODE WILL NOT BE AUDITED BEFORE BEING COMMITTED.** <a href="#audit-risk" id="audit-risk"></a>

Security is paramount to Pinto's success. The version of Pinto currently deployed on Base is heavily audited (via [Beanstalk](https://docs.bean.money/almanac/protocol/audits)), but there is no guarantee that Pinto is secure.

In the future, it is anticipated that the code will be upgraded per the [Upgradability documentation](/appendix/upgradability). There is always additional risk associated with implementing any new code.

There is no guarantee that interacting with Pinto through the Pinto UI is secure. Any issues could lead to a loss of funds.

More information:

* [Beanstalk Audits](https://docs.bean.money/almanac/protocol/audits)
* [Permitted Pinto Upgrades](/appendix/upgradability)

#### **17. THE PINTO USER INTERFACE CAN BE CENSORED AS IT IS HOSTED ON A CLOUD PROVIDER.** <a href="#ui-provider-risk" id="ui-provider-risk"></a>

The Pinto UI hosted at [pinto.money](https://pinto.money) is hosted on Netlify, a privately held United States based cloud provider. Netlify could censor the UI at will, or a technical disruption could prevent access. In either scenario, Pinto would not be accessible from a web browser until contributors could deploy the UI elsewhere, or other parties could use the open source code to deploy their own UI to interact with the Pinto contracts.

There have been multiple instances of Netlify getting compromised, resulting in phishing attacks. There is no guarantee that the Pinto UI will not be subjected to similar attacks.

More information:

* [Pinto UI on GitHub](https://github.com/pinto-org/interface)

#### **18. THE PINTO USER INTERFACE DEPENDS ON VARIOUS DATA PROVIDERS FOR DISPLAYING ONCHAIN DATA. THERE IS NO GUARANTEE THAT THE DATA FROM THESE PROVIDERS IS ACCURATE OR AVAILABLE.** <a href="#data-provider-risk" id="data-provider-risk"></a>

The Pinto UI hosted at [pinto.money](https://pinto.money) depends on Alchemy, 0x, the Pinto Subgraph Proxy and the Pinto Subgraphs for displaying various onchain data.

The Pinto UI uses:

* Alchemy, a privately held United States based RPC provider, to query various onchain data;
* 0x, a privately held United States based exchange API provider, to get swap quotes and route trades efficiently;
* the Pinto Subgraph Proxy, hosted on Digital Ocean, a public United States based cloud provider, to route traffic between multiple different subgraphs; and
* the Pinto Subgraphs, hosted on Alchemy and the Graph Network.

Any of these companies could censor access to data or a technical disruption could prevent access altogether.

#### **19. REGULATORY INTEREST IN STABLECOINS AND DECENTRALIZED FINANCE WILL RESULT IN NEW INDUSTRY REGULATIONS. THE IMPACT OF FUTURE REGULATIONS ON PINTO IS UNCERTAIN.** <a href="#regulatory-risk" id="regulatory-risk"></a>

In alignment with the ethos of DeFi, Pinto has been designed to be permissionless and censorship resistant, without the requirement for any trust-providing intermediary.

It is unclear what regulations, if any, governments will attempt to impose on DeFi. Therefore, it is impossible to predict how any new government regulations of DeFi will affect Pinto, or any of the protocols or networks Pinto relies on as part of its ecosystem.[<br>](https://docs.bean.money/almanac)


# Glossary

#### **Blight Factor** <a href="#convert" id="convert"></a>

The value adjusted by a gauge that changes the Mown Stalk penalty for Converting Deposited Pinto to Deposited LP tokens. Read more [here](https://pinto.money/pinto.pdf#subsubsection.12.3.2).

#### **Convert** <a href="#convert" id="convert"></a>

Changing one Deposited asset for another within the [Silo](/pinto-mechanics/silo-the-perfect-complement-to-credit). Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit/converts-changing-price-from-within).

#### Convert Down Bonus (Stalk Bonus)

A static Stalk bonus for a Convert down (Pinto → LP), currently 0 under all circumstances. Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives).

#### Convert Up Penalty (Stalk Penalty)

A static penalty of 100% of Stalk accumulated from Seeds upon a Convert up (LP → Pinto) above $1. Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives).

#### Crop Ratio <a href="#crop-ratio" id="crop-ratio"></a>

The ratio of [Seed](#seeds) rewards between Pinto and the LP token with the highest [Gauge Points](#gauge-points) per [PDV](#pinto-denominated-value). Adjusted via the [Gauge System](#seed-gauge-system). Determines the relative benefits of holding Pinto exposure vs exposure to the LP token with the most Seeds in the Silo over time. Read more [here](/responding-to-state/crop-ratio-changes).

#### Cultivation Factor

The value adjusted by a gauge that causes the Soil issued to increase as Pinto is Sown into all Soil, and decrease otherwise. Read more [here](https://pinto.money/pinto.pdf#subsubsection.12.3.1).

#### Cultivation Temperature

The Maximum Temperature from the last Season in which Soil either sold out entirely or almost sold out and demand for Soil was steady or increasing. It is used to prevent instances where the protocol gets stuck oscillating the Maximum Temperature downward and the Cultivation Factor upward, and the Maximum Temperature upward and the Cultivation Factor downward. Read more [here](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance#elements-of-the-cultivation-system).

#### Cultivation System

Determines Soil issuance every Season relative to the maximum number of Soil the protocol would be willing to issue given its current state and infinite demand for Soil. It has three elements: the Cultivation Factor, the Cultivation Temperature, and two manipulation resistant thresholds to determine whether Soil sold out or almost Sold out in the previous Season. Read more [here](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance).

#### **deltaP (**∆&#x50;**)** <a href="#deltap" id="deltap"></a>

The shortage or excess of Pinto in a liquidity pool that Pinto trades in. TWA∆P is the time-weighted version of ∆P.

#### Delta Demand <a href="#delta-demand" id="delta-demand"></a>

The ratio of the change in [Soil](#soil) Sown into over the prior two [Seasons](#season). Used to measure Demand for Soil.

#### **Deposit** <a href="#deposit" id="deposit"></a>

Assets on the [Deposit Whitelist](#deposit-whitelist) can be Deposited in the [Silo](#silo) at any time to earn [Stalk](#stalk) and [Seeds](#seeds). Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit#deposit-whitelist).

#### **Deposit Whitelist** <a href="#deposit-whitelist" id="deposit-whitelist"></a>

The whitelist of ERC-20 tokens that can be Deposited in the [Silo](#silo). See the Deposit Whitelist [here](/resources/contracts#current-deposit-whitelist).

#### **Depot** <a href="#depot" id="depot"></a>

The component of the [Toolshed](#toolshed) that facilitates interactions with other protocols in a single transaction. Read more [here](/pinto-mechanics/toolshed/depot).

#### Dynamic Convert Down Penalty

A dynamic fraction of Stalk accumulated from Seeds burned upon a Convert down (Pinto → LP), defined [here](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives#dynamic-convert-down-penalty).

#### Dynamic Convert Up Bonus

A dynamic Stalk bonus per PDV Converted upon a Convert up (LP → Pinto). Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives#dynamic-convert-up-bonus).

#### Dynamic Convert Bonus and Penalty System

A mechanism that instantly credits a Stalk bonus or burns a portion of Stalk accumulated from Seeds on a Deposit upon Convert, as part of the target maintenance mechanism. It comprises four levers:

1. Dynamic Convert Down Penalty (Stalk Penalty)
2. Dynamic Convert Up Bonus (Stalk Bonus)
3. Convert Up Penalty (Stalk Penalty)
4. Convert Down Bonus (Stalk Bonus).

Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit/dynamic-convert-bonus-and-penalty-system-fine-tuned-convert-incentives).

#### **Earned Pinto** <a href="#earned-pinto" id="earned-pinto"></a>

Pinto that have been paid to a Stalkholder since the last Season they [Planted](#plant) their [Plantable Seeds](#plantable-seeds) (Claimed). Upon Plant, Earned Pinto are [Deposited](#deposit).

#### **Earned Stalk** <a href="#earned-stalk" id="earned-stalk"></a>

[Stalk](#stalk) earned from [Earned Pinto](#earned-pinto). Earned Stalk automatically contribute to Stalk ownership and do not require any action to claim them.

#### **Farm** <a href="#farm" id="farm"></a>

The Pinto ecosystem. The Farm has four primary components: the [Sun](#sun), [Silo](#silo), [Field](#field) and [Toolshed](#toolshed). Read more [here](/pinto-mechanics/mechanics-overview).

#### **Farm Balance** <a href="#farm-assets" id="farm-assets"></a>

Balances stored in the Pinto protocol (but not Deposited, in Pod Orders, etc.). Farm Balances can be used in transactions on the [Farm](#farm) and may be more gas efficient than [Wallet Balances](#wallet-balance). Read more [here](/pinto-mechanics/toolshed/farm-balances).

#### **Farmers** <a href="#farmers" id="farmers"></a>

Users of Pinto.

#### **Field** <a href="#field" id="field"></a>

The Pinto credit facility. Read more [here](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto).

#### **FIFO** <a href="#fifo" id="fifo"></a>

First in, first out. [Pods](#pods) become [Harvestable](#harvestable-pods) (redeemable for Pinto) on a FIFO basis. This means that Pods closer to the front of the [Pod Line](#pod-line) become Harvestable before Pods farther back in the Pod Line. Read more [here](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto#creating-a-competition-to-lend-to-pinto).

#### **Flood** <a href="#flood" id="flood"></a>

If it is [Raining](#rain) and the [Pod Rate](#pod-rate) is less than 3% (Excessively Low), at gm there is a Flood. At the beginning of a Season where it Floods, additional Pinto are minted and sold directly into pools on the [Flood Whitelist](#flood-whitelist). Read more [here](/responding-to-state/flood).

#### Flood Whitelist

The whitelist of liquidity pools that the protocol evaluates whether to sell Pinto into or not during a [Flood](#flood). Read more [here](/responding-to-state/flood#current-flood-whitelist).

#### Gauge Points <a href="#gauge-points" id="gauge-points"></a>

Used by the [Gauge System](#seed-gauge-system) to determine [Grown Stalk](#grown-stalk) issuance across LP tokens on the [Deposit Whitelist](#deposit-whitelist).

