All news
cybersecurityproduct

Hulios: eBPF-Based Transparent Tor Gateway for Linux

28 Jul 2026

What Hulios Is

Hulios is a newly surfaced open-source tool that turns a Linux machine into a transparent Tor gateway using eBPF—kernel-level hooks that intercept and redirect traffic without requiring application-level configuration. Instead of routing individual apps through Tor via proxy settings, Hulios works at the network transport layer, redirecting TCP sockets and DNS queries system-wide through an embedded Arti Tor client and a localized Hickory-based DNS resolver.

The project is distributed via the Arch User Repository as hulios-git and has been tested and verified on Arch Linux and Debian 13 (Bookworm). It requires Linux kernel version 5.10 or higher, which may exclude older or more conservative enterprise systems still running legacy kernels.

How It's Built

Hulios's architecture centers on a few notable design choices:

  • Privilege separation: A root supervisor process handles the privileged eBPF operations, while unprivileged worker processes manage the rest of the runtime—reducing the attack surface if a component is compromised.
  • Fail-secure kill-switch: If the daemon crashes or is force-shut down, Hulios blocks all outgoing traffic via kernel policy tables rather than failing open and leaking unprotected traffic.
  • LSM eBPF hook: A Linux Security Module hook globally blocks raw AF_PACKET socket creation, closing off a common technique used to bypass traffic redirection.
  • Zero-config startup: On first run, Hulios automatically generates a default configuration file at /etc/hulios/config.toml.

The Limits, Clearly Stated

The project's documentation is notably upfront about what Hulios does not do—a level of transparency that stands out in privacy tooling:

  • Securing the network transport layer does not guarantee total anonymity.
  • Hulios does not strip application-level trackers, cookies, or browser fingerprinting configurations.
  • It cannot protect a system if an adversary gains root access and disables the eBPF programs or alters routing tables.
  • Traffic security still depends on the Tor network itself, including the risk of correlation attacks by entities controlling both entry and exit nodes.
  • The 5.10+ kernel requirement may limit compatibility with older systems.

What's Missing

Several important details are absent from the current documentation: there's no information on project maturity, release date, or version history; no performance benchmarks or latency data for the eBPF-based routing; no visibility into team size, maintainers, or funding; no stated license or contribution guidelines; and no data on adoption, user base, or independent security audits. Founders evaluating this tool should treat it as early-stage and unverified at scale until more of this context becomes available.

Why Founders Should Care

For founders building in privacy, security, or developer infrastructure, Hulios is a useful signal rather than a proven solution. It's plausible—though not confirmed—that kernel-level, eBPF-based privacy tooling represents a growing direction in the space, given the emphasis on transparent, system-wide protection over app-by-app configuration. The privilege-separated architecture and fail-secure kill-switch design likely reflect a broader pattern worth watching: security-conscious products increasingly building defense-in-depth into their core architecture rather than bolting it on.

The explicit, detailed risk disclosures may also hint at where user trust expectations are heading for privacy tools—transparency about limitations could become a differentiator rather than a liability. That said, with no audit history, no adoption data, and testing limited to just two distributions (Arch and Debian), founders should treat Hulios as an early signal, not a benchmark, and independently verify compatibility and security claims before considering similar tools or approaches for their own products.

Bottom Line

Hulios illustrates a technically interesting approach to system-wide Tor routing on Linux, but it remains an early-stage project with significant unknowns around maturity, backing, and independent validation. Founders in privacy or dev-tools spaces may want to track how eBPF-based approaches evolve, while treating this specific project as a reference point rather than a production-ready dependency.

Sources