How WireGuard works
Each device has a key pair, like an SSH key. Peers know each other by public key, and each public key is tied to the IP addresses allowed to use it inside the tunnel, a design WireGuard calls cryptokey routing.1 Connecting takes a single round trip: a handshake based on the Noise protocol framework sets up session keys, and traffic flows over UDP.
The handshake repeats every two minutes or so, and old keys are wiped. That gives WireGuard forward secrecy.3
| Job | Algorithm |
|---|---|
| Key exchange | Curve25519 |
| Encryption | ChaCha20-Poly1305 |
| Hashing | BLAKE2s |
| Key derivation | HKDF |
The original design was implemented in fewer than 4,000 lines of code,4 small enough for one person to review, which is part of why it was accepted into Linux.
Is WireGuard quantum-safe?
Not on its own. Its key exchange uses Curve25519, which a large quantum computer could break, so recorded WireGuard traffic is exposed to harvest now, decrypt later. The designers planned for this: WireGuard has an optional preshared key that is mixed into the handshake, which its documentation describes as a way to add post-quantum resistance.3 If that preshared key is itself delivered with a post-quantum algorithm such as ML-KEM, breaking Curve25519 is no longer enough to decrypt a session.
Why it matters
For users, WireGuard means fast connects, quick recovery when you switch from Wi-Fi to mobile data, and good battery life. For security, a small, fixed design leaves less room for configuration mistakes and hidden bugs.
Where you’ll see it
- Built into the Linux kernel since 5.6.2
- Behind many consumer VPN apps, often under their own brand name for the protocol.
- In mesh networking tools such as Tailscale, which builds its connections on WireGuard.5
WireGuard in Secria
Secria VPN runs on WireGuard on iOS, Android, Windows, macOS and Linux, and closes its quantum gap. On every connection, the app gets a fresh preshared key sealed with ML-KEM-1024, delivered over a hybrid post-quantum TLS channel, and WireGuard mixes it into every handshake. Breaking a session takes both the Curve25519 secrets and ML-KEM-1024. On networks that block VPNs, a stealth mode carries WireGuard over WebSocket. Read more on the post-quantum VPN page or Secria VPN.
Related terms
Sources
- WireGuard, WireGuard: fast, modern, secure VPN tunnel.
- Kernel Newbies, Linux 5.6 (March 2020).
- WireGuard, Protocol and cryptography.
- Jason A. Donenfeld, WireGuard: next generation kernel network tunnel (NDSS 2017).
- Tailscale, How Tailscale works.
Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.