I recovered from the "black bar instead of Nintendo" failure on EZ Flash Jr. by desoldering and reprogramming the U2 SPI flash chip. My silkscreen says 25Q40H, but the JEDEC ID reads as an EON EN25F40. I saw images of other ez flash jrs that use a Puya P25D40 as the U2 chip.
The flash holds two copies of the FPGA bitstream: "Slot A" at $00000 and "Slot B" at $40000. In my dump they're the same design, differing by only 8 bytes, all in the tail. Confirmed that Slot B matches the FW4 updater payload. Slot A is maybe an older/factory copy the update left alone. (One dump's worth of evidence. Whether other updaters touch Slot A is unknown, and the FW5 updaters carry entirely different bitstreams.) The FPGA boots from Slot A at address 0, and Slot B's purpose (chain-boot target, fallback, or update staging) is unconfirmed. There's definitely no automatic fail-over: my intact Slot B never got used, and with Slot A's head damaged, configuration never starts.
The failure had erased exactly $00000-$0FFFF, leaving Slot A's tail intact. Since the slots only differ in the tail, the fix was to copy Slot B's head at $40000 over the erased 64K and resolder. Copying Slot B wholesale over Slot A does not work (the tails aren't interchangeable), so the repair has to be minimal. I used a T48 programmer, writing the FLASH region only, leaving STATUS/CFG untouched.