A Brief History of VPN Technology

VPNs started as a way for traveling employees to reach the office network, not as a privacy product. Here's how that changed.

Quick answer

The history of VPN technology begins in 1996, when Microsoft engineers created PPTP to let remote employees securely reach a corporate network over the public internet — a purely business tool. Through the late 1990s and 2000s, protocols like IPsec, L2TP, and OpenVPN (released in 2001) made VPN connections more secure and more standardized, still mostly for enterprise use. The shift to a consumer privacy and streaming-access product happened gradually through the 2010s, driven by rising awareness of data collection and government surveillance, and accelerated further after WireGuard's 2015-2020 development made VPN apps faster and simpler to use than ever before. Today's VPN industry is a direct descendant of that decades-long engineering lineage, not a recent invention.

What is the actual history of VPN technology, from the beginning?

The history of VPN technology is really two overlapping stories. The first is a networking-engineering story: a sequence of protocols, each built to solve a specific technical problem the previous one didn't fully solve, stretching from the mid-1990s to today. The second is a market story: how a tool built for corporate IT departments slowly turned into a consumer product marketed on privacy, streaming access, and public Wi-Fi safety. Most explanations of VPN history focus on one story or the other. Understanding both together is what actually explains why today's VPN apps look and work the way they do.

The short version is this: VPN technology didn't appear as a finished consumer idea. It was assembled, piece by piece, out of solutions to specific enterprise networking problems — remote employees needing office access, branch offices needing to talk to headquarters securely, and organizations needing to stop sending sensitive data over the open internet in plain text. Only much later, once those underlying protocols had matured and internet access became a background utility of everyday life, did anyone package a VPN connection as something an individual consumer would want to buy and run on a laptop or phone for their own reasons. This guide walks through that timeline in order, from the earliest technical building blocks to the state of VPN technology today.

What problem was VPN technology originally built to solve?

Before dedicated VPN protocols existed, organizations that needed to connect two private networks over long distances — say, a company's headquarters and a branch office in another city — had a genuinely expensive option available: leased telecommunications lines. A leased line was a dedicated, physically separate circuit rented from a telecom provider, private by virtue of not sharing infrastructure with public internet traffic. It worked, but it was slow to provision and costly enough that only large, well-resourced organizations could justify it for more than a handful of locations.

The internet, as it grew through the 1990s, offered an obviously cheaper alternative path between those same two points — except that public internet traffic wasn't private or authenticated by default. The foundational idea behind VPN technology was to get the cost and flexibility advantages of routing traffic over shared public infrastructure while recreating the privacy and access-control properties of a dedicated leased line, using encryption and tunneling rather than physically separate wiring. That's the literal meaning behind the phrase "virtual private network": virtual, because the private connection doesn't require its own dedicated physical medium, and private, because encryption and authentication recreate what physical separation used to provide.

When was the first VPN protocol actually created?

The most commonly cited starting point for the history of VPN technology is 1996, when a group of engineers at Microsoft — credited in later accounts as including Gurdeep Singh-Pall — began developing the Point-to-Point Tunneling Protocol, or PPTP. PPTP was designed to let a remote user establish a secure, authenticated connection back to a private network over the internet, encapsulating and encrypting their traffic inside an outer tunnel. Microsoft included support for it in Windows 95's OSR2 update and later Windows NT, which meant it shipped, essentially for free, on an enormous number of desktop computers almost from the start.

PPTP wasn't the only tunneling work happening around the same period — competing and complementary efforts inside the IETF (the Internet Engineering Task Force) were underway on related standards — but PPTP's inclusion in mainstream Windows operating systems gave it an outsized role in introducing the basic concept of a VPN connection to a wide base of IT administrators. For a period spanning the late 1990s and into the 2000s, "set up a VPN" and "set up a PPTP connection" were close to synonymous for a large share of corporate IT staff, simply because it was the option already sitting on the operating systems they were already deploying.

Why PPTP eventually fell out of favor

PPTP's convenience came with a real cost that became clearer over time. Its authentication scheme, MS-CHAPv2, and its overall cryptographic design had known weaknesses that security researchers documented as early as the late 1990s, and those weaknesses were demonstrated more concretely in later years as computing power grew and cryptanalysis techniques improved. By the 2010s, PPTP was widely considered broken from a security-research standpoint — not a theoretical concern but a practically exploitable one under realistic conditions — and most credible VPN providers and security guidance had moved away from recommending it, even though it remained available in many operating systems for backward compatibility for years afterward. PPTP's arc — fast, convenient early adoption followed by a slow-motion security reckoning once real scrutiny caught up with it — turns out to be a pattern that shows up more than once in VPN history.

