Hysteria: The "Brutal" Protocol That Refuses to Slow Down

While the rest of the web politely yields to network congestion, Hysteria 2 uses a customized QUIC transport to punch through censorship and throttled networks.

• View on GitHub • More from apernet

An editorial illustration of a massive snowplow clearing a path through a storm of pixelated debris, representing Hysteria forcing its way through a congested network.
Standard protocols slow down when they encounter packet loss. Hysteria treats loss as a lie and accelerates.

So Hysteria began as an attempt to improve my speed for watching YouTube videos.

Toby, lead developer of Hysteria · Meet the Developer: Hysteria - Xeovo Hub

Key Takeaways

The Politeness Trap

Standard TCP congestion control algorithms operate on a gentleman's agreement. When packets drop, the sender assumes the network is congested and politely slows down. Censors and throttled ISPs exploit this behavior by artificially dropping packets, triggering a death spiral of degraded performance that renders connections unusable.

Hysteria throws this politeness out the window. By leveraging a custom congestion control algorithm aptly named "Brutal," it ignores packet loss entirely. Instead of reacting to dropped packets by throttling back, Brutal maintains a user-defined, fixed transmission rate. It treats the network like a fixed-width pipe, forcefully shoving data through regardless of how much is discarded along the way.

How Hysteria's 'Brutal' algorithm ignores packet loss to maintain high throughput.

From Dragonite to Hysteria

The architecture behind Hysteria was born out of utility rather than academic theory. Lead developer Toby initially built the underlying concepts, originally named Dragonite, to solve a highly personal problem with poor international routing.

Portrait of Toby, lead developer of Hysteria.

The transition to Hysteria 2 represented a major architectural shift. The project moved to a Go Workspace structure, cleanly separating the core protocol logic from the application layer. This modularity allowed the team to refine the QUIC transport implementation and introduce advanced evasion techniques.

Hiding in a 233 Status Code

Brute force is useless if the firewall simply blocks the port. To avoid detection by Deep Packet Inspection, Hysteria heavily relies on masquerading. To an outside observer, a Hysteria server looks and acts like a perfectly standard HTTP/3 web server.

If a censor or unauthorized scanner probes the server, it responds with a 200 OK and serves a normal web page. The magic only happens when an authorized client sends a specific HTTP/3 POST request containing the correct authentication headers. The server then responds with a non-standard HTTP 233 status code, upgrading the connection and opening the high-speed proxy tunnel.

An editorial illustration showing a wall with a peephole. Through the peephole, a boring static webpage is visible. Behind the wall, a massive, high-speed data turbine is spinning rapidly.
Hysteria server masquerades as a standard HTTP/3 website to unauthorized probes.

Solving the UDP MTU Headache

Because Hysteria runs on QUIC, it natively supports sending UDP traffic without the performance penalties of "UDP over TCP" solutions. However, QUIC imposes strict Maximum Transmission Unit limits. If an application tries to send a large UDP packet that exceeds the QUIC MTU, it drops.

Hysteria solves this with a Try-and-Fallback fragmentation engine. When the core intercepts a UDP packet, it attempts to send it as a single QUIC datagram. If the underlying transport rejects it as too large, Hysteria catches the error, slices the packet into smaller fragments, assigns them IDs, and reassembles them on the receiving end. This allows Hysteria to handle maximum-size UDP packets seamlessly.

Speed vs. Stealth

The proxy landscape is divided between tools that prioritize blending in and tools that prioritize raw throughput. Hysteria firmly occupies the latter category, making it uniquely suited for networks with high packet loss.

ProtocolPrimary FocusUnderlying TransportPerformance on Lossy Networks
Hysteria 2Raw SpeedCustom QUIC (UDP)Excellent (Ignores packet loss)
Xray (Reality)Stealth / EvasionTCP / TLSModerate (Subject to TCP bottlenecks)
NaiveProxyActive Probing DefenseChrome Network StackPoor (Limited by browser congestion control)

While tools like NaiveProxy offer superior stealth by perfectly mimicking a Chrome browser, they inherit Chrome's polite congestion control. In a highly throttled environment, stealth is irrelevant if the connection is too slow to load a text file. Hysteria chooses the pragmatic path: look just innocent enough to bypass the initial filter, then use brute force to win the race.