As far as I’m aware, that works the same as things like tailscale is doing, where you need at least one node that is publicly reachable to facilitate.
tinc: One public node, thousands of private nodes, with NAT punching. That's fine and typical in my experience.
So yes it is a differentiated thing between wireguard and tinc, as you phrased it in your other comment.