How did IPsec change VPN technology in the 1990s?

Running in parallel with PPTP's rise, a separate and more rigorously engineered effort was underway inside the IETF: IPsec, short for Internet Protocol Security. Rather than being a single protocol, IPsec is a suite of related protocols and standards, developed through a series of RFCs published starting in the mid-1990s, covering authentication, encryption, and key exchange at the network layer of the internet's protocol stack.

IPsec's design was more thorough and more flexible than PPTP's from the outset, supporting a range of encryption algorithms and authentication methods rather than one fixed approach. That flexibility made it well suited to serious enterprise deployments — site-to-site VPNs connecting entire office networks together, not just individual remote users — and IPsec became, and largely remains, the backbone protocol suite underlying a huge share of business VPN infrastructure. Its complexity, though, was also a real practical cost: correctly configuring an IPsec connection required considerably more networking expertise than PPTP did, which kept it more firmly in the domain of trained IT administrators than something an ordinary computer user would set up themselves.

IPsec's continuing relevance today, decades after it was first standardized, says something important about the history of VPN technology more broadly: rigorous, well-reviewed cryptographic engineering tends to age far better than convenience-first shortcuts. IPsec is still the foundation for IKEv2/IPsec connections offered by modern consumer VPN apps, which is a remarkable degree of technical continuity for a protocol suite whose earliest RFCs predate the modern consumer internet.

Why did VPNs remain a purely corporate tool through most of the 1990s and 2000s?

It's worth being direct about something a lot of shorter histories skip over: for roughly the first fifteen years of VPN technology's existence, essentially nobody outside of corporate IT departments and a small number of technically sophisticated individuals had any reason to use one. A few structural facts explain why.

First, home internet access itself was a scarcer and slower resource for much of this period — dial-up and early broadband connections had limited enough bandwidth that adding VPN encryption overhead was a meaningfully bigger relative cost than it is on today's connections. Second, the concept a modern VPN sells to consumers — hiding your IP address and encrypting your traffic against surveillance, ISP tracking, or public Wi-Fi snooping — hadn't yet become a mainstream anxiety. Most people's mental model of internet risk in this era centered on viruses and email scams, not on traffic interception or IP-based tracking. Third, geographic content licensing and country-based streaming restrictions, one of the biggest drivers of today's consumer VPN market, barely existed yet in a form that would motivate someone to want a different-country IP address — on-demand video streaming as a mainstream product was still years away.

Put simply, the specific problems a modern consumer VPN solves either didn't exist yet or weren't yet widely recognized as problems. VPN technology's early history is a story about connecting known networks to known networks under known administrative control — remote workers to their employer's servers, branch offices to headquarters — not about an individual protecting their own traffic from unknown third parties on the open internet.

What role did SSL and TLS play in early VPN technology?

By the early 2000s, a different approach to secure remote access started gaining traction alongside IPsec and PPTP: SSL VPNs, built on the same Secure Sockets Layer (and later Transport Layer Security) encryption already securing web traffic on HTTPS sites. Rather than requiring a dedicated client application and low-level network configuration the way IPsec often did, an SSL VPN could, in some implementations, be accessed through a standard web browser, which lowered the technical barrier to giving remote employees secure access to internal company resources.

SSL/TLS-based VPN technology mattered for a reason beyond convenience: it reused cryptographic infrastructure that was already being deployed, tested, and improved for an entirely different purpose — securing e-commerce and general web traffic — which meant SSL VPN implementations benefited from a much larger, more actively scrutinized body of cryptographic engineering than a narrower, VPN-specific effort would have had access to on its own. This cross-pollination between web security and VPN security is a recurring theme in the field's history, and it resurfaces again later with OpenVPN's own reliance on the OpenSSL library.

How did OpenVPN change the direction of VPN technology in 2001?

OpenVPN, first released by developer James Yonan in 2001, represents one of the most consequential turning points in VPN history, for reasons that go beyond its technical design. It was released as open-source software, meaning its full source code was publicly available for anyone to read, audit, modify, and redistribute — a meaningfully different trust model than proprietary protocols like PPTP, where users had to take Microsoft's security claims largely on faith.

