You could specify a nested wireguard protocol to allow connections through existing wireguard tunnels. Then you can do something like TOR eventually. I wouldn't do it straight away, I'd just limited the packet size to allow for encapsulation without fragmentation.