#### Germination <a href="#germination" id="germination"></a>

Germinating [Deposits](#deposit) are Deposits that are less than 2 [gm](#gm) calls old. Germinating Deposits can be [Withdrawn](#withdraw) or transferred, but cannot be [Converted](#convert). Germination exists to add flash loan and inter-block MEV manipulation resistance to the calculation of Deposited PDV. By preventing the accrual of [Earned Pinto](#earned-pinto) for 1 full [Season](#season), the protocol further disincentivizes inorganic demand.

#### **gm** <a href="#gm" id="gm"></a>

The protocol accepts one gm function call every [Season](#season). Upon the gm call, the protocol adjusts the Pinto supply and various incentives to facilitate low volatility. Read more [here](/pinto-mechanics/sun-the-source-of-life-on-the-farm).

#### **Grown Stalk** <a href="#grown-stalk" id="grown-stalk"></a>

[Stalk](#stalk) earned from [Seeds](#seeds). Grown Stalk does not contribute to Stalk ownership until it is [Mown](#mow) (Claimed). Mow can be called on its own, and it is also called at the beginning of any [Silo](#silo) interaction ([Depositing](#deposit), [Withdrawing](#withdraw), [Converting](#convert), etc.).

#### **Harvest** <a href="#harvest" id="harvest"></a>

Redeem Harvestable Pods for 1 Pinto each.

#### **Harvestable Pods** <a href="#harvestable-pods" id="harvestable-pods"></a>

[Pods](#pods) that are redeemable for 1 Pinto each. Harvestable Pods must be Harvested in order to use them.

#### Liquidity Rate (a.k.a. Liquidity to Supply Ratio or L2SR) <a href="#liquidity-to-supply-ratio-l2sr" id="liquidity-to-supply-ratio-l2sr"></a>

Represents the the Pinto liquidity level relative to the Pinto supply. The Liquidity Rate is a useful indicator of the protocol's health. Read more [here](/responding-to-state/classifying-state#liquidity-level).

#### Liquidity Weight <a href="#liquidity-weight" id="liquidity-weight"></a>

The portion of liquidity in a whitelisted liquidity pool that counts towards the [Liquidity to Supply Ratio](#liquidity-to-supply-ratio-l2sr) calculation.

#### Maximum Temperature <a href="#maximum-temperature" id="maximum-temperature"></a>

The maximum [Temperature](#temperature) the protocol is willing to offer during a [Season](#season). Read more [here](/responding-to-state/temperature-changes).

#### Minting Whitelist <a href="#minting-whitelist" id="minting-whitelist"></a>

The whitelist of liquidity pools whose TWA∆P's are summated to calculate a total TWA∆P. Read more [here](/pinto-mechanics/sun-the-source-of-life-on-the-farm#minting-whitelist).

#### Morning <a href="#morning" id="morning"></a>

The first 10 minutes of each [Season](#season) where the [Temperature](#temperature) approaches the [Maximum Temperature](#maximum-temperature).

#### **Mow** <a href="#mow" id="mow"></a>

Mowing (Claiming) [Grown Stalk](#grown-stalk) adds it to your [Stalk](#stalk) balance. Called upon any interaction with the [Silo](#silo).

#### **Pinto Denominated Value (PDV)** <a href="#pinto-denominated-value-pdv" id="pinto-denominated-value-pdv"></a>

The value of an asset denominated in Pinto. Used to calculate how many [Stalk](#stalk) and [Seeds](#seeds) are rewarded to Depositors of an asset in the [Silo](#silo). Abbreviated as PDV.

#### **Pinto** <a href="#pinto" id="pinto"></a>

The low volatility money protocol that issues Pinto. Also used to refer to the ERC-20 token.

#### **Pinto Contract Multisig (PCM)** <a href="#pcm" id="pcm"></a>

The multisig that custodies ownership of the Pinto contract. Abbreviated as PCM. Read more [here](/appendix/upgradability).

#### **Pipeline** <a href="#pipeline" id="pipeline"></a>

A sandbox contract that can execute an arbitrary number of actions within the EVM from an EOA in a single transaction. Forked from [evmpipeline.org](https://evmpipeline.org).

#### **Plant** <a href="#plant" id="plant"></a>

Planting (Claiming) adds [Plantable Seeds](#plantable-seeds) to your total [Seed](#seeds) balance.

#### **Plantable Seeds** <a href="#plantable-seeds" id="plantable-seeds"></a>

[Seeds](#seeds) earned in conjunction with [Earned Pinto](#earned-beans). Plantable Seeds must be [Planted](#plant) in order to grow [Stalk](#stalk).

#### **Plot** <a href="#plot" id="plot"></a>

[Pods](#pods) that grow from Pinto that were [Sown](#sow) in the same transaction form a Plot.

#### **Pod Line** <a href="#pod-line" id="pod-line"></a>

The order in which [Pods](#pods) will become [Harvestable](#harvest) based on the FIFO Harvest schedule.

#### **Pod Listing** <a href="#pod-listing" id="pod-listing"></a>

An offer to sell [Pods](#pods) on the [Pod Market](#pod-market). Read more [here](/pinto-mechanics/toolshed/pod-market#pod-listings).

#### **Pod Market** <a href="#pod-market" id="pod-market"></a>

The decentralized, trustless market that [Pods](#pods) can be bought and sold on. Read more [here](/pinto-mechanics/toolshed/pod-market).

#### **Pod Order** <a href="#pod-order" id="pod-order"></a>

An order to buy [Pods](#pods) on the [Pod Market](/pinto-mechanics/toolshed/pod-market). Read more [here](/pinto-mechanics/toolshed/pod-market#pod-orders).

#### **Pod Rate** <a href="#pod-rate" id="pod-rate"></a>

The protocol debt level (Pod supply) relative to the Pinto supply. The Pod Rate is often used as a proxy for the protocol's health. Read more [here](/responding-to-state/classifying-state#debt-level).

#### **Pods** <a href="#pods" id="pods"></a>

The Pinto-native debt asset, redeemable for 1 Pinto each once they become [Harvestable](#harvest). Read more [here](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto#pods).

#### Rain

At the beginning of a [Season](#season) where TWA∆P > 0 and [Pod Rate](#pod-rate) < 3% (Excessively Low), it is Raining.

#### **Season** <a href="#season" id="season"></a>

Seasons are Pinto-native time. Every Season is approximately 1 hour. Each Season begins when the [gm](#gm) function is successfully called on Base. Read more [here](/pinto-mechanics/sun-the-source-of-life-on-the-farm).

#### Seed Gauge System <a href="#seed-gauge-system" id="seed-gauge-system"></a>

The component of the [Silo](#silo) responsible for dynamically adjusting the [Seed](#seeds) rewards for different assets whitelisted in the Silo. Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit/optimizing-liquidity-distribution-via-the-seed-gauge-system).

#### **Seeds** <a href="#seeds" id="seeds"></a>

An illiquid token that yields 1/10000 [Grown Stalk](#grown-stalk) every [Season](#season).

#### **Silo** <a href="#silo" id="silo"></a>

The Pinto Deposit facility. Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit).

#### **Soil** <a href="#soil" id="soil"></a>

The current number of Pinto that can be Sown in exchange for [Pods](#pods). Read more [here](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto#soil).

#### **Sow** <a href="#sow" id="sow"></a>

Lending to the protocol. Used in the context of Sowing Pinto, or lending Pinto to the protocol when there is [Soil](#soil).

#### **Stalk** <a href="#stalk" id="stalk"></a>

An illiquid token that entitles the holder to a pro rata share of future Pinto mints. Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit).

#### **Stalkholders** <a href="#stalkholders" id="stalkholders"></a>

Holders of the [Stalk](#stalk) token. Stalkholders earn Pinto seigniorage.

#### Sun <a href="#sun" id="sun"></a>

The component of the [Farm](#farm) that keeps time in [Seasons](#season) and incentivizes cost-efficient and timely calling of the [gm](#gm) function. Read more [here](/pinto-mechanics/sun-the-source-of-life-on-the-farm).

#### Target Seasons to Catch Up <a href="#target-seasons-to-catch-up" id="target-seasons-to-catch-up"></a>

Determines the target number of [Seasons](#season) for a new [Deposit](#deposit) with an average number of [Seeds](#seeds) to catch up to the average [Grown Stalk](#grown-stalk) per [PDV](#bean-denominated-value) of existing Deposits at the time of Deposit. Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit/optimizing-liquidity-distribution-via-the-seed-gauge-system#the-seed-gauge-step-by-step).

#### **Temperature** <a href="#temperature" id="temperature"></a>

The interest rate for Sowing Pinto. Read more [here](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-field-simply-put#temperature).

#### Toolshed <a href="#toolshed" id="toolshed"></a>

The Toolshed offers a suite of tools for efficient use of Pinto and other Base-native protocols. Read more [here](/pinto-mechanics/toolshed).

#### **Wallet Balance** <a href="#wallet-balance" id="wallet-balance"></a>

Balances in Farmers' wallets. Can be used in the same transaction as [Farm Balances](#farm-assets).

#### **Withdraw** <a href="#withdraw" id="withdraw"></a>

Deposited assets can be Withdrawn from the [Silo](#silo) at any time. The number of [Stalk](#stalk), [Seeds](#seeds), and Stalk from Seeds rewarded for a Deposited asset must be forfeited upon its Withdrawal from the Silo. Read more [here](/pinto-mechanics/silo-the-perfect-complement-to-credit#withdraw).


# How-To Guides

Learn how to use Pinto, step-by-step.

* [Getting Started](/resources/how-to-guides/getting-started)
* [Silo](/resources/how-to-guides/silo)
* [Field](/resources/how-to-guides/field)
* [Trading](/resources/how-to-guides/trading)
* [Balances](/resources/how-to-guides/balances)
* [sPinto](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/37/resources/how-to-guides/spinto)


# Getting Started

Introductory guides on interacting with Pinto.

