The three real costs of a VPN hop
Encryption, the thing everyone blames, is the cheapest part: AES on any CPU from the last decade runs at multi-gigabit rates, and WireGuard's ChaCha20 is even lighter. What actually costs you speed is the detour — every extra thousand kilometers between you and the exit node adds latency — plus the protocol's design, and how many strangers share your server.
OpenVPN over TCP is the classic silent killer: it carries an already reliable stream inside another TCP connection, so every lost packet triggers a double retransmit dance that looks exactly like a broken connection. WireGuard over UDP keeps 90–95% of raw throughput on a decent line. And a crowded server — the norm on free tiers and oversold providers — slows everyone on it regardless of your link quality.
- Server distance — each extra 1,000 km adds roughly 5–10 ms of latency; pick a node in or near your country
- Protocol — WireGuard typically keeps 90–95% of raw speed; OpenVPN over TCP can halve it under load
- Server load — free tiers and oversold nodes share one uplink among too many strangers
- Multi-hop chains — every extra hop multiplies both the distance and the loss
- ISP peering — how well your provider exchanges traffic with the VPN's datacenter matters more than marketing admits
- MTU mismatches — fragmented packets look exactly like flaky Wi-Fi until you fix the size
When the VPN is the faster option
Honesty cuts both ways: a tunnel is sometimes quicker than your direct line. ISPs that throttle video traffic or congested international transit routes lose to a VPN's datacenter peering, which is why a video that stutters direct can stream smoothly through the tunnel. Heavy CGNAT on mobile carriers sometimes behaves better through a clean exit node too.
Measure before blaming: run the same speed test three times with the VPN off and on, same server region, wired if possible. If the off/on gap is under 10%, your VPN costs about what it should. If throughput halves, try another server before another subscription — and weigh the exit node's load, since a busy Thursday-evening node is not a verdict on the provider.
Cutting the penalty without going unprotected
Three moves recover most of the loss. Switch to WireGuard or another modern protocol if the app still defaults to OpenVPN. Pick the nearest server that still serves your purpose — unblocking needs a specific country, but plain browsing privacy rarely does. And use split tunneling so streaming and downloads that don't need the tunnel skip it entirely.
The kill switch stays on for everything that remains in the tunnel, because a fast connection that leaks your real IP when it reconnects is worse than a slow one that never does. What you should stop expecting is a free VPN performing like a paid one: free tiers oversell bandwidth by design, and their speed ceiling is a business decision, not a setting you can tune.
Questions and Answers
How much speed should a VPN lose?
On a nearby WireGuard server, 5–10% is normal. Over 20–30% points to congestion or an outdated protocol; losing half your speed is a server or provider problem.
Can a VPN make the internet faster?
Occasionally, yes — if your ISP throttles specific traffic or routes it through congested transit, an encrypted tunnel over better-peered servers can beat the direct path.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]