What is X25519?

X25519 is a key exchange that lets two devices agree on a shared secret over an open network, using an elliptic curve called Curve25519. Designed by Daniel J. Bernstein in 2006 and standardized in RFC 7748, it is fast, uses 32-byte keys and is one of the most widely used key exchanges on the internet.

Also called: Curve25519 Diffie-Hellman, ECDH over Curve25519

Updated October 2026. Sources are numbered and listed at the end.

On this page

How X25519 works

X25519 is a form of Diffie-Hellman key exchange. Each side picks a random 32-byte private key and computes a matching 32-byte public key from it. They swap public keys in the open. Each side then combines its own private key with the other’s public key, and both arrive at the same 32-byte shared secret.1 Someone watching sees both public keys but can’t compute the secret.

The math happens on Curve25519, a curve over the prime number 2255 minus 19, which is where the name comes from.2 Breaking it means solving the elliptic-curve discrete logarithm problem, which takes about 2128 operations on a classical computer, far beyond reach.1

Bernstein designed it to be hard to get wrong. Every 32-byte string works as a public key, so there are fewer checks to forget, and it is designed to run in constant time, which helps stop timing attacks that leak secret bits.2

Three names that get mixed up.
NameWhat it is
Curve25519The elliptic curve itself
X25519The key exchange function on that curve1
Ed25519A signature scheme on a related curve, used to prove identity, not to agree on keys3

Why X25519 matters

X25519 is the default handshake behind much of the encrypted internet, which makes it a good thing to understand. It also has one known weakness: a large quantum computer running Shor’s algorithm could solve the math it rests on. Anything protected by X25519 alone could be recorded now and decrypted later, the harvest now, decrypt later problem.

The fix most of the industry has chosen is not to drop X25519 but to pair it with ML-KEM, so an attacker must break both. That is hybrid encryption, and the IETF has standardized it for TLS 1.3 as X25519MLKEM768.4

Where you’ll see X25519

  • TLS 1.3, the protocol behind HTTPS, which recommends support for X25519.5
  • SSH, through the curve25519-sha256 key exchange.6
  • WireGuard, which uses Curve25519 for its handshake.7
  • Signal, whose key agreement protocol is built on X25519.8

X25519 in Secria

Secria uses X25519 as the classical half of its hybrid key exchange. In Secria Mail, every message in your mailbox is sealed with a key from ML-KEM-1024 and X25519 together, joined with HKDF-SHA256, so an attacker has to break both. Secria VPN’s WireGuard tunnel uses Curve25519 with an ML-KEM-1024 protected key mixed in.

Sources

  1. IETF, RFC 7748: Elliptic Curves for Security (January 2016).
  2. Daniel J. Bernstein, Curve25519: new Diffie-Hellman speed records, PKC 2006.
  3. IETF, RFC 8032: Edwards-Curve Digital Signature Algorithm (EdDSA) (January 2017).
  4. IETF, RFC 10024: Post-quantum traditional hybrid key agreement for TLS 1.3.
  5. IETF, RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3, section 9.1 (August 2018).
  6. IETF, RFC 8731: Secure Shell (SSH) Key Exchange Method Using Curve25519 and Curve448 (February 2020).
  7. Jason A. Donenfeld, WireGuard: Next Generation Kernel Network Tunnel, NDSS (2017).
  8. Signal, The X3DH Key Agreement Protocol.

Checked October 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about X25519

What is X25519 used for?

Agreeing on a shared secret key between two devices, such as your browser and a website. That key then encrypts the actual data with a fast cipher.

Is X25519 the same as Curve25519?

Not quite. Curve25519 is the elliptic curve. X25519 is the key exchange function that runs on it. People often use the names interchangeably.

Is X25519 secure?

Yes, against today’s computers. It offers about 128 bits of security. A future large quantum computer could break it, which is why it is now paired with ML-KEM.

What is X25519MLKEM768?

A hybrid key exchange for TLS 1.3 that runs X25519 and ML-KEM-768 together and combines their results. It is now the default in major browsers.

Email that’s ready for what comes next.

Post-quantum encryption on every plan, free included.

Start free

Explore Secria Mail