Technically, OpenVPN built on the OpenSSL cryptographic library, giving it access to well-established, actively maintained encryption primitives rather than requiring its own from-scratch cryptographic implementation. It supported a flexible range of configuration options, could run over either UDP or TCP — including, notably, over TCP port 443, the same port used for ordinary HTTPS traffic, which let OpenVPN connections blend in with regular encrypted web traffic on networks that tried to block or throttle VPN use. That TCP-443 capability became one of OpenVPN's signature practical advantages and a big part of why it remained relevant for so long, particularly for users trying to reach the internet from countries or networks that actively interfere with VPN traffic.

OpenVPN's open-source, cross-platform, actively community-maintained nature made it the closest thing to a universal standard the VPN industry had for roughly a decade and a half. When the first wave of consumer VPN companies emerged in the following years, OpenVPN was overwhelmingly the protocol they built their apps around, precisely because it was free to implement, well understood, and didn't require reinventing core cryptographic engineering from scratch.

When did VPNs start being sold to ordinary consumers instead of businesses?

The shift from VPN technology as a strictly corporate tool to VPN technology as something an individual might pay for personally didn't happen at one clean moment — it was gradual, roughly spanning the mid-2000s through the early 2010s, and it was driven by several converging trends rather than a single cause.

Broadband internet access became widespread and fast enough during this period that the performance overhead of VPN encryption stopped being a meaningful obstacle for everyday use. Public Wi-Fi — in coffee shops, airports, and hotels — became commonplace at the same time that awareness grew of how easily unencrypted traffic on a shared open network could be intercepted by anyone else on it, giving individuals a concrete, personally relevant reason to want traffic encryption that had nothing to do with corporate network access. And streaming video services, as they matured and began licensing content differently by country, created a second, entirely separate motivation: accessing a different region's content library by appearing to connect from a different country.

Early consumer VPN companies packaged the same underlying protocols — mostly OpenVPN, with PPTP and L2TP/IPsec still offered for compatibility — into simplified apps aimed at people with no networking background: install an app, click connect, done. That simplification, more than any new cryptographic breakthrough, is what actually turned VPN technology into a consumer product. The protocols themselves were largely already built; what consumer VPN companies added was an accessible interface and a server network sized for a much larger, more geographically distributed user base than any single company's remote workforce.

What drove the consumer VPN boom of the 2010s?

If there's a single decade where VPN technology visibly transformed from a niche IT tool into a mainstream consumer category, it's the 2010s, and a specific sequence of public events during that decade did a lot of the work in making that shift happen.

Revelations in 2013 about the scale of government mass-surveillance programs brought public attention to internet privacy and traffic interception in a way that no prior single event had. That story pushed a much wider segment of the general public — well beyond security researchers and IT professionals — to start asking practical questions about who could see their internet traffic and what could be done about it. VPN providers, understandably, leaned heavily into privacy-focused marketing in the years that followed, and consumer VPN adoption climbed noticeably through the mid-to-late 2010s as a direct result.

Around the same period, a steady drumbeat of large-scale data breaches, growing public awareness of how internet service providers and advertising networks track browsing activity, and expanding public Wi-Fi use on smartphones all reinforced the same basic pitch: a VPN as a simple, one-app way to reduce your everyday exposure to several different kinds of tracking and interception at once. Streaming access — reaching a different country's version of a video-on-demand catalog — grew into an equally large driver of subscriptions during this same window, often eclipsing privacy as the stated reason a given subscriber actually signed up, even at companies that marketed primarily on privacy grounds.

By the end of the 2010s, the VPN had completed its transformation from an obscure IT acronym into a category most internet users had at least heard of, with an increasingly crowded market of competing consumer-facing providers.

How did smartphones change the history of VPN technology?

Mobile devices introduced a genuinely new technical problem that desktop-era VPN protocols hadn't been designed around: a connection that needs to survive a device physically moving between different networks — switching from home Wi-Fi to cellular data as someone walks out the door, for instance — without the tunnel dropping and requiring a full reconnection each time.

