Jan said:

BTW, Curve25519 has the disadvantage that it is difficult to secure against side channel attacks.

This message on the GnuPG mailing-list by the author of Curve25519's implementation says exactly the opposite.

Fill in the blank.