What is a multi-hop VPN?

A multi-hop VPN sends your traffic through two or more VPN servers in a row instead of one. The first server knows who you are but not where you’re going, and the last knows the destination but not you. No single server sees the whole path, so one compromised server can’t link you to your activity.

Also called: double VPN, VPN chaining, cascading VPN

Updated October 2026. Sources are numbered and listed at the end.

On this page

How a multi-hop VPN works

With a normal VPN, one server receives your encrypted traffic, decrypts it and sends it on to the website. That server sees both your IP address and the sites you visit. You have to trust it completely.

A multi-hop VPN splits that knowledge across servers. In a three-hop circuit:

  1. Entry server. Sees your real IP address, but only that your traffic is heading to the next server.
  2. Middle server. Sees only the entry and exit servers, not you and not your destination.
  3. Exit server. Sends your traffic to the website. It sees the destination, but your traffic appears to come from the middle server, not from you.

The idea comes from onion routing, the design behind Tor, where each relay knows only the hop before and after it.1 A two-hop setup, often called double VPN, uses the same principle with an entry and an exit.

Who can see what.
ServerYour IP addressYour destination
Single-hop VPN serverYesYes
Multi-hop entryYesNo
Multi-hop middleNoNo
Multi-hop exitNoYes

Why multi-hop matters

A single VPN server is a single point of trust. If it is hacked, misconfigured or forced to cooperate, everything passing through it is exposed. Multi-hop removes that single point: an attacker would need to control several servers, often in different countries, to connect you to what you do online.

The cost is speed. Every extra hop adds distance, so pages take a little longer to load. That is why multi-hop is usually an option you turn on when you need it, rather than the default for everyday browsing.

Where you’ll see multi-hop

  • VPN apps with a multi-hop or double VPN setting, often letting you pick the entry and exit countries.
  • Tor, which routes traffic through three volunteer relays by default.1
  • Journalists and activists, for whom one server being compromised could be dangerous.

Multi-hop works on top of the tunnel protocol, such as WireGuard,2 so each hop still has to be protected by strong encryption.

Multi-hop in Secria

Secria VPN offers an optional three-hop circuit through an entry, a middle and an exit server, with each hop able to see only the previous and next one. The circuit is tracked only in server memory with a short time to live, and every server in it is RAM-only and runs the same post-quantum WireGuard tunnel with ML-KEM-1024.

Sources

  1. Dingledine, Mathewson and Syverson, Tor: The Second-Generation Onion Router, USENIX Security (2004).
  2. Jason A. Donenfeld, WireGuard: Next Generation Kernel Network Tunnel, NDSS (2017).

Checked October 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about multi-hop VPNs

What does a multi-hop VPN do?

It sends your traffic through several VPN servers in a row, so no single server knows both your IP address and the sites you visit.

Is a double VPN better than a normal VPN?

It is more private, because you no longer have to trust one server with everything. It is also a bit slower, so many people turn it on only for sensitive tasks.

Is multi-hop the same as Tor?

They share the idea of splitting knowledge across several relays. Tor uses volunteer relays and its own network. A multi-hop VPN uses servers run by the VPN provider.

Can I use two VPN apps at once instead?

Running two VPN apps on one device rarely works well and can break your connection. A built-in multi-hop option does the same job properly.

A VPN built for the quantum era.

Post-quantum on every connection, nothing to switch on.

Get Secria VPN

Explore Secria VPN