* [Where to Begin?](https://app.gitbook.com/o/vaU8RboRkIPnZEKgwwZ8/s/E6o3oJ1UvNLq82fMCMG5/~/changes/20/resources/how-to-guides/getting-started/where-to-begin)
* [Connect to Pinto](/resources/how-to-guides/getting-started/connect-to-pinto)
* [Fund a Wallet on Base](/resources/how-to-guides/getting-started/fund-a-wallet-on-base)


# Where to Begin?

**New to Pinto?** Learn the basics by reading about the [primary components of Pinto](/pinto-mechanics/mechanics-overview).

**How do I participate in Pinto's success?** Earn yield through different components of the [Farm](/pinto-mechanics/mechanics-overview):

* **Silo:** Earn yield by [Depositing](/resources/glossary#deposit) whitelisted assets. Silo Deposits earn a portion of new Pinto mints. Learn more [about the Silo](/pinto-mechanics/silo-the-perfect-complement-to-credit) and how to [Deposit in the Silo](/resources/how-to-guides/silo/deposit-in-the-silo).
* **Field:** Earn yield by [Sowing](/resources/glossary#sow) (lending) Pinto to Pinto. Lenders receive [Pods](/resources/glossary#pods), which are placed in a First In, First Out (FIFO) line that earns a portion of new Pinto mints. Pods become [Harvestable](/resources/glossary#harvestable-pods) (redeemable) at an indeterminate future time for a fixed number of Pinto. Learn more [about the Field ](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto)and how to [Sow Pinto](/resources/how-to-guides/field/sow-pinto).
* **Market**: Buy and sell Pinto-native assets and transfer your balances between your wallet and the Pinto protocol. Learn more about [Trading Pinto](/resources/how-to-guides/trading/trading-pinto-native-assets) and [Transferring Balances](/resources/how-to-guides/balances/transferring-balances).

**Ready to use Pinto?** [Connect your wallet to the Pinto UI](/resources/how-to-guides/getting-started/connect-to-pinto) and start farming.

**Have questions?** [Join the Discord](https://pinto.money/discord) to ask anything not covered in the documentation.


# Connect to Pinto

Interacting with Pinto requires a wallet on the [Base network](https://www.base.org/) with an Ethereum (ETH) balance. If you don't have a wallet yet, learn how to [Fund a Wallet on Base](/resources/how-to-guides/getting-started/fund-a-wallet-on-base).

Pinto works with many Base-compatible wallets. Here's how to connect using Rabby as an example, though the process is similar for other wallets.

### **Connect to Pinto with the Rabby Browser Extension** <a href="#connect-to-pinto-with-rabby" id="connect-to-pinto-with-rabby"></a>

1. Visit <https://pinto.money/>.
2. Select 'Connect' in the top right of the page.
3. Click the Rabby Wallet icon in the wallet selector.
4. Select 'Connect'.
5. You are now connected to Pinto. Double check that the wallet address in the top right of <https://pinto.money/> is the same as your wallet address.

   <br>


# Fund a Wallet on Base

Interacting with Pinto requires a wallet on the [Base network](https://www.base.org/) with an Ethereum (ETH) balance.

* [Selecting and Funding a Wallet](#selecting-and-funding-a-wallet)
* [Creating a Wallet on Base with Rabby (Browser Extension)](#creating-a-wallet-on-base-with-rabby-browser-extension)
* [Creating a Wallet on Base with Rabby (Mobile)](#creating-a-wallet-on-base-with-rabby-mobile)
* [Fund your Wallet from Coinbase](#fund-your-wallet-from-coinbase)
* [Bridging from Other Networks](#bridging-from-other-networks)

### **Selecting and Funding a Wallet** <a href="#selecting-and-funding-a-wallet" id="selecting-and-funding-a-wallet"></a>

Wallets are applications that let you manage your assets on the Base network. Your wallet lets you connect to decentralized applications such as Pinto and authorize transactions. On Base, you are responsible for the security of your own funds. If you are new to decentralized finance, it strongly recommend to research best practices in wallet security before proceeding.

Pinto works with many Base-compatible wallets. Some wallets allow purchasing Ethereum directly within the wallet. Alternatively, send Ethereum from a cryptocurrency exchange to your wallet address. Make sure both sending and receiving addresses are on the Base network.

Here's how to fund a wallet using Rabby and Coinbase as an example, though the process is similar for other wallets and exchanges.

### Creating a Wallet on Base with Rabby (Browser Extension)

1. Go to <https://rabby.io/> and select 'Download for Chrome'.
2. You will be taken to the Chrome Web Store where you can select 'Add to Chrome' and approve the installation in your browser.
3. Rabby is now installed and can be opened from your browser's extension menu (the puzzle piece icon in the top right corner).
4. To create a new wallet, select 'Create a new address' and follow the instructions. For better security, you can connect a hardware wallet instead and select 'I already have an address'.
   1. A hardware wallet protects your assets even if your computer is hacked.
   2. The hardware wallet must be supported by Rabby - check the list provided by selecting 'I already have an address'.
5. Never share your seed phrase - anyone who has it can steal your assets. Keep it offline in a secure location, as it's your only way to recover your wallet.
6. To copy your wallet address on Base, open Rabby and select the copy icon: ![](https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/qwAXoI2SjUyLQFJTFaYY/image.png)

### Creating a Wallet on Base with Rabby (Mobile)

1. Download Rabby from the [App Store](https://apps.apple.com/us/app/rabby-wallet-crypto-evm/id6474381673) or [Google Play](https://play.google.com/store/apps/details?id=com.debank.rabbymobile\&hl=en_US).
2. To create a new wallet, select 'Create New Address' and follow the instructions. For better security, you can connect a hardware wallet instead and select 'I already have an address'.
   * A hardware wallet protects your assets even if your device is hacked.
   * The hardware wallet must be supported by Rabby - check the list provided by selecting 'I already have an address'.
3. Never share your seed phrase - anyone who has it can steal your assets. Keep it offline in a secure location, as it's your only way to recover your wallet.
   * If you opt for cloud backup, your wallet can be accessed by anyone who has both your cloud account credentials and the encryption password.
4. To connect to an app such as Pinto, select 'Dapps' and enter the URL (e.g. <https://pinto.money>) in the in-app browser.
5. To copy your wallet address on Base, select 'Receive', then select the displayed address.

### Fund your Wallet from Coinbase

1. Buy Ethereum on Coinbase before transferring it to your wallet. See Coinbase documentation for purchase instructions.
2. Go to <https://www.coinbase.com/assets>.
3. Select 'Send crypto'.
4. Click the "Send" arrow and type 'Ethereum'.
5. Enter the amount to send in USD, or click the switch icon to enter it in Ethereum instead.
6. Click the 'To' arrow and under 'Send via' select 'Base'.
7. Under 'Send Ethereum on Base to' enter your wallet address on Base.
8. Select 'Preview Send' then 'Send'.
9. You have funded your wallet and are now ready to [Connect to Pinto](/resources/how-to-guides/getting-started/connect-to-pinto).

### Bridging from Other Networks

Bridging has security risks, so research and evaluate third-party services before using them.

1. Go to <https://jumper.exchange/> and select 'Connect' to connect your wallet.
2. Under 'From' select the network and asset you want to bridge to Base.
3. Under 'To' select Base and the Pinto-native asset you plan to use with Pinto.
   * Jumper will exchange between the input and output asset as well as performing the network bridge.
4. Under "Receive," select a bridging provider and verify that the output amount provides acceptable execution.
5. Select 'Review Bridge' and 'Start Bridging' to prompt the approval and bridging transactions to your wallet.
   * If you haven't used your wallet on Base before and you're bridging assets other than ETH, you may need to bridge some ETH separately to cover gas fees while using Pinto.


# Silo

Guides on interacting with the [Silo](/pinto-mechanics/silo-the-perfect-complement-to-credit).

* [Deposit in the Silo](/resources/how-to-guides/silo/deposit-in-the-silo)
* [Withdraw from the Silo](/resources/how-to-guides/silo/withdraw-from-the-silo)
* [Claim Silo Rewards](/resources/how-to-guides/silo/claim-silo-rewards)
* [Convert in the Silo](/resources/how-to-guides/silo/convert-in-the-silo)
* [Combine Deposits](/resources/how-to-guides/silo/combine-deposits)
* [Bridge WSOL from Solana](/resources/how-to-guides/silo/bridge-wsol-from-solana)<br>


# Deposit in the Silo

Assets on the [Deposit Whitelist](/resources/contracts#current-deposit-whitelist) can be [Deposited](/resources/glossary#deposit) in the [Silo](/pinto-mechanics/silo-the-perfect-complement-to-credit) to earn [Stalk](/resources/glossary#stalk) and [Seeds](/resources/glossary#seeds).&#x20;

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Silo' page. At the bottom of the page, there is a table showing the various assets on the Deposit Whitelist.
3. Select the asset you want to Deposit.
4. Select the 'Deposit' tab.
5. There is a drop down menu to select the token you would like to Deposit.
   * Deposits may be made in any Pinto-native asset and will be converted as part of the transaction using [Pinto Exchange](https://pinto.exchange/).
6. Enter the amount you want to Deposit. A transaction preview showing the Stalk and Seeds to be rewarded will appear below the inputs.
7. You may select a slippage tolerance by selecting the gear icon. The default slippage tolerance is 0.5%.
   * The transaction will revert if it doesn't meet the specified conditions.
8. If an approval is not necessary, skip to Step 10. For all other cases, select 'Approve Spending'. This allows the Pinto contract to spend the asset, but does not Deposit it yet.
9. Confirm the approval transaction in your wallet, and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
10. Select 'Deposit'.
11. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
12. After the transaction has been confirmed by the network, your Deposit will appear in the 'My Deposits' table on the current page.


# Withdraw from the Silo

The associated amount of Stalk, Seeds, and Stalk from Seeds from a given Deposit must be forfeited when the Deposit is Withdrawn from the Silo. You can find more information about Withdrawals [here](/pinto-mechanics/silo-the-perfect-complement-to-credit#withdraw).