This is the specific problem IKEv2, paired with IPsec, was well positioned to solve. IKEv2 (Internet Key Exchange version 2), standardized by the IETF in the mid-2000s, included support for an extension called MOBIKE (Mobility and Multihoming Protocol), which allows a VPN tunnel to persist through a change in the underlying network connection rather than forcing a fresh handshake. As smartphone VPN use grew through the 2010s, IKEv2/IPsec's resilience to network switching made it a natural fit for mobile apps, and it became a standard alternative protocol offered alongside OpenVPN in most consumer VPN apps' settings, particularly favored on iOS given Apple's native platform-level support for the protocol.

The broader effect of the mobile era on VPN history was to push the entire industry toward valuing seamlessness and low battery/performance overhead much more heavily than the desktop-era, enterprise-focused protocols had needed to. A corporate IT administrator configuring a site-to-site IPsec tunnel in 2001 didn't particularly care about battery consumption; a consumer VPN app competing for smartphone users in 2018 very much did, and protocol choice increasingly reflected that changed set of priorities.

How did WireGuard's development change VPN technology after 2015?

The most recent major turning point in VPN technology's history is WireGuard, first published by developer Jason A. Donenfeld starting around 2015-2016 and merged into the mainline Linux kernel in 2020. Where OpenVPN and IPsec had grown into large, highly configurable systems over many years of incremental additions, WireGuard was built from the ground up around a narrow, deliberately minimal design: a small, thoroughly auditable codebase, a fixed and non-negotiable set of modern cryptographic primitives, and an emphasis on real-world speed that older protocols, weighed down by decades of accumulated flexibility, struggled to match.

WireGuard's rise mattered for VPN history for reasons beyond its own technical merits. It demonstrated that a protocol built by a small, independent effort — rather than a large standards body or a corporation — could earn enough credibility, through formal academic review and eventual Linux kernel adoption, to displace decades-old incumbents as the default choice across nearly the entire consumer VPN industry within about half a decade. Most major providers today run WireGuard directly or a proprietary implementation layered on top of it, such as NordVPN's NordLynx. For the full story of how that specific shift happened, see our dedicated guide on why WireGuard became the default VPN protocol.

What other protocols appear in VPN history, and why didn't they take over?

A few other protocols are worth knowing as part of the fuller picture, even though none of them displaced the main lineage covered above.

L2TP/IPsec

Layer 2 Tunneling Protocol, typically paired with IPsec for encryption since L2TP itself doesn't provide encryption on its own, emerged in the late 1990s as something of a successor and merger of ideas from PPTP and an earlier Cisco protocol called L2F. It saw broad adoption thanks to built-in operating system support, but its double-encapsulation design (tunneling, then separately encrypting) made it somewhat less efficient than alternatives, and it has gradually been displaced by IKEv2/IPsec and WireGuard in most modern consumer VPN apps, though it still appears as a legacy option in some software.

SSTP

Secure Socket Tunneling Protocol, introduced by Microsoft with Windows Vista's Service Pack 1 in the late 2000s, wraps VPN traffic inside an SSL/TLS channel similarly to how OpenVPN can run over TCP 443. It never achieved the cross-platform reach OpenVPN did, remaining largely tied to Windows environments, which limited its adoption by VPN providers building apps meant to work identically across many operating systems.

Proprietary provider protocols

Some providers have built their own proprietary protocols rather than relying solely on open standards — efforts aimed at combining strong performance with obfuscation features suited to bypassing network-level VPN blocking. These typically build on the cryptographic groundwork laid by IPsec, TLS, or WireGuard rather than inventing entirely new cryptography from scratch, which is generally the more defensible engineering approach: reusing well-reviewed cryptographic primitives rather than rolling entirely new ones that haven't had the benefit of years of independent scrutiny.

How has government surveillance history shaped VPN technology and marketing?

It's worth separating two related but distinct effects that surveillance-related news events have had on VPN history. The first is a genuine demand-side effect: each major public revelation about government or corporate data collection tends to produce a measurable, if temporary, spike in consumer interest in privacy tools generally, VPNs included. The second is a marketing effect that's less about the technology itself: VPN providers, understandably, use these same events as a recurring backdrop for advertising copy, sometimes overstating what a VPN can actually protect against in the process.

The honest, technically grounded version of this story is narrower than a lot of marketing suggests. A VPN encrypts traffic between your device and the VPN provider's own servers, and hides your IP address from the websites and services you connect to past that point. It doesn't make you anonymous everywhere on the internet, and it doesn't stop a website you're logged into from knowing who you are through your account itself, regardless of what surveillance concerns motivated your interest in the first place. Understanding VPN history's connection to surveillance news is useful context for why the consumer market grew when it did — but it isn't a substitute for understanding what a VPN's encryption and IP-masking actually do and don't cover today.

