curve25519
curve25519 is the elliptic curve behind modern pgp encryption and tor's own crypto - fast, constant-time and hard to implement badly.
curve25519 is a specific elliptic curve published by daniel j. bernstein in 2005, designed for high-speed Diffie-Hellman key agreement (the x25519 function). it offers roughly 128 bits of security - comparable to rsa-3072 - with far smaller keys and dramatically faster operations.
part of its reputation comes from design choices aimed at safe implementations: it uses complete formulas resistant to timing leaks in constant-time code, needs no random parameters, and avoids the trap-filled parameter negotiation that plagued older ecc setups. in crypto, "hard to implement badly" is a feature worth paying for.
adoption is everywhere: openpgp encryption keys, the signal protocol, ssh, tls 1.3 defaults, and - closest to home - the ed25519 variant signs every v3 onion identity. when our key generator offers curve25519 versus rsa-4096, both are considered secure today; the curve option is simply smaller, faster and more modern.
related naming trivia that trips people up: curve25519 (montgomery form) is for key agreement, ed25519 (twisted Edwards form of the same underlying curve) is for signatures. same mathematical family, different jobs.