> This high-key-bit leak is only saved by X25519's insistence on setting the > highest bit to 1 on every secret key. This is not a coincidence. Djb was the first, and is still one of the few, cryptographers who think about it from a full systems approach and design things so that proper implementation is relatively easy.