KotoVPN

Guide · Updated August 15, 2026

When Double VPN and Onion over VPN are worth it

Is Double VPN or Onion over VPN worth using?

Is Double VPN or Onion over VPN worth using?

Double VPN and Onion over VPN are not worth it for most people: a second hop costs throughput and defends one narrow threat. It stops one of the two servers being compromised or compelled from exposing you, and does nothing about accounts you sign into, fingerprinting, or an adversary watching both ends.

Is Double VPN or Onion over VPN worth the speed cost?

For almost everyone reading this, no. A second hop buys protection against one specific failure — a single server in the path being compromised, seized or compelled to give up what it saw — and charges a large share of your connection speed for it. If you cannot describe a plausible situation in which one server in your path is taken and the other is not, you are paying a real cost for a benefit that does not apply to you.

That is a much narrower claim than the feature names imply. "Double" suggests twice the security, and it is not that. The encryption is no stronger, the provider is no more trustworthy, and none of the things that actually identify people online are touched. What changes is the number of separate machines an attacker has to reach before they can join up the two halves of the picture: who you are, and where you went.

The cost is not a rounding error. Traffic is encrypted twice, decrypted at two points, and routed through servers that are usually in different countries by design, so distance rises along with processing. Proton VPN lists that throughput cost in its own documented limitations rather than leaving reviewers to find it. We publish no speed figures of our own for it, because we run no speed tests — our lab pages are deliberately empty and say so, and an invented number would be worse than none.

What does a second hop actually defend against?

In an ordinary tunnel, one server sees both halves at once: the address you connected from, and the destination you asked for. The whole privacy promise rests on that server not writing the pair down. Add a hop and the halves separate. The entry server sees your real address and an encrypted onward connection it cannot read. The exit server sees the destination and a request that appears to arrive from another server rather than from you.

So the threat this defeats is narrow and specific: somebody obtaining what a single machine in the path holds. That covers a server seizure, an intrusion into one datacentre, a host compelled to mirror traffic at one site, or a passive observer sitting on one leg — your local network and the entry server, say, but not the exit. In each case an attacker gets half the pair, and half the pair cannot say where you went.

What multi-hop does not change is that both machines usually belong to one company. The guarantee is that no single server holds both halves, not that no single party does. The provider still operates both ends, controls the software on both, and answers legal process in one jurisdiction. Tor’s three-relay design differs structurally right here: the relays are run by unrelated volunteers, so collusion requires several parties rather than one company’s internal decision. A commercial double hop is one administrative domain with two addresses in it.

That is why the provider’s evidence matters more than the feature does. NordVPN’s 2025 no-logs assurance engagement with Deloitte, carried out from 10 November to 12 December 2025 under ISAE 3000 (Revised), states its scope as the no-logs claim across "standard, Double VPN, Onion over VPN and obfuscated servers". The feature sat inside the audit boundary rather than beside it. Most multi-hop marketing rests on an audit of the ordinary fleet with the special servers unmentioned, which leaves readers assuming a conclusion the auditor never reached. Naming the server types in the scope is the difference between a claim and a checked claim.

Separation is the other thing that decides whether a second hop means anything. Two servers in the same rack, on the same hardware, reachable with the same operator credentials, raise nobody’s costs. Two hops in different countries with different hosting and different legal exposure do. That is a question about infrastructure, not about a toggle in an app.

What does multi-hop not defend against?

Almost everything that actually deanonymises people. The feature is sold as a general-purpose upgrade and it is nothing of the kind.

It does not help if you are signed in. The moment you log in, you have told the service who you are, and the number of servers your request passed through is irrelevant. A second hop protects the association between your address and your destination; if the destination already knows your name, that association was never the weak link. Browser fingerprinting and advertising identifiers behave the same way — fonts, screen dimensions, timezone and graphics behaviour identify your browser whether the packets took one hop or two, because all of it operates above the network layer a VPN works on.

It also does not defeat end-to-end correlation. An adversary who can watch traffic entering your line and traffic leaving the exit server does not need to break any encryption: the pattern of packet timing and volume matches one to the other. A hop in the middle adds nothing to that analysis, because the two ends being compared are the same two ends. Multi-hop raises the cost for an adversary who can see one end and does nothing at all for one who can see both. That is the honest boundary of the feature, and it is the one most guides skip.

