Well, looks like I got ahead of myself. The ROM chip in the cartridges is a DS28E01, which is an EEPROM with SHA-1 encryption. You can read whatever you want, but you have to know the secret encryption key to change any values. So this may be a dead-end. I might see if I can find anything about the way they're implementing SHA-1 and figure out if there's a why to hand the machine a new chip with encryption disabled and have it still work. My guess is no, but I'll look into it.