Day 512. While the shit from day 511 somewhat makes sense (traffic from the #Azure VPN Gateway is forwarded traffic after all), the description in the Azure Portal is highly misleading and there is no documentation available for this behavior.
This will blow up in your face if you always only had Gateway Transit enabled on peerings and you decide to disable Gateway Transit. Now you're stuck troubleshooting why your indirectly peered VMs can no longer talk to each other.