China’s internet censors just closed one of the last doors that was still open. VLESS, a protocol built specifically to dodge censorship detection, is now being blocked inside China, months after a wave of server disconnections already wiped out most other circumvention tools. Users are calling the whole episode “the Great Unplug.”

What happened in April, and why it’s still going

Since April 2026, Chinese authorities have escalated their crackdown on the Great Firewall’s blind spots by physically pulling the plug on relay servers sitting in domestic data centers. Thousands of them went dark at once. The effect landed hardest on proxy services built around Shadowsocks, V2Ray, Trojan, and similar tools, protocols that circumvention communities had relied on for years precisely because they were harder to fingerprint than a standard VPN connection.

That first wave was already unusual for its scale. Normally the Great Firewall works by detecting and throttling traffic patterns. Cutting the physical connection to relay servers is a blunter, more permanent move, and it’s the reason people started calling it the Great Unplug rather than just another round of blocking.

Why VLESS mattered, and why it’s gone now

VLESS held out longer than the rest. It’s a lightweight protocol designed from the ground up to look like nothing in particular, stripped of the extra overhead that makes other protocols easier to spot, which is exactly why it became one of the few reliable options left standing after the April purge. For a few months, VLESS was close to the default recommendation in circumvention circles simply because so little else still worked.

That window has now closed. China has moved to block VLESS specifically, removing what had become one of the last dependable circumvention protocols still functioning at scale. There isn’t an obvious next protocol waiting in the wings the way VLESS was waiting after Shadowsocks and V2Ray got hit. That’s what makes this escalation different from the ones before it.

The technical crackdown was matched by an administrative one. A notice dated April 8, 2026 ordered every IP address under Shaanxi Telecom’s jurisdiction to immediately stop connecting to any external network that doesn’t run through approved channels. The notice explicitly targets “any form of circumvention business,” language broad enough to cover VPN services and proxy routing alike. Providers caught violating it face immediate service termination, permanent loss of their IP allocations, and liability for damages.

That’s a notably harder line than China’s historical approach, which mostly left individual VPN use in a gray zone while going after commercial providers. This notice reads like a template other provinces could adopt, and it’s aimed squarely at the businesses and operators running the infrastructure, not just the traffic.

Machine learning is doing the detection now

The other reason VLESS and its predecessors are having a harder time is what’s sitting behind the Great Firewall itself. Reports describe a shift toward machine-learning traffic classification that looks at temporal patterns, bidirectional data ratios, and connection behavior rather than just packet signatures. Against standard VPN protocols like OpenVPN, WireGuard, and IKEv2, this approach is reportedly hitting near-100% detection accuracy.

That’s a meaningfully different threat model than deep packet inspection alone. A protocol that merely hides its signature isn’t enough if the classifier is watching how a connection behaves over time. It’s part of why protocols that worked well a year ago, and even ones like VLESS that worked well three months ago, keep losing ground faster than before.

Personal use isn’t explicitly illegal, but the risk is real

It’s worth being precise here: personal VPN use in China isn’t explicitly outlawed. The law is written to target providers, payment facilitators, and commercial operators selling circumvention as a service, not an individual tourist or expat checking Gmail. That distinction still holds on paper.

In practice, enforcement has gotten less predictable. In March 2026, police in Hubei province raided individual homes and issued fines for VPN use, in one documented case a fine of 200 yuan, about $29, for using a VPN to access TikTok and X. That’s a small fine in absolute terms, but a home raid over personal VPN use is a different category of enforcement than anything seen at scale before, and it signals that local authorities have more latitude to act than the letter of the law might suggest.

What still works

After this round of crackdowns, the protocols still reported as reliably functional are the ones using advanced TLS-based obfuscation, meaning VPN traffic is dressed up to look identical to ordinary encrypted web traffic rather than relying on a specific protocol’s obscurity. That’s a narrower category than it was even six months ago.

We haven’t independently verified specific providers’ performance inside China right now, and conditions there change quickly enough that any claim needs a caveat attached. What we can say is that obfuscation technology in general is designed to defeat exactly the kind of traffic-shape detection China is now using, which is why providers investing in it are the ones worth watching. NordVPN’s NordWhisper protocol is one example built around this approach; we cover how it works in our breakdown of NordVPN’s obfuscated servers, and our explainer on obfuscation covers the underlying mechanics for anyone who wants the full picture before relying on it anywhere censorship-heavy.

NordVPN is one of the providers we track for obfuscated server infrastructure, though we’d stop short of calling any commercial VPN a guaranteed fix for China specifically. Treat any provider’s China claims with skepticism and confirm current conditions before you travel. Our full guide to VPNs in China tracks which providers still have working servers as the situation shifts, and our guide to VPN legality by country covers how China’s rules compare with other restrictive jurisdictions.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Where this leaves things

The pattern since April has been consistent: whatever protocol is currently working becomes the next target. Shadowsocks and V2Ray fell first, VLESS followed a few months later, and there’s no sign the Great Firewall’s classification system is done improving. Anyone depending on a VPN for genuinely important access inside China should assume today’s working setup might not be tomorrow’s, and should plan around TLS-obfuscated tools specifically rather than whichever protocol happens to be the current workaround of choice.

The personal-use enforcement stories out of Hubei are also worth taking seriously even though the law technically still targets commercial operators. Fines and home visits over VPN use didn’t used to happen at this scale, and that shift in practice matters as much as any technical detail about which protocol got blocked this week.

Our Verdict

VLESS getting blocked is the next step in a pattern that started with April's mass server disconnections and hasn't slowed down. Machine-learning traffic classification is closing the gap faster than new protocols can open it, so the safe assumption for anyone relying on a VPN in China is that today's workaround has a shelf life. TLS-based obfuscation is the category still holding up, but treat every claim about what "still works in China" as provisional, verify before you travel, and understand that even personal use now carries a small but real enforcement risk in some provinces.

Sources: RelyVPN: China VPN Crackdown 2026 | ThroughWire: China VPN Crackdown 2026