Known Limitations

WireGuard is a protocol that, like all protocols, makes necessary trade-offs. This page summarizes known limitations due to these trade-offs.

Deep Packet Inspection

WireGuard does not focus on obfuscation. Obfuscation, rather, should happen at a layer above WireGuard, with WireGuard focused on providing solid crypto with a simple implementation. It is quite possible to plug in various forms of obfuscation, however.

tl;dr Read the docs.

Mullvad does exactly this.

WireGuard limitations hurt the attempt however.

For example, multi-hop betrays the actual exit node to your ISP (or MITM) due to the port used.

To clarify, this is refering to Mullvad multi-hop feature. Doing your own multihop setup doesn't have this issue, right?

Correct. Note that the MTU will be further reduced and that WireGuard DIY multi-hop may be inferred.