1. Make sure you are on <https://pinto.money/> and [connect your wallet](https://docs.pinto.money/guides/getting-started/connect-to-pinto).
2. Navigate to the 'Silo' page. At the bottom of the page, there is a table showing the various assets on the [Deposit Whitelist](/resources/contracts#current-deposit-whitelist).
3. Select the asset you want to Withdraw. You must already have a Deposit of this asset in order to Withdraw.
4. Select the 'Withdraw' tab and enter the amount of the Deposited asset you would like to Withdraw. You may Withdraw any amount up to your 'Total' shown below the input box.
5. Under 'Destination', select '[Wallet Balance](/resources/glossary#wallet-balance)' or '[Farm Balance](/resources/glossary#farm-assets)'. Selecting Wallet Balance returns Withdrawn assets to your wallet. Selecting Farm Balance keeps the asset stored in Pinto.
6. A transaction preview showing the decrease in Stalk and Seeds will appear below the inputs.
7. Select 'Withdraw'.
8. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](https://docs.pinto.money/resources/contracts) before signing it.
9. After the transaction has been confirmed by the network, the location of your assets will depend on the option selected in Step 5:
   * If 'Wallet Balance' was selected, the assets will be in your wallet.
   * If 'Farm Balance' was selected, view your balances by selecting your wallet address in the upper right, then select 'Farm Balance'.
   * If your Withdraw was a liquidity pool token, you can unwrap it to the underlying assets by selecting the 'Unwrap via Pinto Exchange' button.


# Claim Silo Rewards

Assets on the [Deposit Whitelist](/pinto-mechanics/silo-the-perfect-complement-to-credit#deposit-whitelist) can be Deposited in the Silo to earn Silo Rewards. You can find more information about Silo Rewards [here](/pinto-mechanics/silo-the-perfect-complement-to-credit#silo-rewards).

* [Claim Pinto, Stalk, and Seeds](#claim-pinto-stalk-and-seeds)
* [Claim Flood Distributions](#claim-flood-distributions)

### Claim Pinto, Stalk, and Seeds

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Overview' page. If you have earned Silo Rewards, they will appear as a 'Claimable' row at the top of the 'My Deposits' table. If you haven't earned any rewards yet, this row won't be shown.
3. Select 'Claim Pinto, Stalk, and Seed' next to the Claimable row.
   * \[Mobile only] Select 'Claim Yield' at the bottom of the page.
4. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
5. After the transaction has been confirmed by the network, your Silo Rewards will be added to the balances in the 'My Deposits' table on the current page.

### Claim Flood Distributions

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. In the upper right corner, select your wallet address. If you have Flood distributions, the amount will be shown under 'Claim from Flood'.
3. Select an option under 'Receive proceeds to' then 'Claim from Flood'.
   * Selecting [Wallet Balance](/resources/glossary#wallet-balance) sends the Flood distributions to your wallet.&#x20;
   * Selecting [Farm Balance](/resources/glossary#farm-assets) keeps the distributions stored in Pinto.
4. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
5. After the transaction has been confirmed by the network, the location of your assets will depend on the option selected in Step 3:
   * If 'Wallet Balance' was selected, the assets will be in your wallet.
   * If 'Farm Balance' was selected, view your balances by selecting your wallet address in the upper right, then select 'Farm Balance'.


# Convert in the Silo

Farmers can participate in target maintenance by Converting certain Deposited assets to others within the Silo. You can find more information about [Converts](/pinto-mechanics/silo-the-perfect-complement-to-credit/converts-changing-price-from-within) here.

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Silo' page. At the bottom of the page, there is a table showing the various assets on the [Deposit Whitelist](/resources/contracts#current-deposit-whitelist).
3. Select the asset you want to Convert from. For example, to Convert from Pinto to another asset, select Pinto. You must already have a Deposit of this asset in order to Convert from it. Assets may or may not be convertible at a given time based on [deltaP](/resources/glossary#deltab).  See [Converts](/pinto-mechanics/silo-the-perfect-complement-to-credit/converts-changing-price-from-within) for additional information.
4. Select 'Convert' and enter the amount of the Deposited asset you would like to Convert.
5. If you are Converting from Pinto to an LP token, select the asset to Convert to.
6. A transaction preview will appear below the inputs showing the change in asset and change in [Stalk](/resources/glossary#stalk) and [Seeds](/resources/glossary#seeds).
7. You may select a slippage tolerance by selecting the gear icon. The default slippage tolerance is 0.1%.
8. Select 'Convert'.
9. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
10. After the transaction has been confirmed by the network, your Converted Deposit will appear on the 'Silo' page for the asset you Converted to under the 'My Deposits' table.


# Combine Deposits

Combining Deposits will merge them into a single Deposit. While this can reduce gas fees for future Silo transactions, it comes with a tradeoff: your Stalk gets averaged across the combined Deposits. As a result, withdrawing from the Silo will burn more Stalk than if you had kept the Deposits separate.

Note: Combining is not available yet on the mobile UI.

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Silo' page. At the bottom of the page, there is a table showing the various assets on the [Deposit Whitelist](/resources/contracts#current-deposit-whitelist).
3. Select the asset you want to combine. You must already have multiple Deposits of this asset in order to combine.
4. Select 'Combine Deposits'.
5. Pick which Deposits you want to combine, or use 'Select All' to combine all Deposits of this asset.
6. Check that the number shown in the 'Combine Deposits' button matches the Deposits you want to combine, then select to proceed.
7. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
8. After the transaction has been confirmed by the network, your combined Deposit will appear in the 'My Deposits' table on the current page.


# Bridge WSOL from Solana

WSOL liquidity on Base is [limited](https://basescan.org/token/0x1c61629598e4a901136a81bc138e5828dc150d67), which may result in worse price execution if exchanging for WSOL on Base. To avoid this, you can mint new WSOL on Base by bridging SOL directly from the Solana network using the Portal Bridge.

Bridging has security risks, so research and evaluate third-party services before using them.

* [Moving Funds from Base to Solana](#moving-funds-from-base-to-solana)
* [Bridging SOL Using the Portal Bridge](#bridging-sol-using-the-portal-bridge)

### Moving Funds from Base to Solana

1. Go to <https://portalbridge.com/> and in the 'From' selector, choose 'Base'.
2. In the 'To' selector, choose 'Solana'.
3. Select 'Connect source wallet' and 'Connect destination wallet' to connect your Base and Solana wallets. If you do not have a Solana wallet yet, [Phantom](https://phantom.app/) is a popular choice.
4. Choose which token you want to send through the Portal Bridge under the 'From' selector and which token to receive under the 'To' selector:
   * If sending and receiving different tokens, e.g. ETH to SOL or USDC to SOL, Portal Bridge will use [Mayan Swift](https://docs.mayan.finance/architecture/swift) to perform the exchange. There is a nominal fee for this method and it is subject to potential exchange slippage.
   * If sending USDC to USDC, you will have the choice under 'Routes' to use Mayan Swift or [Mayan MCTP](https://docs.mayan.finance/architecture/mctp). Mayan MCTP uses [Circle CCTP](https://www.circle.com/en/cross-chain-transfer-protocol) to bridge. There are no protocol fees for this method and you can choose any exchange once on Solana to swap the USDC to SOL, such as [Jupiter](https://jup.ag/).
5. Enter the amount to send and confirm the bridging details under 'Routes'.
6. Approve (if applicable), review and confirm the bridging transaction. After confirmation, you will now have SOL in your Solana wallet.

### Bridging SOL Using the Portal Bridge

1. Go to <https://portalbridge.com/> and in the 'From' selector, choose 'Solana' and 'SOL'.
2. In the 'To' selector, choose 'Base' and 'WSOL''.
3. Select 'Connect source wallet' and 'Connect destination wallet' to connect your Solana and Base wallets.
4. Enter the amount of SOL to send and confirm the bridging details under 'Routes'.
5. Review and confirm the bridging transaction. After confirmation, you will now have WSOL in your Base wallet.
   * Because of the relative low quantity of WSOL on Base, some wallets may not show your balance. View your WSOL balance by connecting to <https://pinto.money/> and selecting your wallet address in the upper right.


# Field

Guides on interacting with the [Field](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto).

* [Sow Pinto](/resources/how-to-guides/field/sow-pinto)
* [Harvest Pods<br>](/resources/how-to-guides/field/harvest-pods)


# Sow Pinto

When there is [Soil](/resources/glossary#soil) in the [Field](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto), Farmers can lend their Pinto to the protocol for an interest rate known as the [Temperature](/responding-to-state/temperature-changes).

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Field' page.
3. The amount of Pinto that can be Sown for Soil is shown under 'Available Soil'. Pods will be issued in accordance with the 'Current Temperature'.
   * The Soil supply is set by the Pinto target maintenance mechanism. See [The Cultivation System: Optimal Soil Issuance](/pinto-mechanics/field-the-most-innovative-lending-facility-in-crypto/the-cultivation-system-optimal-soil-issuance) for additional information.
   * During the first ten minutes of each Season, the Temperature ramps from 1% to 100% of the Maximum Temperature in a Dutch auction known as the Morning Auction.
4. Select the 'Sow' tab.
5. There is a dropdown menu to select the token you would like to use to buy and Sow Pinto.
6. Note: For Sowing in sizes greater than the available Soil in a given Season, farmers can setup recurring Sows via [Tractor](/pinto-mechanics/toolshed/tractor-automating-the-farm) – see [here](https://x.com/pintodotmoney/status/1914728533320237207). **Since the introduction of the Cultivation System, which increased the scarcity of Soil every Season, a Tractor Order is likely a farmer's best option to Sow.**
7. Enter the amount of the selected token you want to use to buy and Sow Pinto.
   * The Soil available when preparing to buy and Sow Pinto may not still be available at the time the transaction is confirmed by the network.&#x20;
   * If a transaction is submitted to Sow a greater amount of Soil than is available, the remaining Soil will be Sown, and all remaining Pinto from the transaction will be sent to your [Farm Balance](/resources/glossary#farm-assets).
   * If you are Sowing during the Morning Auction, the number of Pods to be received will increase in real time on the UI with the increasing Temperature.
   * The actual amount of Pods you receive depends upon Soil availability and the Temperature at the time your transaction is confirmed.
8. You may select a slippage tolerance or minimum acceptable Temperature by selecting the gear icon. The default slippage tolerance is 0.1%.
   * The transaction will revert if it doesn't meet the specified conditions.
9. If an approval is not necessary, skip to Step 10. For all other cases, select 'Approve Spending'. This allows the Pinto contract to spend the asset, but does not use it yet.
10. Confirm the approval transaction in your wallet, and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
11. Select 'Sow'.
12. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
13. After the transaction has been confirmed by the network, your Pods will appear in the 'My Pods' table at the bottom of the 'Field' page.


