- Last I checked, dynamic server IPs were not supported
- It's system wide by default. With all VPNs, it is relatively difficult to say: use this connection for these applications, or these addresses. Popular VPN apps have per-app-settings, but I find them buggy and not trustworthy. And if you are an expert you can set your own routing of course. But it would be great if you could just right click on a titlebar and say "use VPN for this app", and it was integrated with the OS
- There is no obfuscation for hostile environments. I would like a VPN which has pluggable transports, and can, say, look like ssh or http or a game, and route over 20 random servers. I know of shadowsocks etc., but I could never get it to run.
- There is no integration with Windows login AFAIK. If you want to log into a Windows AD domain, you need to be in the VPN, but you can't establish connection when you are not logged in. This is really annoying. There is a capability in Windows for this, but I never found a VPN where it works properly.
So technically WireGuard is great, security and speed wise, but for me the potential VPN killer application would be defined by superior UX, not by tech.