you could probably write an eBPF filter for WireGuard packets and offload it to the NIC. - Cloudflare Developers