# Harvest Pods

Once [Pods](/resources/glossary#pods) reach the front of the [Pod Line](/resources/glossary#pod-line), they become [Harvestable](/resources/glossary#harvestable-pods). Harvestable Pods are redeemable for 1 Pinto each.

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Field' page.
3. Select the 'Harvest' tab, which shows how many Pods you can convert into Pinto through Harvesting.
4. Under 'Destination', select '[Wallet Balance](/resources/glossary#wallet-balance)' or '[Farm Balance](/resources/glossary#farm-assets)'. Selecting Wallet Balance sends the Pinto to your wallet. Selecting Farm Balance keeps the Pinto stored within the protocol.
5. Select 'Harvest'.
6. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
7. After the transaction has been confirmed by the network, the location of the Pinto from your Harvestable Pods will depend on the option selected in Step 4:
   * If 'Wallet Balance' was selected, the Pinto will be in your wallet.&#x20;
   * If 'Farm Balance' was selected, view your balances by selecting your wallet address in the upper right, then select 'Farm Balance'.


# Trading

Guides on trading and transferring Pinto-native assets.

* [Trading Pinto-Native Assets](/resources/how-to-guides/trading/trading-pinto-native-assets)
* [Buy Pods](/resources/how-to-guides/trading/buy-pods)
* [Sell Pods](/resources/how-to-guides/trading/sell-pods)<br>


# Trading Pinto-Native Assets

Pinto and Pinto-native assets can be bought and sold on the [Swap](https://pinto.money/swap) page. To transfer between Wallet and Circulating balances, see [Transferring Balances](/resources/how-to-guides/balances/transferring-balances).

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Swap' page.
3. In the first field select the input token, or the asset you would like to sell. The dropdown menu will show each available input token and your total Wallet Balance and Farm Balance.
   * [Wallet Balance](/resources/glossary#wallet-balance) is the balance in your wallet, separate from Pinto.
   * [Farm Balance](/resources/glossary#farm-assets) is the balance stored within the Pinto protocol.
4. In the second field, select the output token, or the asset you would like to buy.
5. Enter the amount of the input token to sell, up to the amount held in your Wallet and Farm balances.
6. Verify the amount of the output token you will receive in the 'Buy' field.
7. Under 'Destination', select 'Wallet Balance' or 'Farm Balance'.
8. You may select a slippage tolerance by selecting the gear icon. The default slippage tolerance is 0.1%.
9. If an approval is not necessary, skip to Step 11. For all other cases, select 'Approve Spending'. This allows the Pinto contract to spend the token, but does not execute the trade yet.
10. Confirm the approval transaction in your wallet, and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
11. Select 'Swap'.
12. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
13. After the transaction has been confirmed by the network, the location of your assets will depend on the option selected in Step 7:
    * If 'Wallet Balance' was selected, the assets will be in your wallet.
    * If 'Farm Balance' was selected, view your balances by selecting your wallet address in the upper right, then select 'Farm Balance'.


# Buy Pods

Pods can be exchanged in a trustless fashion on the Pod Market. Read [Pod Market](/pinto-mechanics/toolshed/pod-market) first for an introduction to Pod Market mechanics, [Pod Listings](/resources/glossary#pod-listing) and [Pod Orders](/resources/glossary#pod-order).

* [Fill Pod Listing](#fill-pod-listing)
* [Order Pods](#order-pods)

Note: The Pod Market is not available yet on the mobile UI.

### Fill Pod Listing <a href="#fill-pod-listing" id="fill-pod-listing"></a>

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Pod Market' page.
3. Open Pod Listings appear below the 'Listings' tab. This view displays all the Pod Listings, sorted by ascending [Place in Line](/resources/glossary#pod-line).
   * The 'Amount' is the number of Pods left to be purchased from the Pod Listing.
   * The 'Place in Line' is the position in the Pod Line when the Pods in the Pod Listing will start to become Harvestable.
   * The 'Price' is the number of Pinto requested per Pod.
   * If the Pod Line moves forward by the amount in the 'Expires In' field, the Pod Listing will automatically expire.
4. Select a Pod Listing to view details and to buy Pods from a Pod Listing.
5. Under the 'Fill Using' component, select the token you would like to use to buy Pods, and enter the amount you would like to buy. You may buy up to the 'Amount' of Pods available from the Pod Listing.
6. A transaction preview will appear below the inputs.
7. You may select a slippage tolerance by selecting the gear icon. The default slippage tolerance is 0.1%.
8. If an approval is not necessary, skip to Step 10. For all other cases, select 'Approve Spending'. This allows the Pinto contract to spend the asset, but does not use it yet.
9. Confirm the approval transaction in your wallet, and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
10. Select 'Buy Pods'.
11. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
12. After the transaction has been confirmed by the network, your Pods will appear in the 'My Pods' table at the bottom of the 'Field' page.

### Order Pods <a href="#order-pods" id="order-pods"></a>

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Pod Market' page.
3. Select 'Buy Pods'. 'Order' is selected by default, allowing you to create a Pod Order.
   * 'I want to order Pods with a Place in Line up to' is the maximum [Place in Line](/resources/glossary#pod-line) at which you are willing to buy Pods at the specified price. Any Pods at a lower Place in Line than the maximum Place in Line will be eligible to Fill the Pod Order.
   * 'Amount I am willing to pay for each Pod' is how much you will pay for each Pod, denominated in Pinto.
   * 'Order Using' specifies the amount and the asset to be used to buy Pods. This amount will be locked in the Pod Order to allow for instant settlement. Pod Orders may be partially filled.
4. A transaction preview will appear below the inputs.
5. You may select a slippage tolerance by selecting the gear icon. The default slippage tolerance is 0.1%.
6. If an approval is not necessary, skip to Step 8. For all other cases, select 'Approve Spending'. This allows the Pinto contract to spend the asset, but does not use it yet.
7. Confirm the approval transaction in your wallet, and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
8. Select 'Order Pods'.
9. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
10. After the transaction has been confirmed by the network, your Pod Order will be shown on the 'Pod Market' page under the 'My Activity' tab, where you can check the status of your Pod Order or cancel it.


# Sell Pods

Pods can be exchanged in a trustless fashion on the Pod Market. Read [Pod Market](/pinto-mechanics/toolshed/pod-market) first for an introduction to Pod Market mechanics, [Pod Listings](/resources/glossary#pod-listing) and [Pod Orders](/resources/glossary#pod-order).

* [List Pods](#list-pods)
* [Fill Pod Order](#fill-pod-order)

Note: The Pod Market is not available yet on the mobile UI.

### List Pods <a href="#list-pods" id="list-pods"></a>

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Pod Market' page.
3. Select 'Sell Pods' then select the 'List' tab.
   * The 'Select Plot' dropdown shows all your Plots. Select the Plot that has the Pods you would like to List and enter the number of Pods to List.
   * 'Amount I want for each Pod' is how much to sell each Pod for, denominated in Pinto.
   * If the Pod Line moves forward by the amount in 'Expires In', the Pod Listing will automatically expire.
4. Under 'Send proceeds to', select 'Wallet Balance' or 'Farm Balance'. Selecting Wallet Balance sends the proceeds to your wallet. Selecting Farm Balance keeps the proceeds stored in Pinto.
5. A transaction preview will appear below the inputs.
6. Select 'List Pods'.
7. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
8. After the transaction has been confirmed by the network, your Pod Listing will be shown on the 'Pod Market' page under the 'My Activity' tab, where you can check the status of your Pod Listing or cancel it.
9. When your Pod Listing is filled, the location of your Pinto will depend on the option selected in Step 4:
   * If 'Wallet Balance' was selected, the Pinto will be in your wallet.
   * If 'Farm Balance' was selected, view your balances by selecting your wallet address in the upper right, then select 'Farm Balance'.

### Fill Pod Order <a href="#fill-pod-order" id="fill-pod-order"></a>

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Navigate to the 'Pod Market' page.
3. Select 'Sell Pods' then select the 'Fill' tab. This view displays all the active Pod Orders, sorted by ascending [Place in Line](/resources/glossary#pod-line).
   * 'Amount' is the number of Pods left to be sold to the Pod Order.
   * Any Pods within the Pod Line range listed under 'Place in Line' are eligible to be sold to the Pod Order.
   * The 'Price' is the number of Pinto offered per Pod.
4. Select a Pod Order to view details or to sell Pods to a Pod Order.
5. Under the 'Fill' modal, select the Plot you would like to use to Fill the Pod Order, and enter the number of Pods you would like to sell. You may sell up to the 'Amount' to the Pod Order.
6. Under 'Destination', select 'Wallet Balance' or 'Farm Balance'. Selecting Wallet Balance sends the proceeds to your wallet. Selecting Farm Balance keeps the proceeds stored in Pinto.
7. A transaction preview will appear below the inputs.
8. Select 'Sell Pods'.
9. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
10. After the transaction has been confirmed by the network, the location of your proceeds will depend on the option selected in Step 6:
    * If 'Wallet Balance' was selected, the Pinto will be in your wallet.
    * If 'Farm Balance' was selected, view your balances by selecting your wallet address in the upper right, then select 'Farm Balance'.


# Balances

Guides on managing your Pinto balances.

* [Send Tokens](/resources/how-to-guides/balances/send-tokens)
* [Transferring Balances](/resources/how-to-guides/balances/transferring-balances)


# Send Tokens

You can transfer Deposits, Pods, and tokens from your Farm Balance between Base addresses. When transferring Deposits, you'll keep all your Stalk and Seeds.

To transfer assets between [Wallet Balance](/resources/glossary#wallet-balance) and [Farm Balance](/resources/glossary#farm-assets), see [Transferring Balances](/resources/how-to-guides/balances/transferring-balances).

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Select your wallet address in the upper right, then select 'Send'.
3. Select which tokens to send or 'Send Everything'.&#x20;
   * If you are not sending all the the tokens held by the connected address, select which Deposits, Pods, or Farm Balance tokens to send.
4. Enter the Base address where the tokens will be sent.
5. Under 'Confirm send', review the tokens to be sent and the receiving address for accuracy.
6. Select 'Send'.
7. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
8. Connect the receiving wallet to Pinto after the transaction is confirmed to view your sent tokens.


