# chili-chips-ba/wireguard-fpga

Full-throttle, wire-speed hardware implementation of Wireguard VPN, using low-cost Artix7 FPGA with opensource toolchain. If you seek security and privacy, nothing is private in our codebase. Our door is wide open for backdoor scrutiny, be it related to RTL, embedded, build, bitstream or any other aspect of design and delivery package. Bujrum!

Repository: https://github.com/chili-chips-ba/wireguard-fpga
Canonical: https://ross.abutalabs.com/products/wireguard-fpga
Homepage: https://nlnet.nl/project/KlusterLab-Wireguard
Language: Verilog
License: BSD-3-Clause
License Family: permissive
Topics: cocotb, embedded, fpga, iss, risc-v, rtl, verilator, verilog, vpn, wireguard, vproc
Last push: 2026-08-26T13:57:15+00:00

## Health v2 (maintenance only)
Score: 68/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 36, longevity 55
- inputs: {"age_days": 781, "days_push": 7, "days_rel": 218, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1355, forks 35 (observed 2026-08-28T04:04:29.161925+00:00)

## What it is
An open-source, wire-speed hardware implementation of the WireGuard VPN protocol on a low-cost Artix-7 FPGA, written in Verilog with an open-source toolchain (OpenXC7, Verilator, cocotb). It builds a complete hardware-software SoC including a RISC-V CPU and open Ethernet IP for secure, high-throughput tunneling.

## Use cases
- implement wireguard vpn in hardware on an fpga
- line-rate encrypted vpn tunneling beyond software performance
- open-source verilog wireguard gateware for security auditing
- learn fpga networking and rtl design with a real project
- build a low-cost hardware vpn appliance with 1g ethernet ports
- verify no backdoors in a vpn implementation via open rtl

## When to choose
- you need wireguard throughput that software implementations cannot reach
- you require a fully open, auditable hardware VPN stack with no proprietary IP blocks
- you want an affordable FPGA platform (Artix-7) supported by open-source tooling
- you are studying or teaching hardware security and RTL networking

## When to avoid
- you just need a working VPN on general-purpose hardware - use standard WireGuard software
- you need a turnkey product with vendor support or certification
- you lack FPGA hardware or interest in working with HDL toolchains
- you need multi-100G throughput like the proprietary Alveo-based solutions

## Facets
- artifact type: library
- maturity: active
- function: vpn, cryptography, networking, security, embedded
- domain: security, networking, privacy, hardware, embedded-systems
- platform: embedded, self-hosted
- tags: wireguard, fpga, verilog, risc-v, rtl, cocotb, verilator, open-source-hardware, artix-7, nlnet, linux

## Member repositories
- chili-chips-ba/wireguard-fpga (main) score 68

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:29.161925+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:41:57.441146+00:00, confidence not recorded.
  - readme: https://github.com/chili-chips-ba/wireguard-fpga (fetched 2026-08-28T04:04:29.161925+00:00, sha 6b2fe4be5877)
  - homepage: https://nlnet.nl/project/KlusterLab-Wireguard (fetched 2026-08-29T12:00:14.324825+00:00, sha 2b47fb3736e6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
