I believe the 0xBFC0 RAM is scrambled inside of the IPL. Every IPL performs "*(u32 *)0xBC100004 = -1;" and on 2.60 upwards this is not done until after the gzip payload is decrypted and the 0xBFC0 RAM is zeroed - it appears this write tells the CPU to kill the hidden boostrap data. The dum...