# Transferring Balances

The Transfer Tokens field can be used to transfer tokens between your [Wallet Balance](/resources/glossary#wallet-balance) and [Farm Balance](/resources/glossary#farm-assets).

To send Pinto assets to another Base address, see [Send Tokens](/resources/how-to-guides/balances/send-tokens).

1. Make sure you are on <https://pinto.money/> and [connect your wallet](/resources/how-to-guides/getting-started/connect-to-pinto).
2. Select your wallet address in the upper right, then select 'Manage Farm Balance'.
3. Use the ⇅ button to switch between sending from Wallet Balance to Farm Balance, or from Farm Balance to Wallet Balance.
4. Select the token and enter the amount you want to send in the 'Amount and Token to Transfer' field.
5. If an approval is not necessary, skip to Step 7. For all other cases, select “Approve Spending”. This allows the Pinto contract to spend the token, but does transfer it yet.
6. Confirm the approval transaction in your wallet, and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
7. Select “Transfer”.
8. Confirm the transaction in your wallet and your hardware wallet, if applicable. You should verify that the transaction is interacting with the [correct contract](/resources/contracts) before signing it.
9. After the transaction has been confirmed by the network, the location of your assets will depend on the direction of the transfer.
   * If the destination was 'Wallet Balance', the assets will be in your wallet.
   * If the destination was 'Farm Balance', view your balances by selecting your wallet address in the upper right, then select 'Farm Balance'.


# sPinto

Step by step guides on how to mint and use sPinto across various ecosystem integrations.

* [Wrap/Unwrap sPinto](/resources/how-to-guides/spinto/wrap-unwrap-spinto)
* [Borrow against sPinto on Cream Finance](/resources/how-to-guides/spinto/borrow-against-spinto-on-cream-finance)
* [Trade sPinto yield on Spectra](/resources/how-to-guides/spinto/trade-spinto-yield-on-spectra)


# Wrap/Unwrap sPinto

This guide will walk you through the steps to wrap and unwrap sPinto using Pinto Silo Deposits or any supported ERC20 token.

Siloed Pinto (sPINTO) is a fungible Pinto Deposit wrapper that captures Silo yield. It leverages the ERC-20 and [ERC-4626](https://erc4626.info/) standards to achieve composability in the DeFi ecosystem and provide utility for Pinto outside of the core protocol. For more information on how sPinto works check out [sPinto: Composing Pinto with DeFi](/pinto-mechanics/toolshed/spinto-composing-pinto-with-defi)

### Wrap

To get sPinto and start earning yield follow the steps below:

* Go to <https://pinto.money/wrap>
* On the left, choose how you wish to use to wrap sPinto. By pressing the toggle, you can wrap from silo deposits or any ERC20.&#x20;
* If you choose to unwrap to an ERC20, In the backend the interface will unwrap your token to Pinto and swap it for the token you choose.
* You can also wrap your existing Pinto silo deposits into sPinto. Note that Stalk is socialized among sPinto holders and not returned in equal proportion when unwrapping. Therefore, users wrapping sPinto directly from Silo Deposits should be wary of the Stalk cost of using older Deposits. If you wish to wrap your existing deposits, the UI will pick the deposits with the least amount of grown stalk to use.
* Here we will use USDC to buy Pinto and wrap it directly.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/UDyEr0FXz6YCMD5WBUVn/image.png" alt="" width="375"><figcaption></figcaption></figure>

* Click on "Approve" to approve your tokens or Deposits for spending.
* Choose the destination where you wish to receive the token. Wallet or Farm balance.
* Click on "Wrap" to get sPinto.

You can now start earning Silo yield by holding sPinto or use it across various DeFi protocols. For guides on how to achieve this see:&#x20;

* [Borrow against sPinto on Cream Finance](/resources/how-to-guides/spinto/borrow-against-spinto-on-cream-finance)
* [Trade sPinto yield on Spectra](/resources/how-to-guides/spinto/trade-spinto-yield-on-spectra)

### Unwrap

If you wish to unwrap sPinto into pinto or any ERC20 token, follow the steps below:

* Go to <https://pinto.money/wrap>
* On the left, choose how you wish to use to unwrap sPinto. By pressing the toggle, you can unwrap to silo deposits or any ERC20.&#x20;
* If you choose to unwrap to an ERC20, In the backend the interface will unwrap your token to Pinto and swap it for the token you choose.&#x20;
* By unwrapping sPinto into a Silo Deposit you can start managing your Silo positions directly. Here, we will unwrap and swap to USDC.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/okaJafR8DUJhCiOfyGBt/image.png" alt="" width="375"><figcaption></figcaption></figure>

* Click on "Approve" to approve your tokens for spending
* Choose the destination where you wish to receive the token. Wallet or Farm balance.
* Click on "Unwrap" to unwrap your sPinto.


# Borrow against sPinto on Cream Finance

This guide will walk you through the steps to borrow and leverage against your sPinto on Cream Finance borrowing and lending markets.

### Step 1: Wrap your pinto into sPinto from the Pinto UI

* Navigate to Pinto UI, go to <https://pinto.money/wrap>, connect your wallet and choose an amount of Pinto to wrap from your existing Silo Deposits. The UI will automatically wrap your Pinto Deposits with the least amount of Grown Stalk.
* If you don’t have Pinto Deposited in the Silo, use any of the available tokens in your wallet and the UI will automatically swap them into Pinto and wrap them into sPinto.
* After approving and wrapping, you should now see sPinto tokens appear in your wallet.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/ZlTi9FSizYKnNDrD6DH2/image.png" alt="" width="375"><figcaption></figcaption></figure>

### Step 2: Borrow USDC against your sPinto on Cream

* Now that you acquired sPinto, lets put it as collateral so you can borrow against it on Cream.
* Go to <https://app.cream.finance/>.
* Connect your wallet and change your network to “Base” on the top right of the screen

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/AYKNnXkQPSXNAus7s5XN/image.png" alt=""><figcaption></figcaption></figure>

* Choose "sPinto" as a supply asset (left) and click on it

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/y1OMIbcKITtVOpHmgGkQ/image.png" alt=""><figcaption></figcaption></figure>

* Choose the amount you wish to supply.
* Click on “Approve” and sign the transaction on the popup.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/BIOiJRx0rjLQMXRlTFgI/image.png" alt="" width="375"><figcaption></figcaption></figure>

* Then click on "Supply" to supply sPinto to the market.
* Next, you need to make your sPinto a collateral asset by clicking on the toggle on the right and signing the required transaction. Wait a few seconds and you should see the toggle turned on.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/UJe4ObJz9RkwoKUar1XA/image.png" alt="" width="563"><figcaption></figcaption></figure>

* Now you are ready to borrow USDC against your sPinto collateral. Choose "USDC" as a borrow asset on the right.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/2lXjIJ03uhNJ4T2s5D8l/image.png" alt="" width="375"><figcaption></figcaption></figure>

* Use the slider to choose a USDC borrow amount.&#x20;
* Note the Borrow APY. This is the interest you would be paying annually for your USDC loan.
* The loan to value ratio max for sPinto is 75%. This means that *if the Pinto price decreases such that your loan is worth more than 75% of your collateral you will get **liquidated***. It also means that you can borrow up to 75% of the USD value of the sPinto being used as collateral. ie $1000 of sPinto can borrow 750 USDC.
* **Collateral Up:** When sPinto accrues value (from new Pinto mints) your collateral value will automatically increase and risk of liquidation decrease. If there are significant mints it will be safe to return and borrow more *without adding additional collateral*.
* **Collateral Down:** sPinto will never decrease in terms of Pinto, but if the Pinto/USD price decreases your collateral will be worth less relative to the USDC loan. This is the only way to get liquidated.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/ZtDAzTYkH0vl7nXsoPx0/image.png" alt="" width="375"><figcaption></figcaption></figure>

* This page lets you set your borrow amount as a percentage *of the maximum borrow amount*. So 75% on this page is \~56% of the value of your collateral (75% max LTV \* 75% borrow). So 75% here means that you will get liquidated if Pinto decreases in value by 25% with no new mints.
* When you’re ready to borrow the USDC just click on “Borrow” and sign the transaction in your wallet.
* You have now borrowed against your sPinto collateral, meaning you are long sPinto while your collateral asset is increasing in value due to silo yield, thus, repaying your loan if the Silo APY is above your loan interest rate.

### Step 3: Repeat to get Leveraged Long sPinto exposure.

* With that USDC loan, you can go and purchase pinto on the pinto UI again <https://pinto.money/swap> and rewrap it into sPinto.
* Then you can supply that sPinto as collateral again on Cream and repeat the same process, meaning you get leveraged exposure to sPinto and sPinto yield.
* The formula to figure out max leverage exposure is `1/(1-LTV)` meaning with an 75% LTV, you could leverage sPinto 4x. Note that this increases liquidation risk meaning if the price of Pinto drops significantly, cream will seize your collateral and sell it, meaning you will incur a loss.

### Notes

#### Borrow sPinto Against any collateral asset on Cream

* If you do the process above in reverse, you can borrow sPinto against some other collateral asset, meaning, you'll be effectively shorting sPinto, with the risk of  your loan increasing in value due to either the sPinto price increasing or sPinto yield being distributed. Be careful when doing this as there these 2 factors might work against you.

#### Borrow interest and kinks

* Keep an eye out on the borrow APY (your loan interest rate). This depends on market utilization of USDC. If utilization goes above 90% (or \~16% interest rate/ borrow APY) then the interest rate skyrockets because of the shape of the interest rate curve and sPinto yield might not be enough to offset this.

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/gZqcLo8NwHdehPFIlx9r/image.png" alt="" width="563"><figcaption></figcaption></figure>

* sPinto utilizes the stable interest rate curve on Cream. For more information visit: <https://docs.cream.finance/lending/interest-rate-model>


# Trade sPinto yield on Spectra

This guide will walk you through the steps to speculate on sPinto yield in Spectra Finance.

