Can you verify if the traffic really leaves WAN? The log with accepted packets just indicates it tries to push these packets via the correct rule, no matter if gw group is down or not.
Second test would be to add a rules to Wireguard gateway explicit, not the whole group, and try to reproduce.