This time we actually manufactured an adapter/breakout PCB so that we did not have to solder on the CLARN board.
After much data logging and analysis we could see that the protection was similar to that of Moto Frenzy but also significantly harder due to the fact that they would dynamically change the LSB byte of the LFSR polynomial several times a second.
Finally after months of hacking we fully broke the whole protection system