When sniffer starts, fasttrack is disabled. Which means that your fasttrack rule doesn't take into account that traffic flowing through wireguard tunnel should not be fasttracked or else it gets sent out through wrong interface (the physical WAN interface).