How did the modern VPN review and comparison industry emerge?

As the consumer VPN market grew through the 2010s, a parallel industry of review sites, comparison articles, and affiliate marketing grew alongside it — a development that's part of VPN history in its own right, and one worth understanding with some skepticism. As more providers competed for the same pool of new subscribers, marketing claims about speed, server counts, and security features multiplied faster than independent verification of those claims did.

This dynamic is part of why independent security audits of VPN apps and no-logs claims became an increasingly emphasized differentiator among providers over the course of the 2010s and into the 2020s — a response to a review and marketing ecosystem where unverified superlative claims had become common enough that a real, dated, scoped third-party audit started functioning as a genuine trust signal rather than routine due diligence. Our own approach on this site reflects that same lesson from VPN industry history: we link out to a provider's own policy pages and any real audit reports we can point to, and we deliberately leave a pricing or rating claim blank rather than restate a marketing number as an independently verified fact.

What does the current state of VPN technology look like today?

Today's VPN landscape is best understood as a settled-but-still-evolving descendant of everything covered above, rather than a fresh start. WireGuard, or a proprietary implementation built on top of it, functions as the default protocol at most major providers, valued for its speed and its comparatively small, auditable codebase. OpenVPN remains widely available as an alternative, particularly valued for its TCP-443 obfuscation capability on restrictive networks. IKEv2/IPsec persists as a strong option for mobile devices that move between networks frequently. PPTP, by contrast, has essentially aged out of the mainstream entirely, retained (where it's retained at all) mostly for legacy compatibility rather than as a genuine recommendation.

On the market side, the industry has consolidated somewhat around a smaller number of larger, better-resourced providers investing in independent security audits, broader server networks, and increasingly bundled security products — password managers, ad blockers, and antivirus tools sold alongside the core VPN connection. That consolidation and feature-bundling trend is its own story; see our guide on VPN industry consolidation for more on how the competitive landscape has shifted in recent years.

Where is VPN technology headed next?

A few active areas of development are worth knowing about as extensions of the history already covered, while being honest that none of them represent settled, universally deployed facts yet.

Post-quantum cryptography is an active area of engineering work across the industry, driven by the long-term theoretical concern that a sufficiently advanced future quantum computer could eventually break the public-key cryptography — including the elliptic-curve key exchange methods used in WireGuard and modern IPsec implementations — that current VPN protocols rely on. Some providers have begun layering post-quantum key-exchange methods on top of their existing protocols; this remains an evolving, provider-by-provider effort rather than an industry-wide finished feature, and it's worth reading our dedicated guide on post-quantum encryption and VPNs for a fuller technical picture.

Decentralized VPN architectures, which distribute server operation across many independent node operators rather than a single company's own infrastructure, represent another experimental direction, aimed at reducing the amount of trust concentrated in any single provider. This approach is still early-stage relative to the traditional centralized-provider model that has dominated VPN history to date; see our guide on decentralized VPNs explained for more detail on how that model actually works and where it currently falls short of mainstream providers on practical grounds.

More broadly, the trend line running through the entire history of VPN technology — from PPTP's convenience-first design, through IPsec's rigor, through OpenVPN's open-source transparency, to WireGuard's minimalism — points toward continued pressure in the same general direction: smaller, more auditable, more independently verified engineering, rather than large, complex systems asking users to simply trust a vendor's word. That pattern is a reasonable lens for evaluating whatever the next major shift in VPN technology turns out to be.

What can VPN history actually teach you about choosing a provider today?

A decades-long engineering history like this one isn't just trivia — it offers a genuinely useful framework for evaluating a modern VPN provider rather than just trusting whichever one has the loudest advertising. A few concrete lessons carry over directly.

Protocol maturity and independent scrutiny matter more than a protocol simply being new. PPTP's history is a cautionary tale about convenience outpacing security review; WireGuard's history is a counterexample of a young protocol that earned trust quickly specifically because it went through rigorous, verifiable, independent review rather than asking to be trusted on reputation alone. When evaluating a provider, it's worth checking whether they support well-established, independently reviewed protocols like WireGuard, OpenVPN, and IKEv2/IPsec, rather than only a proprietary, unreviewed protocol with no external validation.

