I work on secure elements.
The secure elements used by the Mk4, one of them is a dated platform that had a low security level even at the date of release.
The other is also in the same bucket, and to make it worse is made by a company with low SE experience.
MCUs are trivial to extract secrets from, there’s more documented attacks than I can count.
It doesn’t matter if you could easily execute a supply chain attack though, which you can.
