Security
Nothing to steal here.
The safest frontend is the one with no funds, no keys and no database. Loom is a static page. Every transfer you make is signed by you, in your wallet, against Circle's published contract addresses.
The model
No custody, at any point
Your USDC moves from your wallet to a Circle contract. There is no Loom deposit address, no treasury, no pooling. A hack of this site cannot drain balances we never held.
No backend, no accounts
Static files on a CDN. No server process, no database, no API keys, no analytics cookies. Nothing to breach, nothing to leak.
Official contracts only
Transfers run on Circle's CCTP v2, the same infrastructure used by major exchanges and wallets. The code is public and audited by Circle's auditors.
Open source
Every line of this site is on GitHub. Build it yourself and compare. If what you see on this domain does not match the repository, do not use it.
Verify before you sign
Contract addresses.
Arc-side CCTP contracts as published in the official Arc docs. Cross-check them against docs.arc.io and against what your wallet shows before signing.
0x3600000000000000000000000000000000000000 0x8FE6B999Dc680CcFDD5Bf7EB0974218be2542DAA 0xE737e5cEBEEBa77EFE34D4aa090756590b1CE275 Honest risks
Could a fake Loom appear?
Yes. Anything with traction gets cloned. Bookmark the exact domain, and check that the transaction you sign shows official Circle contracts. Never sign transfers to addresses you cannot verify.
What is the worst case for this site?
Someone compromises this page or its build. Then the page could try to trick you into signing a bad transaction. Your defense is the same as everywhere: read what your wallet shows before you sign. The wallet is the last checkpoint, and it works.
Does Loom collect anything?
No accounts, no email, no tracking cookies, no analytics. The site loads, you click through to the official bridge, done.