Your authentication is not built to stop it. Relock is.
Over 90 billion stolen browser cookies are circulating on criminal markets. Harvested through XSS or a malicious browser extension, a stolen cookie loads straight into the attacker's browser and drops them into an authenticated session — no login, no MFA.
Industrialized by widely available infostealers like LummaC2, RedLine, and Vidar, these attacks lift the entire authenticated client state. The exfiltrated material often includes access and refresh tokens — letting the attacker persist well beyond a single session.
The most complete session attack. Alongside the stolen session, the attacker clones the victim's device fingerprint and replays it all through an "anti-detect" browser. Sold as ready-made IMPaaS packages on criminal markets, they slip past even the strictest fraud and device controls.
An all-too-common phishing technique: the attacker runs a live proxy between the user and the real service. When the victim signs in, the proxy grabs both the credentials and the authenticated session. Available to anyone as PhaaS kits like Tycoon 2FA.
Across three real-world attack scenarios, the vast majority of top software products could not tell apart a stolen session from the real user.
See all findingsRelock prevents the use of stolen sessions in any application.
Compare it against your current defenses and what we see in the field.
With Relock
Relock binds each session to the legitimate device.
It uses a system of cryptographic keys that are deployed directly to the browser, invisibly to the user and without any interaction. Any attack that attempts to replay session material is stopped and immediately detected.
Full prevention and direct visibility
Relock cryptographically binds each session to the device, preventing attackers from weaponizing stolen tokens.Relock cryptographically binds each session to the device,
preventing attackers from weaponizing stolen tokens.
Relock issues each browser a cryptographic anchor of trust that cannot be reused or replayed. The keys are verified by Relock server at access and throughout the entire user journey.
The system is deployed server-side only, with no changes to the application. User adoption is instantaneous and requires no separate installs, browser extensions, or education.
Trust is continuously renewed and validated at each request. The cryptographic keys change each time they are used, not relying on static secrets and ensuring inevitable attack detection even if compromised.
Log in to a Relock-protected application.
It is an open space for defenders to see session security in action, run real-world attack scenarios, and test your apps.