Spectra Finance is a decentralized finance (DeFi) protocol that enables users to tokenize and trade future yield, offering options such as fixing interest rates, yield trading, and earning additional returns on liquidity.&#x20;

In this guide we'll walk through:

* How you can get fixed yield for sPinto over a period of time by buying the sPinto PT (principal token).
* How you can get leveraged sPinto yield exposure by buying the sPinto YT  (yield token).
* How to provide liquidity on the sPinto Spectra pool and get exposure to sPinto yield, swap fees and additional incentives.

Note that this guide assumes that you already have sPinto in your wallet. For details on how to get sPinto, see here: [Wrap/Unwrap sPinto](/resources/how-to-guides/spinto/wrap-unwrap-spinto)

For more in-depth explanations about the underlying mechanisms at play, visit the Spectra docs at <https://docs.spectra.finance/>

### Getting Fixed Yield on your sPinto

When "fixing" sPinto yield, you are forfeiting your rights to sPinto yield for a period of time in exchange for a fixed return. This enables you to "lock-in" a guaranteed yield on your sPinto regardless of the underlying Silo yield. Note that you are still exposed to the price of Pinto when doing that as the sPinto price is denominated in Pinto.&#x20;

Here is how to achieve this:

* Go to the fixed rate page on the spectra app <https://app.spectra.finance/fixed-rate>
* Choose Base as the chain.
* Choose "sPinto" as the pool and click on it.&#x20;

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/LMkSbKg7rp7Sleg9amdT/image.png" alt=""><figcaption></figcaption></figure>

* Choose an input token to use. In this case, you can fix yield using plain Pinto or sPinto directly.
* In the output section, you should see:&#x20;

  * How much of the PT (Principal token) you are getting. PT tokens:
    * Represent the initial deposit, also known as the principal.
    * Redeemable 1:1 for underlying at maturity; trading at a discount until maturity, provided no negative yield.
    * Adhere to the ERC-20 token standard.
  * How much yield you''ll get at maturity.
  * The implied APY you are getting for that period of time.&#x20;

  <figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/TtMyRwkKKCw2S3uOT5qD/image.png" alt="" width="375"><figcaption></figcaption></figure>
* Click on "Fix Rate" and sign the transaction in your wallet.
* You have now successfully "fixed" sPinto yield for a period of time. You will be able to redeem your PT for Pinto at maturity.
* If you wish to redeem earlier, you''ll have to sell your PT for regular sPinto in the liquidity pool. To do so, you just need to click on "Exit Position" on the same page. Note that you may incur slippage from trading when performing that action.

### Get leveraged sPinto yield exposure

When getting leveraged sPinto yield exposure you are buying the rights to the yield of a certain amount of sPinto for a period of time. If the actual yield ends up being higher than the price you paid to get it, you will make a profit. However if the yield turns out to be lower over that period of time, you will incur a loss. This strategy has more inherent risk due to the volatile nature of pinto silo yield but can produce outsized returns in the case of a pinto growth cycle over that period of time.&#x20;

Here is how to achieve this:

* Go to the yield leverage page on the spectra app <https://app.spectra.finance/trade-yield>.
* Choose base as the chain.
* Choose "sPinto" as the pool and click on it.&#x20;

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/MSF94bQkhxxPwebN7rWh/image.png" alt=""><figcaption></figcaption></figure>

* Choose an input token to use. In this case, you can leverage yield using plain Pinto or sPinto directly.
* In the output section, you should see:&#x20;

  * How much of the sPinto  YT (Yield token)  you are getting. YT tokens:
    * Represent the right to future yield
    * Accrue yield for its holder
    * The value of the YT itself heads toward 0 until the expiry date
    * Adheres to ERC-20 token standard; freely transferable
  * How much leveraged yield exposure you'll get when buying the sPinto YT token.
  * The implied APY at which you are buying the YT. A lower value means the future yield is being bought for cheap.

  <figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/rj3YafBFDVJeIEE13cVb/image.png" alt="" width="375"><figcaption></figcaption></figure>
* Click on "Get Yield Leverage" and sign the transaction in your wallet.
* You have now successfully earned rights to leveraged sPinto yield for a period of time. You will be able to claim your yield as it comes in your portfolio page: <https://app.spectra.finance/portfolio>.
* If you wish to exit your position earlier, you can do that in the "Exit Position" tab on the same page you bought the YT in.

### Provide Liquidity on the sPinto Spectra Pool

sPinto PTs and YT are traded via a Curve stableswap liquidity pool with the ratios in the pool determining the price of the tokens and thus, the underlying yield. To facilitate trading, you can provide liquidity on the sPinto spectra pool and earn swap fees and sPinto yield exposure. Pools are comprised of sPinto and the sPinto PT token. Due to the nature of the protocol, impermanent loss when providing liquidity on spectra is negligible. Read more on why this is the case here: <https://docs.spectra.finance/the-basics/faq>

* Go to the pool page on the spectra app <https://app.spectra.finance/pools>
* Choose base as the chain.
* Choose "sPinto" as the pool and click on it.&#x20;

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/WiatFK1yCi3grDAfXjTN/image.png" alt=""><figcaption></figcaption></figure>

* Choose an input token to use. In this case, you can LP using plain Pinto or sPinto directly.
* In the output section, you should see:&#x20;

  * How much of the LP token you are getting. LP tokens:
    * Represent the number of liquidity provider (LP) tokens you receive in exchange for your deposit. These tokens are proof of your share in the pool and can be used to redeem your portion of the pool's assets, plus any accrued swap fees.
  * How much of the YT token you are getting.
    * Yield Tokens result from the yield tokenization process; however, they are not part of the pool composition. LP token holders remain entitled to fees from Yield Token (YT) swaps as they are driven by flash swaps utilizing the pool. Read more about output composition when providing liquidity in the Spectra FAQs here: <https://docs.spectra.finance/the-basics/faq#pool-creation>
    * You can sell YTs (subject to slippage) or continue earning sPinto yield by holding them.
  * How much of the pool share you will own.
  * New implied APY as a result of adding liquidity.

  <figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/bpWZQdtbDAC0n0NQhiAf/image.png" alt="" width="375"><figcaption></figcaption></figure>
* Click on "Add Liquidity" and sign the transaction in your wallet.
* You have now successfully provided liquidity for the sPinto Spectra pool. You will be able to redeem your LP tokens for sPinto at any time. In the meantime, you will be earning yield from fees and sPinto YT if you keep it. Keep track of all of your positions at the portfolio tab here: <https://app.spectra.finance/portfolio>
* If you wish to remove liquidity earlier than maturity just go to the same page where you added the liquidity in the "Remove" tab and specify how much of the LP tokens you want to redeem.


# Contracts

### Pinto <a href="#pinto" id="pinto"></a>

<table><thead><tr><th width="282">Contract</th><th>Base Address</th></tr></thead><tbody><tr><td>Pinto Protocol</td><td><a href="https://basescan.org/address/0xD1A0D188E861ed9d15773a2F3574a2e94134bA8f">0xD1A0D188E861ed9d15773a2F3574a2e94134bA8f</a></td></tr><tr><td>Pinto ERC-20 Token</td><td><a href="https://basescan.org/address/0xb170000aeeFa790fa61D6e837d1035906839a3c8">0xb170000aeeFa790fa61D6e837d1035906839a3c8</a></td></tr></tbody></table>

### Current Deposit Whitelist

<table><thead><tr><th width="236">Contract</th><th>Base Address</th><th>Optimal Distribution</th></tr></thead><tbody><tr><td>PINTO</td><td><a href="https://basescan.org/address/0xb170000aeeFa790fa61D6e837d1035906839a3c8">0xb170000aeeFa790fa61D6e837d1035906839a3c8</a></td><td>N/A</td></tr><tr><td>PINTO:cbETH LP</td><td><a href="https://basescan.org/address/0x3e111115A82dF6190e36ADf0d552880663A4dBF1">0x3e111115A82dF6190e36ADf0d552880663A4dBF1</a></td><td>⅓ of LP</td></tr><tr><td>PINTO:cbBTC LP</td><td><a href="https://basescan.org/address/0x3e11226fe3d85142B734ABCe6e58918d5828d1b4">0x3e11226fe3d85142B734ABCe6e58918d5828d1b4</a></td><td>⅓ of LP</td></tr><tr><td>PINTO:USDC LP</td><td><a href="https://basescan.org/address/0x3e1133aC082716DDC3114bbEFEeD8B1731eA9cb1">0x3e1133aC082716DDC3114bbEFEeD8B1731eA9cb1</a></td><td>⅓ of LP</td></tr></tbody></table>

### **DeWhitelisted Pools**

<table><thead><tr><th width="236">Contract</th><th>Base Address</th></tr></thead><tbody><tr><td>PINTOWETH LP</td><td><a href="https://basescan.org/address/0x3e11001CfbB6dE5737327c59E10afAB47B82B5d3">0x3e11001CfbB6dE5737327c59E10afAB47B82B5d3</a></td></tr><tr><td>PINTOWSOL LP</td><td><a href="https://basescan.org/address/0x3e11444c7650234c748D743D8d374fcE2eE5E6C9">0x3e11444c7650234c748D743D8d374fcE2eE5E6C9</a></td></tr></tbody></table>

### Facets <a href="#facets" id="facets"></a>

Pinto is a [ERC-2535 Diamond](https://eips.ethereum.org/EIPS/eip-2535). You can explore the current list of Pinto facets on Louper, an interface for inspecting Diamonds.