Open-source components tend to earn trust for good reason. OpenVPN's decades of relevance and WireGuard's fast rise both trace substantially back to being open, publicly auditable software rather than a closed, proprietary black box — a pattern worth favoring when a provider gives you the choice.

Marketing claims and verified facts are two different things, and VPN history's own marketing excesses — surveillance-anxiety-driven advertising, superlative claims not always backed by independent verification — are a good reminder to check a provider's actual, current policy pages, published audit reports, and documented protocol support directly, rather than taking a homepage's summary of them at face value. This site links directly to providers' own policy and audit documentation wherever we reference it, for exactly that reason. You can review current options for two of the longer-established providers discussed in this article's history — NordVPN and Proton VPN — directly on their review pages.

Practical takeaway

The history of VPN technology runs from Microsoft's PPTP in 1996 through IPsec's more rigorous enterprise engineering, through OpenVPN's open-source transparency starting in 2001, through the smartphone-driven rise of IKEv2/IPsec, to WireGuard's minimalist redesign after 2015 — and in parallel, a separate market story of VPNs shifting from a corporate remote-access tool into a mainstream consumer privacy and streaming product over the course of the 2010s. Neither the protocol lineage nor the market shift happened all at once, and neither is fully finished: post-quantum cryptography and decentralized architectures are the current frontier, built the same way every prior shift in VPN history was — on top of what came before, tested by independent scrutiny, rather than replacing it wholesale. Understanding that lineage is genuinely useful when evaluating a provider today, because the same pattern that separated PPTP's early convenience from WireGuard's earned credibility — independent review over marketing claims — still separates a well-engineered VPN provider from an overhyped one now.

Frequently asked questions

When was the first VPN protocol invented?

The most commonly cited starting point is 1996, when engineers at Microsoft developed PPTP (Point-to-Point Tunneling Protocol) to let remote employees securely connect back to a corporate network over the internet. It shipped with Windows 95's OSR2 update and later Windows NT, making it the first VPN protocol most IT administrators encountered. Standards-body work on related tunneling and security protocols, including early IPsec RFCs, was happening around the same period.

Were VPNs originally built for businesses or for individual privacy?

Businesses. Early VPN technology — PPTP, IPsec, and later L2TP/IPsec — was built to let remote employees and branch offices securely reach a company's private network over the public internet, replacing expensive dedicated leased lines. The idea of an individual buying a VPN subscription for personal privacy or streaming access didn't become a mainstream consumer product until roughly the mid-2000s through the 2010s.

Why did OpenVPN become so widely used?

OpenVPN, released in 2001, was free, open-source, and cross-platform at a time when many alternatives were proprietary or tied to a specific operating system. Its open-source code let it be independently audited rather than requiring trust in a single vendor's claims, and its ability to run over TCP port 443 let it disguise VPN traffic as ordinary HTTPS web traffic on networks that tried to block VPN use. Those factors made it the default choice for most consumer VPN providers for roughly a decade and a half.

What made VPNs become popular with everyday consumers instead of just businesses?

Several trends converged over the 2010s: broadband internet became fast enough that VPN encryption overhead stopped mattering for everyday use, public Wi-Fi use on smartphones grew along with awareness of how easily it could be intercepted, streaming services began licensing content differently by country, and 2013's revelations about government mass surveillance programs pushed broad public attention toward internet privacy. VPN providers packaged existing protocols into simple one-click consumer apps to meet that demand.

Is PPTP, the original VPN protocol, still safe to use today?

No. Security researchers documented weaknesses in PPTP's authentication scheme as early as the late 1990s, and by the 2010s it was widely considered broken by security-research standards — practically exploitable under realistic conditions, not just a theoretical concern. Most credible VPN providers moved away from recommending PPTP years ago, even though some operating systems retained it for legacy compatibility.

How does WireGuard fit into the broader history of VPN technology?

WireGuard, developed starting around 2015-2016 and merged into the mainline Linux kernel in 2020, is the most recent major turning point in VPN history. It replaced the large, highly configurable designs of OpenVPN and IPsec with a small, fixed, thoroughly auditable codebase, and it became the default protocol at most major providers within about five years of its creation. See our dedicated guide on why WireGuard became the default VPN protocol for the full story.