By Eric L.
09/08/2026 · 6 MIN READ

Double VPN, also called multi-hop, sends your traffic through two VPN servers in sequence: your device encrypts to server A, server A forwards to server B, and B sends the traffic on to the website.

The first server sees your real address but not your destination; the second sees the destination but not your address. It's a defense against the compromise of a single server, at the cost of roughly doubling the tunnel's overhead. For most everyday use it adds latency without adding protection you need; for a few situations it's exactly the right tool.

DIAGRAMFIG. 01
                  One hop  Multi-hop

hides you from site   ✓        ✓
one server sees both  ✓        ✗
speed                 ▇▇▇▇     ▇▇
battery               ▇▇▇▇     ▇▇
    └─ Tor does this with three

How double VPN (multi-hop) works

With an ordinary VPN, one server decrypts your traffic and forwards it. That server is the single point where your address and your destinations meet; the provider's policy is what keeps them from being recorded together.

● ONE HOPYouVPN serverboth ends meet hereSite● TWO HOPS, TWO LAYERSYouServer Aremoves the outer layerServer Bremoves the inner layerSitesees only:"forward this to B"sees only:"from A, to this site"
One hop is a single place where both ends meet; with two, each server opens only its own layer.

With multi-hop, the traffic is encrypted in layers. Server A removes the outer layer and sees only "forward this to B." Server B removes the inner layer and sees only "this came from A, send it to this site." Neither server holds the full picture. If one server were seized or compromised, the attacker would still have to compromise the other to link you to your activity. Ideally the two servers are in different countries under different jurisdictions.

HOW IT WORKSFIG. 02
you → server A → server B → the site
  ├─ A knows who you are
  ├─ B knows where you went
  └─ neither knows both
the whole idea is splitting knowledge

What double VPN protects against

  • Compromise of a single server. Malware on a server, a seized machine, a rogue operator: they get half the picture.
  • Correlation at one point. An observer watching a single VPN server's traffic can't match entering and exiting streams as easily when the exit is a different server elsewhere.
  • Jurisdictional pressure on one location. Two countries have to cooperate.
WHAT MULTI-HOP ACTUALLY STOPSFIG. 03
one operator logging everything   yes
one server seized                 yes
a network watching one hop        yes
a website recognizing you         no
your own logged-in accounts       no
Three of these five are about the network path; the other two are about the site itself, which multi-hop never touches.

What double VPN doesn't protect against

  • The provider itself. Both servers belong to the same company. If its policy or practice is to log, two hops don't help. Multi-hop is a defense against attackers, not against the provider; read the policy as described in what does no logs mean.
  • Websites recognizing you. Cookies, accounts and browser fingerprints are unchanged; see browser fingerprinting explained.
  • Leaks. DNS, IPv6 and WebRTC leaks bypass both hops equally. Test with is my DNS leaking.
  • A global observer who can watch traffic entering the first server and leaving the second at the same time. Against that, timing correlation still works, as it does against Tor.
THE COSTFIG. 04
latency        roughly doubles
throughput     drops
battery        drains faster
failure modes  two servers to break
   └─ paid on every packet, useful
      only in a narrow case

Double VPN speed cost

Two servers mean two detours and two encryptions. Latency roughly doubles compared with a single nearby server, throughput drops, and battery use on a phone goes up. If the two servers are far apart, browsing feels noticeably slower. The general reasons a VPN slows things are in does a VPN slow down your internet; multi-hop multiplies them.

MULTI-HOP VERSUS TORFIG. 05
multi-hop  two servers, both chosen
           by one company
Tor        three relays, chosen
           independently
   └─ for anonymity that difference
      is the whole point

Multi-hop versus Tor

Tor uses three hops through volunteer-run relays operated by different people, so no single organization controls the path, and Tor Browser also hardens the browser against fingerprinting. Multi-hop uses two servers run by one company, which is faster and simpler but trusts that company. For anonymity against a determined adversary, Tor is the stronger design; for everyday privacy with an extra layer against server compromise, multi-hop is the practical one. The full comparison is in VPN vs Tor vs proxy.

When double VPN is worth it

  • You have a concrete reason to worry about a single server being watched or seized: sensitive research, journalism, a hostile environment.
  • You're on a network where your entry to the first server is observed and you want the exit to be somewhere else entirely.
  • You want an exit country different from the entry country without trusting a single server in either.

When you don't need double VPN

  • Everyday browsing, streaming, calls: pay the speed cost for nothing.
  • Public Wi-Fi protection: a single hop already closes what the coffee shop can see.
  • Any situation where the threat is the website, not the network: multi-hop doesn't change what sites know.
WORTH IT OR NOTFIG. 06
both hops run by one company
  └─ the split is mostly cosmetic
hops in different jurisdictions
  └─ the split is real
you need anonymity, not privacy
  └─ this is not the tool

Multi-hop is worth it in a narrow case. Check whether yours is one of them.

Prompt for an AI
Help me decide whether multi-hop is worth it
for me.

What I am trying to achieve: (privacy from my
ISP / not being identified by a website /
protection if one provider is compromised /
I am not sure).
Both hops run by one company: (yes / no /
not sure).
What I would give up: my connection is
(fast / slow), my device is (plugged in /
on battery).

Say whether the split of knowledge is real in my
case or mostly cosmetic, and what it costs me.
If this is not the right tool for my goal, say so
and name what is.

A sensible way to use it

Keep single-hop as the default with the kill switch on. Turn multi-hop on for the specific task that needs it, pick a first server close to you for the least added latency, and turn it off afterward. If the app lets you choose both hops, put the exit in the country you want to appear from.

ON FOR ONE TASK, OFF AFTERWARD1Single hopthe default,kill switch on2Multi-hop onfor the taskthat needs it3First servercloseleast addedlatency4Exit countrywhere you wantto appear, ifthe app lets you5Off afterwardback tosingle hopEveryday browsing, streaming and calls: stay on step 1.
Multi-hop works best as a switch you flip for one task and then flip back.

404 VPN runs single-hop connections only, over VLESS in the Android and macOS apps or over WireGuard configs for Istanbul and Marseille from the dashboard, with DNS inside the tunnel and a kill switch in the Android app. Plans are on the home page; what is stored is in the privacy policy.