{% embed url="<https://louper.dev/diamond/0xD1A0D188E861ed9d15773a2F3574a2e94134bA8f?network=base>" %}

### Non-Pinto Assets <a href="#non-bean-assets" id="non-bean-assets"></a>

<table><thead><tr><th width="219">Contract</th><th>Base Address</th></tr></thead><tbody><tr><td>WETH</td><td><a href="https://basescan.org/address/0x4200000000000000000000000000000000000006">0x4200000000000000000000000000000000000006</a></td></tr><tr><td>cbETH</td><td><a href="https://basescan.org/address/0x2Ae3F1Ec7F1F5012CFEab0185bfc7aa3cf0DEc22">0x2Ae3F1Ec7F1F5012CFEab0185bfc7aa3cf0DEc22</a></td></tr><tr><td>cbBTC</td><td><a href="https://basescan.org/address/0xcbB7C0000aB88B473b1f5aFd9ef808440eed33Bf">0xcbB7C0000aB88B473b1f5aFd9ef808440eed33Bf</a></td></tr><tr><td>USDC</td><td><a href="https://basescan.org/address/0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913">0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913</a></td></tr><tr><td>WSOL</td><td><a href="https://basescan.org/address/0x1C61629598e4a901136a81BC138E5828dc150d67">0x1C61629598e4a901136a81BC138E5828dc150d67</a></td></tr></tbody></table>

### sPinto

| Contract Name         | Address                                                                                                               |
| --------------------- | --------------------------------------------------------------------------------------------------------------------- |
| sPinto Token          | [0x00b174d66adA7d63789087F50A9b9e0e48446dc1](https://basescan.org/address/0x00b174d66adA7d63789087F50A9b9e0e48446dc1) |
| sPinto Admin          | [0x71C596E55CaE926cAaF8aa6b96Bec724923FC60D](https://basescan.org/address/0x71C596E55CaE926cAaF8aa6b96Bec724923FC60D) |
| sPinto Implementation | [0x162c9c2f956Cf171b0C1CAB3079CE6d8cC0a3fB5](https://basescan.org/address/0x162c9c2f956Cf171b0C1CAB3079CE6d8cC0a3fB5) |

### Oracles

<table><thead><tr><th width="293">Contract</th><th>Base Address</th></tr></thead><tbody><tr><td>LSD Chainlink Oracle</td><td><a href="https://basescan.org/address/0x1CD1CDDc6383dfD53Acd7A22456A82256730b8Ef">0x1CD1CDDc6383dfD53Acd7A22456A82256730b8Ef</a></td></tr><tr><td><a href="https://data.chain.link/feeds/base/base/eth-usd">ETH/USD Chainlink Data Feed</a></td><td><a href="https://basescan.org/address/0x71041dddad3595F9CEd3DcCFBe3D1F4b0a16Bb70">0x71041dddad3595F9CEd3DcCFBe3D1F4b0a16Bb70</a></td></tr><tr><td><a href="https://data.chain.link/feeds/base/base/cbeth-usd">cbETH/USD Chainlink Data Feed</a></td><td><a href="https://basescan.org/address/0xd7818272B9e248357d13057AAb0B417aF31E817d">0xd7818272B9e248357d13057AAb0B417aF31E817d</a></td></tr><tr><td><a href="https://data.chain.link/feeds/base/base/cbbtc-usd">cbBTC/USD Chainlink Data Feed</a></td><td><a href="https://basescan.org/address/0x07DA0E54543a844a80ABE69c8A12F22B3aA59f9D">0x07DA0E54543a844a80ABE69c8A12F22B3aA59f9D</a></td></tr><tr><td><a href="https://data.chain.link/feeds/base/base/usdc-usd">USDC/USD Chainlink Data Feed</a></td><td><a href="https://basescan.org/address/0x7e860098F58bBFC8648a4311b374B1D669a2bc6B">0x7e860098F58bBFC8648a4311b374B1D669a2bc6B</a></td></tr><tr><td><a href="https://data.chain.link/feeds/base/base/sol-usd">SOL/USD Chainlink Data Feed</a></td><td><a href="https://basescan.org/address/0x975043adBb80fc32276CbF9Bbcfd4A601a12462D">0x975043adBb80fc32276CbF9Bbcfd4A601a12462D</a></td></tr></tbody></table>

### Misc. <a href="#misc" id="misc"></a>

<table><thead><tr><th width="270">Contract</th><th>Base Address</th></tr></thead><tbody><tr><td><a href="https://app.safe.global/transactions/queue?safe=base:0x2cf82605402912C6a79078a9BBfcCf061CbfD507">Pinto Contract Multisig (PCM)</a></td><td><a href="https://basescan.org/address/0x2cf82605402912C6a79078a9BBfcCf061CbfD507">0x2cf82605402912C6a79078a9BBfcCf061CbfD507</a></td></tr><tr><td><a href="https://app.safe.global/transactions/queue?safe=base:0xA8d8BD1745bA40D8B673f690c26BeB9440372b8f">Pinto Immunefi Committee Multisig (PICM)</a></td><td><a href="https://basescan.org/address/0xA8d8BD1745bA40D8B673f690c26BeB9440372b8f">0xA8d8BD1745bA40D8B673f690c26BeB9440372b8f</a></td></tr><tr><td>Pinto Development Budget Contract</td><td><a href="https://basescan.org/address/0xb0cdb715D8122bd976a30996866Ebe5e51bb18b0">0xb0cdb715D8122bd976a30996866Ebe5e51bb18b0</a></td></tr><tr><td><a href="https://pinto.exchange">Pinto Exchange</a></td><td>See <a href="https://docs.pinto.exchange/resources/contracts">Pinto Exchange Docs</a></td></tr><tr><td>Pipeline</td><td><a href="https://basescan.org/address/0xb1bE0001f5a373b69b1E132b420e6D9687155e80">0xb1bE0001f5a373b69b1E132b420e6D9687155e80</a></td></tr><tr><td>Pinto Price Contract</td><td><a href="https://basescan.org/address/0xD0fd333F7B30c7925DEBD81B7b7a4DFE106c3a5E">0xD0fd333F7B30c7925DEBD81B7b7a4DFE106c3a5E</a></td></tr><tr><td>Shipment Planner</td><td><a href="https://basescan.org/address/0x73924B07D9E087b5Cb331c305A65882101bC2fa2">0x73924B07D9E087b5Cb331c305A65882101bC2fa2</a></td></tr><tr><td>Junctions</td><td><a href="https://basescan.org/address/0x5A5A5A799569A567FC5Bd5850aB46CA24762Cb89">0x5A5A5A799569A567FC5Bd5850aB46CA24762Cb89</a></td></tr><tr><td>Unwrap and Send ETH Helper</td><td><a href="https://basescan.org/address/0xEEE0001Ba9488B70cf72E8FdFf43AEda68a4203d">0xEEE0001Ba9488B70cf72E8FdFf43AEda68a4203d</a></td></tr></tbody></table>


# Audits

<figure><img src="https://content.gitbook.com/content/E6o3oJ1UvNLq82fMCMG5/blobs/7qkuQuIrMDD6zv8WyF6K/Group%202.png" alt=""><figcaption></figcaption></figure>

To date, the Pinto ecosystem and its predecessor Beanstalk have undergone 20 audits. These audits include both full-protocol and audits of specific features. Additionally, the Pinto ecosystem is secured by a 1,200,000 Pinto bug bounty program through Immunefi.

{% embed url="<https://immunefi.com/bug-bounty/pinto/>" %}

## Inherited Security

Pinto was forked from Beanstalk after BIP-50 was deployed. From this, Pinto inherits the audits and security efforts of Beanstalk on the vast majority of the protocol code. Detailed information about the audit history of Beanstalk can be found at the link below.

{% embed url="<https://docs.bean.money/almanac/protocol/audits>" %}

## Improvements Beyond Beanstalk

Pinto implemented minor changes on top of Beanstalk, as well as several incremental upgrades since launch:

* [PI-0: Update Pump Parameters](https://github.com/pinto-org/protocol/pull/1) (November 19, 2024)
* [PI-1: Convert Newly Earned Pinto and Misc. Bug Fixes](https://github.com/pinto-org/protocol/pull/2) (November 26, 2024)
* [PI-2: Remove Anti Lambda to Lambda Convert](https://github.com/pinto-org/protocol/pull/3) (November 27, 2024)
* [PI-3: Bug Fixes and Parameter Changes](https://github.com/pinto-org/protocol/pull/4) (December 4, 2024)
* [PI-4: Demand for Soil Adjustments](https://github.com/pinto-org/protocol/pull/5) (December 8, 2024)
* [PI-5: Soil Issuance and Parameter Changes](https://github.com/pinto-org/protocol/pull/7) (January 2, 2025)
* [PI-6: Soil Issuance Below Value Target and Crop Ratio Changes](https://github.com/pinto-org/protocol/pull/8) (March 12, 2025)
* [PI-7: Convert Down Penalty](https://github.com/pinto-org/protocol/pull/33) (March 25, 2025)
* [PI-8: Misc. Efficiency Improvements](https://github.com/pinto-org/protocol/pull/54) (April 17, 2025)
* [PI-9: Helper Function Bug Fix](https://github.com/pinto-org/protocol/pull/77) (April 18, 2025)

Helper functions added in PI-8 were audited by [Egis](https://www.egissec.com/) (report [here](https://arweave.net/W7cfGzLVsTAEb65AR4wYfFLOl5Nm3EMy0Sg3Dk7C7e0)).

[Cantina](https://cantina.xyz/welcome) has audited up to PI-8 since deployment (report coming soon).

***

[sPinto](/resources/how-to-guides/spinto) is an extension of Pinto built entirely external to the protocol contracts. sPinto was audited by both Egis and Cantina before launch. The audit reports can be referenced [here](<https://github.com/Egis-Security/audits/blob/main/reports/SiloedPinto.pdf >) and [here](https://cantina.xyz/portfolio/c7410678-05f5-4dc3-bdbd-976d11738bcd).


# Links

* [Pinto Website](https://pinto.money)
* [Pinto Whitepaper](https://pinto.money/pinto.pdf)
* [Pinto Mirror (articles)](https://mirror.xyz/0xEA13D1fB14934E41Ee7074198af8F089a6d956B5)
* [Pinto GitHub](https://github.com/pinto-org/protocol)
* [Pinto Discord](https://pinto.money/discord)
* [Pinto X](https://x.com/pintodotmoney)
* [Pinto Bot X](https://x.com/pintoseasons)
* [Pinto Medium](https://medium.com/@pintodotmoney)
* [Pinto Announcements Telegram](https://t.me/pintoannouncements)
* [Pinto Bot Telegram](https://t.me/pintotracker)
* [Pinto Seasons Bot Telegram](https://t.me/pintoseasons)
* [Pinto Dune](https://dune.com/pintomoney/pinto)
* [Pinto Exchange Website](https://pinto.exchange)
* [Pinto Exchange Docs](https://pinto-exchange.gitbook.io/exchange/resources/links)
* [Pinto Exchange Links](https://pinto-exchange.gitbook.io/exchange/resources/link)


