Hysteria2 or WireGuard: which to choose
Comparing two fast UDP protocols by design, speed on bad networks, visibility to DPI and convenience.
October 1, 2026 · 2 min readWireGuard and Hysteria2 are two modern, fast protocols, and both run over UDP. But they were designed for different jobs, and that shows clearly on filtered networks.
WireGuard in brief
WireGuard is a VPN protocol built into the Linux kernel and available on every platform. It is based on the Noise framework: Curve25519 key exchange, ChaCha20-Poly1305 encryption and BLAKE2s hashing. There is little code, it is easy to audit, and it is very fast.
However, WireGuard makes no attempt to hide. Its packets have fixed headers and recognisable handshake sizes. For a DPI system it is one of the easiest protocols to identify. In 2023–2024 users in Russia widely reported WireGuard and OpenVPN being blocked.
Hysteria2 in brief
Hysteria2 runs over QUIC, the same transport as HTTP/3. The handshake is standard TLS 1.3 with a valid certificate, and to an observer the connection looks like a website visit over HTTP/3. Its own congestion control keeps the configured pace even with packet loss.
Comparison
| WireGuard | Hysteria2 | |
|---|---|---|
| Transport | UDP | QUIC (UDP) |
| Encryption | Noise: Curve25519, ChaCha20-Poly1305 | TLS 1.3 |
| Disguise | None | Looks like HTTP/3 |
| Resistance to DPI | Low | High |
| Speed on a clean network | Very high | Very high |
| Speed with packet loss | Drops | Holds thanks to its own congestion control |
| If UDP is blocked | Does not work | Does not work; needs a TCP fallback |
Which to choose
- At home or at work without filtering, WireGuard is an excellent choice: simple and fast.
- On networks that block or throttle WireGuard, Hysteria2.
- Where all UDP is cut, neither works. You need a TCP protocol such as VLESS Reality or Trojan.
Why Colitu has no WireGuard
We chose protocols that work on filtered networks: Hysteria2, VLESS Reality, Trojan and Shadowsocks 2022. The app switches between them automatically, so you never need to work out which one currently works on your network.