Glossary

What is WireGuard?

WireGuard is a modern VPN protocol that creates an encrypted tunnel between your device and a server. Created by Jason A. Donenfeld, it’s known for a small codebase, a fixed set of modern cryptography and quick connections. It has been part of the Linux kernel since version 5.6 in 2020, and runs on Windows, macOS, iOS and Android.12

Also called: WireGuard protocol, WireGuard VPN

Updated September 2026. Sources are numbered and listed at the end.

How WireGuard works

Each device has a key pair, like an SSH key. Peers know each other by public key, and each public key is tied to the IP addresses allowed to use it inside the tunnel, a design WireGuard calls cryptokey routing.1 Connecting takes a single round trip: a handshake based on the Noise protocol framework sets up session keys, and traffic flows over UDP.

The handshake repeats every two minutes or so, and old keys are wiped. That gives WireGuard forward secrecy.3

WireGuard’s fixed cryptography.3 There is nothing to negotiate, which rules out downgrade attacks.
JobAlgorithm
Key exchangeCurve25519
EncryptionChaCha20-Poly1305
HashingBLAKE2s
Key derivationHKDF

The original design was implemented in fewer than 4,000 lines of code,4 small enough for one person to review, which is part of why it was accepted into Linux.

Is WireGuard quantum-safe?

Not on its own. Its key exchange uses Curve25519, which a large quantum computer could break, so recorded WireGuard traffic is exposed to harvest now, decrypt later. The designers planned for this: WireGuard has an optional preshared key that is mixed into the handshake, which its documentation describes as a way to add post-quantum resistance.3 If that preshared key is itself delivered with a post-quantum algorithm such as ML-KEM, breaking Curve25519 is no longer enough to decrypt a session.

Why it matters

For users, WireGuard means fast connects, quick recovery when you switch from Wi-Fi to mobile data, and good battery life. For security, a small, fixed design leaves less room for configuration mistakes and hidden bugs.

Where you’ll see it

  • Built into the Linux kernel since 5.6.2
  • Behind many consumer VPN apps, often under their own brand name for the protocol.
  • In mesh networking tools such as Tailscale, which builds its connections on WireGuard.5

WireGuard in Secria

Secria VPN runs on WireGuard on iOS, Android, Windows, macOS and Linux, and closes its quantum gap. On every connection, the app gets a fresh preshared key sealed with ML-KEM-1024, delivered over a hybrid post-quantum TLS channel, and WireGuard mixes it into every handshake. Breaking a session takes both the Curve25519 secrets and ML-KEM-1024. On networks that block VPNs, a stealth mode carries WireGuard over WebSocket. Read more on the post-quantum VPN page or Secria VPN.

Sources

  1. WireGuard, WireGuard: fast, modern, secure VPN tunnel.
  2. Kernel Newbies, Linux 5.6 (March 2020).
  3. WireGuard, Protocol and cryptography.
  4. Jason A. Donenfeld, WireGuard: next generation kernel network tunnel (NDSS 2017).
  5. Tailscale, How Tailscale works.

Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about WireGuard

Is WireGuard safe?+

Yes. It uses well-studied modern cryptography, has a small codebase that is easy to review, and has been part of the Linux kernel since 2020. Its one gap is quantum computers, which a post-quantum preshared key closes.

Is WireGuard free?+

WireGuard itself is free, open-source software. VPN services built on it charge for their servers, apps and extra protections.

Does WireGuard use UDP or TCP?+

UDP only. That keeps it fast. On networks that block VPN traffic, some services wrap WireGuard in another protocol to get through.

Is WireGuard quantum-safe?+

Not by default, because its key exchange uses Curve25519. Adding a preshared key delivered with a post-quantum algorithm such as ML-KEM makes recorded sessions resistant to quantum decryption.

A VPN built for the quantum era. Post-quantum on every connection, nothing to switch on.