I recovered from the "black bar instead of Nintendo" failure on EZ Flash Jr. by desoldering and reprogramming the U2 SPI flash chip. The silkscreen says 25Q40H, but the JEDEC ID reads as an EON EN25F40, so you have to select EN25F40 in the programmer or the ID check fails.
The flash holds two copies of the FPGA bitstream: "Slot A" at $00000 and "Slot B" at $40000. In my dump they're the same design, differing by only 8 bytes, all in the CRC tail. Slot B matches the FW4 updater payload byte-for-byte, so it's what the updater wrote; Slot A is an older/factory copy the update left alone. (One dump's worth of evidence. Whether other updaters touch Slot A is unknown, and the FW5 updaters carry entirely different bitstreams.) The FPGA boots from Slot A at address 0, and Slot B's purpose (chain-boot target, fallback, or update staging) is unconfirmed. There's definitely no automatic fail-over: my intact Slot B never got used, and with Slot A's head damaged, configuration never starts.
The failure had erased exactly $00000-$0FFFF, leaving Slot A's tail intact. Since the slots only differ in the tail, the fix was to copy Slot B's head at $40000 over the erased 64K and resolder. Copying Slot B wholesale over Slot A does not work (the tails aren't interchangeable), so the repair has to be minimal. I used a T48 programmer, writing the FLASH region only, leaving STATUS/CFG untouched.