# HypoMux: a Windows multi-NIC bandwidth aggregator that splits connections, not packets

> HypoMux is an AGPL-3.0 Windows tool that spreads concurrent downloads across Ethernet, Wi-Fi and phone tethering. It aggregates connections, not single TCP streams, and the README is explicit about that boundary.

**Hypostasis-Cat/HypoMux** — CN Windows 多网卡带宽叠加工具。无需复杂配置，一键聚合多网卡（有线、Wi-Fi网卡、手机热点等），实现物理级多线下载与叠加网速。 EN Windows multi-NIC bandwidth aggregator. Zero complex setup. One-click to combine multiple networks (Ethernet, Wi-Fi, mobile hotspots, etc.) for physical-level concurrent downloading and multiplied speeds.

- Repository: https://github.com/Hypostasis-Cat/HypoMux
- Stars: 3,648 · Forks: 129
- Language: Python
- License: AGPL-3.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/hypostasis-cat-hypomux

## The problem HypoMux targets: one Windows box, several idle links

Most Windows machines have more than one path to the internet and use exactly one of them. A laptop on Ethernet with Wi-Fi also associated, a desktop with a USB tether from a phone, a machine with a Wi-Fi card and a hotspot: Windows picks a route and the rest of the links sit idle. HypoMux exists to put those links to work at the same time.

The audience is narrow and specific. It is Windows-only. It assumes at least two active adapters, because with one adapter there is nothing to distribute. It assumes the workload is a downloader that opens many sockets, since the README states plainly that HypoMux aggregates multiple independent connections rather than splitting a single TCP connection into several paths. Steam, IDM, Epic Games Launcher, EA App, Xbox, WeGame, and large browser downloads are the named cases.

That framing matters more than any feature list. If you want one big file to move faster than your fastest line, this is the wrong tool by the project's own description. If you want two lines' worth of throughput on a workload that already opens dozens of connections, the design is aimed directly at you.

## System proxy mode versus virtual NIC mode: two different interception points

HypoMux offers two ways to capture traffic, and they are not interchangeable.

System proxy mode starts a local HTTP/HTTPS proxy on port 10801 and a SOCKS5 proxy on port 10800, then writes that proxy chain into the current user's Windows Internet Settings. Only applications that honor the system proxy are captured. The README calls this the lighter option: no virtual adapter is created, and resource use is lower. IDM, browsers and Steam fall into this group.

Virtual NIC mode uses Wintun and sing-box, combined with WFP, DNS and routing rules, to capture a wider set of TCP and UDP traffic including applications that ignore the system proxy. It requires the Core service, Wintun and WFP, and the README states it cannot coexist with another TUN that claims the default route. Game platform downloads and complex per-process splitting are the intended cases.

The architecture separates the two privilege levels. Since 2.5.0 the desktop is Go with Wails v3, React and Fluent UI, and it runs with ordinary user rights. TUN, WFP, routing, DNS and network recovery are handled by a separate Go Core/Windows service that holds the network-management privileges. The README describes the 2.5.0 work as validating adapters, DNS, the privilege service, Wintun, sing-box, WFP and third-party TUNs before startup, and blocking startup or rolling back before touching system networking when validation fails. That pre-flight ordering is the most interesting design decision in the project: it treats a half-applied network configuration as the failure to avoid.

## How per-connection egress selection actually works

The engine's job is to choose an outbound adapter for each new connection, then pin that socket so it stays there. The README describes the mechanism as combining local source-address binding with the Windows interface index through `IP_UNICAST_IF`. In other words, the socket is bound to a real physical link at creation time rather than being routed by the kernel's default route.

A rule layer decides which link a connection gets, or whether it gets aggregated at all. Rules can match by process, by domain and subdomain, and by destination IP or CIDR, and can direct traffic to aggregation, to a direct connection, to Ethernet, to Wi-Fi, or to one named adapter. The README notes that multi-value rules in older configuration files are migrated item by item.

There is also a per-link memory. The README describes recording domains that a particular link cannot reach, so later connections are not assigned to a link already known to fail for that destination. That is a small piece of state with a large effect on the user experience, because without it a bad link would keep receiving connections that then time out.

Third-party proxy compatibility is handled the same way, by identity rather than by name. The README says running programs are matched first by full executable path, and that local system-proxy listeners are resolved back to a PID by port, specifically to avoid relying on process names that change between versions. UU, Xunyou, Leigod, Qiyou, Clash/Mihomo, v2rayN, Hiddify, Shadowsocks and Proxifier are named as recognized process families.