Nor does it repair the provider trust question. A second hop is worthless if the operator retains records at either end, and records appear in unglamorous places. When KPMG examined PureVPN across all protocols in February 2023, it found the service broadly compliant but flagged origin IP addresses appearing in the error logs of failed manual connections, plus some logs holding first- and last-connection times with a connection count. PureVPN says both were remediated and verified. The lesson for anyone weighing a second hop is that logging failures live in error paths, not in the tidy diagram, and doubling the servers doubles the places an edge case can be written down.

The gap in evidence between providers matters for the same reason. FastestVPN has one published audit, by Altius IT, covering 15 December 2022 to 29 January 2023 and never repeated, and its scope explicitly excluded security safeguards and privacy controls at third parties. A feature that depends entirely on two servers behaving as described should only be bought from an operator whose behaviour has been checked recently, in a scope that includes the thing you are relying on.

Avoid

  • Turning on a second hop as a general precaution, with no named threat that a single compromised server would create
  • Believing "Double VPN" means double the encryption strength — the cipher is unchanged, only the path is longer
  • Expecting multi-hop to defeat correlation by an adversary who can observe both ends of the path, which it does not
  • Assuming the feature is covered by a provider’s no-logs audit when the published scope names only standard servers
  • Using it to hide activity from a service you are logged into, where the tunnel is not the identifying link

Why is Onion over VPN a different trust arrangement, not extra security?

Onion over VPN — Tor over VPN, in the more literal name — sends your traffic through the VPN tunnel first and into the Tor network second. Providers offer it as a server type you pick in the app, and the pitch is that you get the VPN’s protections and Tor’s anonymity at once. That framing is wrong in a way worth spelling out: it does not add a layer of security, it moves one specific piece of knowledge from one party to another.

Without a VPN, your ISP can see that you are connecting to Tor — not what you do inside it, but the fact of it, which on some networks and in some countries is itself the notable event. Put a VPN in front and your ISP sees an ordinary encrypted connection to a VPN server. Tor’s entry guard, which would normally see your real address, now sees the VPN server’s address. Both changes are real. But your VPN provider now knows you use Tor, and holds the position the guard used to hold with respect to you. You have not gained a party who cannot see you; you have swapped which party can. Whether that is an improvement depends on which of the two you would rather be identifiable to — an ISP in your country that holds your billing details, or a company whose jurisdiction, logging policy and audit record you have actually checked.

The Tor Project is more cautious about this than VPN marketing acknowledges. Its support documentation says it does not recommend using a VPN with Tor unless you are an advanced user who knows how to configure both without compromising your privacy, and warns that in practice the combination can reduce anonymity or break Tor’s protections if configured wrongly. That is the organisation that builds the anonymity network saying the combination is not free, and it is worth reading before anyone’s affiliate-funded recommendation, including ours.

There is a second problem specific to the provider-run version. Selecting an Onion over VPN server routes your ordinary browser into Tor — but you are not using Tor Browser, and Tor Browser is where most of Tor’s anonymity comes from. It normalises your fingerprint against everyone else’s, isolates circuits per site, and blocks a long list of identifying browser behaviours that a VPN can do nothing about. Routing Chrome through Tor gives you Tor’s latency with Chrome’s fingerprint. If your reason for wanting Tor is anonymity rather than reaching an .onion address, the right tool is Tor Browser used on its own.

Which providers we cover actually offer a second hop?

Two of the four, documented differently enough to be worth separating.

Proton VPN calls its version Secure Core, and it routes through a second hop in Switzerland, Iceland or Sweden before reaching the exit. The choice of countries is the design: those three make compelling an operator harder than most places do, so the hop that sees your real address sits in a jurisdiction chosen to be awkward to lean on. Proton is itself Swiss and has published five consecutive annual no-logs audits by Securitum from 2022 through 2026, with full reports rather than summaries, so the operator holding that entry position is among the better-evidenced ones available. Proton also lists Secure Core’s throughput cost in its limitations while listing the feature in its strengths — a small thing, but more than most vendors manage.

NordVPN ships both Double VPN and Onion over VPN as server categories, and the useful fact is the audit scope quoted above: Deloitte’s December 2025 engagement named those server types explicitly, the most recent of six no-logs engagements since 2018 and the fourth under ISAE 3000 (Revised). That is not proof about the particular server you connect to on a given day, and no audit is. It is evidence that when an outside firm looked, the special servers were inside the boundary being looked at.

