In only 0x100 bytes of ROM that is so simple, there’s unlikely to be too many software bugs that allow dumping. Decapping a chip and imaging it isn’t cheap either. The hardware mechanism for locking the boot ROM may be hard to figure out without having the boot ROM already. And given how simple and effective the hardware mechanism is, it, too, is unlikely to have any obvious flaws to exploit.
So they didn’t exploit flaws, they just tried to work around the protection.
Even though the Gameboy is relatively slow (~4.7 Mhz processor IIRC) it’s still not going to be easy to hit exactly at the right time to be able to perform your fault injection.
The protection is simple enough to be effective. If you did it with a modern manufacturing process it’d probably be quite difficult to be able to image the bits directly...
Nowadays, for say Nintendo Switch, you are more likely to see keys and firmware data dumped via early boot exploits or privilege escalation.