## Installing HypoMux and running a first aggregation

There is no package manager install. The README points to the Releases page on GitHub and to a Tencent CNB mirror for mainland China, and says both distribute the same SignPath-signed installer. Download the latest `HypoMux_Setup_*.exe` and confirm the publisher shows as SignPath Foundation after installation, since that is the check the project itself asks for.

Building from source is documented separately and is heavier. The README lists Windows 10/11, Go 1.26, Node.js 22, pnpm 10 and the Wails v3 CLI `v3.0.0-alpha2.119`, plus NSIS for the installer. The repository root's `bin/` directory must contain `sing-box.exe`, `wintun.dll` and `libcronet.dll`, which the README calls the official runtime files. The build sequence given in the README is:

```powershell
go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-alpha2.119
pnpm --dir desktop/frontend install --frozen-lockfile
Push-Location desktop
wails3 generate bindings -clean=true -ts -i
Pop-Location

go -C engine test ./...
go -C desktop test ./...
pnpm --dir desktop/frontend build

Set-Location desktop
wails3 dev
# 或构建 NSIS 安装包
wails3 task windows:package
```

For ordinary use, the README's quick-start sequence is the real tutorial. Connect at least two working networks, for example wired broadband plus Wi-Fi, or broadband plus a phone USB or hotspot share. Start HypoMux, refresh the home page and tick the active adapters you want in the aggregation pool. Run the network health check and confirm each link has a valid IPv4 address, gateway, DNS and working source-address binding. Pick system proxy or virtual NIC mode, and add latency-sensitive games, voice and conferencing programs to the direct-connect rules first. Then start the aggregation engine and launch the download. If Steam is already running, the README says to restart it so the proxy settings apply fully. When you are done, stop aggregation or exit normally and HypoMux restores the system proxy and network settings it took over.

One practical note from the README: do not let two programs fight over the Windows system proxy switch. If you use HypoMux system proxy mode, turn off the other program's system proxy takeover. If another program has created its own TUN or VPN adapter and owns the default route, close it before starting HypoMux virtual NIC mode; the README says HypoMux detects and blocks that conflict before modifying system networking.

## Where HypoMux stops: connection-level distribution and its consequences

The central limitation is stated by the project itself. Aggregation is connection-level load distribution. It does not let one TCP connection exceed the speed of the link it is on, and it does not turn several lines into a link-aggregation protocol with a single public IP. A downloader with one connection to one server gains nothing. A downloader with sixteen connections gains whatever the sum of the links can carry, minus overhead.

The second limitation is latency. The README says aggregation targets throughput and does not promise lower latency, and recommends direct-connect rules or pausing aggregation for competitive games, voice and video calls. Spreading connections across links with different round-trip times and jitter profiles is a throughput play, not a latency play, and the documentation does not pretend otherwise.

The third is coexistence. Virtual NIC mode cannot share the default route with another TUN. Third-party accelerators that install their own virtual adapter must be closed first. Two programs cannot both own the Windows system proxy switch. These are not bugs to be worked around; they are boundaries of the interception model.

The fourth is scope. HypoMux is Windows-only, and the README's compliance note restricts use to devices and networks you own or are authorized to use, and says it should not be used to bypass third-party access controls, network restrictions, platform rules or security measures. It also notes that while HypoMux does not read game memory, inject DLLs or modify game protocol packets, third-party platforms and anti-cheat rules differ and users remain bound by their terms of service. For a competitive online game, the project's own advice is to put it on the bypass list or pause the tool.

## Alternatives: what connection-level aggregation is not

The honest comparison is not another download accelerator. It is the class of tools that do per-packet or per-flow aggregation with a remote endpoint, such as multipath routing setups built on a VPS with MPTCP or a tunnel that terminates both ends. Those approaches can, in principle, present a single logical link, because a server on the far side reassembles the streams. They also require that server, a stable public address, and configuration on both ends. HypoMux has none of that: no remote endpoint, no server to run, no account. It works entirely between your machine and whatever the destination already is, which is why it cannot merge a single connection and why it needs no infrastructure.