PureVPN and FastestVPN are not part of this discussion in any documented way, and we would rather say so than pad the comparison. PureVPN’s relevant history runs the other direction: in 2017 it supplied user connection logs to the FBI in a criminal case while advertising a no-logs policy, which is why it scores 4 out of 10 for transparency in our rubric. No number of hops compensates for an operator that keeps records, because the operator sits at both ends of them.

What we cannot tell you is how much speed you will lose, and provider-published multi-hop figures are marketing. Use the refund window as the measurement instead — 30 days at both Proton VPN and NordVPN, long enough to run a week of real work over Secure Core or Double VPN and find out whether the loss is tolerable on your line, to the destinations you actually use.

When is a second hop the right answer?

There is a real list, and it is short. These are the cases where the narrow threat multi-hop addresses is the threat you actually have.

  • You are a journalist, researcher or source whose adversary could plausibly compel or compromise a single datacentre, and you need the entry server’s knowledge and the exit server’s knowledge held in different legal territories
  • You are on a network whose operator you consider actively hostile rather than merely nosy, and you want the entry hop somewhere that operator cannot easily reach
  • You want the fact of your Tor use hidden from your ISP specifically, and have decided your VPN provider is the safer of the two to reveal it to
  • You need an .onion address occasionally and accept that a provider-run Onion server gives you Tor routing without Tor Browser’s protections

What should most readers do instead?

If none of those describe you, spend the effort where the exposure actually is. Sign out of accounts you do not want a session associated with, use a browser that resists fingerprinting for the browsing you care about, and keep the ordinary tunnel on a provider whose no-logs claim has been checked recently by a named firm in a scope you can read. Those three changes affect more of your real exposure than any number of hops.

If you already pay for a provider that includes a second hop, the reasonable position is to leave it off by default and switch it on for the specific session where the narrow threat applies — whatever prominence the toggle is given in the app.

Questions

Is Double VPN worth it?
Rarely. It defends against one server in your path being compromised, seized or compelled, and charges a large share of your speed for it. It does not strengthen encryption, make the provider more trustworthy, or affect logged-in accounts and fingerprinting. Switch it on for a specific session with a specific threat, not as a default.
Does Double VPN make you anonymous?
No. It separates who you are from where you went across two servers, but both servers usually belong to one company in one jurisdiction. Anything identifying you above the network — an account login, a browser fingerprint, an advertising ID — is unaffected. Tor distributes trust across unrelated operators; a commercial double hop does not.
Is Onion over VPN safer than using Tor Browser?
Not for anonymity. It hides Tor use from your ISP and reveals it to your VPN provider, which is a different trust arrangement rather than an extra layer. It also routes an ordinary browser through Tor, so you lose the fingerprinting resistance and circuit isolation that supply most of Tor Browser’s protection.
Does the Tor Project recommend using a VPN with Tor?
No. Its support documentation says it does not recommend using a VPN with Tor unless you are an advanced user who can configure both without compromising your privacy, and notes that in practice the combination can reduce anonymity or break Tor’s protections if set up wrongly. Read that page before any VPN marketing.
Which VPNs here offer multi-hop, and is it audited?
Proton VPN’s Secure Core routes through a second hop in Switzerland, Iceland or Sweden and lists the throughput cost in its own limitations. NordVPN offers Double VPN and Onion over VPN, and Deloitte’s December 2025 no-logs engagement named those server types in its scope, which is unusual evidence that the feature was inside the audit boundary.

Terms used here

Multi-hop

Routing traffic through two VPN servers in sequence, usually in different countries.

Tor over VPN

Connecting to the Tor network through a VPN tunnel, so your ISP sees a VPN connection rather than Tor usage.

Jurisdiction

The country whose law governs the company operating the VPN, which determines who can compel it and by what process.

Server seizure

Physical confiscation of a VPN server by authorities, usually at the datacentre rather than from the provider.

No-logs policy

A provider’s commitment not to record which sites you visit, when you connected, or what address you connected from.

Throughput retention

The share of your unencrypted line speed that survives once the VPN is connected, expressed as a percentage.

Related