MFA guards the login; infostealers steal the token issued after it. How sender-constrained tokens (DPoP, mTLS, DBSC) make a stolen session inert.