Against a plain proxy client such as Clash/Mihomo or v2rayN, the difference is intent rather than mechanism. Those route traffic through a chosen proxy; HypoMux routes new connections across your own physical adapters and treats those proxy programs as processes to be identified and bypassed so they do not loop into each other. If your goal is to reach a remote network, HypoMux is not that tool. If your goal is to use the links you already have, it is.

Against simply bonding adapters in Windows or at the switch, the difference is that native bonding requires support on the other end and typically a single logical interface. HypoMux instead keeps the adapters separate and makes the choice per connection, which is why it works with a phone hotspot that no bonding configuration could include.

## Maintenance, licence and what upgrading costs you

The repository is not archived, and the last push was on 2026-08-28, which is the same timestamp as release v2.5.8. Releases v2.5.7 and v2.5.6 precede it on 2026-08-17 and 2026-08-16, so the project has been shipping frequently in the weeks before that push. The README describes the maintainer as a student working in spare time, and the 2.5.0 notes describe a full migration from Python/Qt and an interim WPF implementation to Go with Wails v3, React and Fluent UI. That migration is the main upgrade cost: anyone on a pre-2.5.0 build is moving between runtimes, not just version numbers.

Updates are not ambient. The README says update metadata is distributed through a separate signed update channel verified with Ed25519, and the client then checks the installer's size, SHA-256 and Windows Authenticode signature. That is a chain worth understanding before you point a machine at it, because it means update trust rests on a signing key and a manual approval step: the README states that every production signing request is manually approved in the SignPath UI.

The licence is AGPL-3.0. For an end user running the installer on their own Windows machine, that is unremarkable. For anyone who wants to embed the engine in a product, offer it as a service, or ship a modified build, the copyleft terms and the network-use clause are the thing to read before writing code, and the repository's LICENSE file is the authoritative text. This is a description of the licence, not legal advice.

The privacy position is stated in the README: no personal data or telemetry is collected, sold or uploaded. The program communicates with other network systems only when a requested feature needs it, forwarding the traffic the user selected, checking the signed update channel, downloading installers from GitHub or CNB, and verifying connectivity after virtual NIC mode is enabled. If your environment forbids outbound update checks, that is a configuration question the README does not answer, and it does not document a rollback procedure for a failed upgrade.

## Conclusion

Adopt HypoMux if you run Windows with two or more live links and your workload is many parallel connections: Steam updates, IDM, WeGame, large browser downloads. Do not adopt it expecting a single TCP stream to exceed one line's speed, and do not run it alongside another TUN or VPN that owns the default route. Before trusting it, confirm the installer publisher reads SignPath Foundation, run the built-in network health check so every link has a valid IPv4 address, gateway, DNS and source-address binding, and put latency-sensitive games and voice apps in the direct-connect rule list first.

## FAQ

### What is HypoMux and which Windows setups is it meant for?

It is an open source Windows multi-NIC aggregator that assigns concurrent download connections across several active adapters, so wired broadband, Wi-Fi and phone tethering can carry traffic at the same time. It suits high-concurrency downloads such as Steam updates, IDM, WeGame and large browser downloads, and requires at least two active links to do anything.

### Does HypoMux make a single download faster than my fastest line?

No. The README states that HypoMux aggregates multiple independent connections rather than splitting one TCP connection into several paths, so a single-connection task remains limited by the link it uses. Speed gains come from summing many parallel connections across adapters.

### Which ports does HypoMux use in system proxy mode?

The README's architecture diagram shows the local HTTP/HTTPS proxy on port 10801 and the SOCKS5 proxy on port 10800, with the proxy chain written into the current user's Windows Internet Settings. Only applications that follow the system proxy are captured in this mode.

### Can HypoMux run at the same time as another VPN or game accelerator?

Not if that program owns the default route with its own TUN or VPN adapter; the README says to close it first, and that HypoMux detects and blocks this conflict before modifying system networking. Two programs also should not both take over the Windows system proxy switch.

### How do I install HypoMux?

Download the latest HypoMux_Setup_*.exe from the GitHub Releases page or the Tencent CNB mirror, both of which the README says distribute the same SignPath-signed installer. After installing, confirm the publisher shows as SignPath Foundation.

## Sources

- [Official README](https://github.com/Hypostasis-Cat/HypoMux#readme)
- [Project repository](https://github.com/Hypostasis-Cat/HypoMux)
- [Release notes](https://github.com/Hypostasis-Cat/HypoMux/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/hypostasis-cat-hypomux
