Essentially these chips are locked by setting certain flags in memory. Various flags control various peripherals, including a flag to disable read/write access to the firmware. Obviously once you disable access, it’s permanent because you don’t have access to reenable it.
This side channel attack takes advantage of a flaw in the actual silicon, where branches can be skipped if the power is altered momentarily. So if you skip that first check, the attacker has low level firmware control.
(This was also how the firmware was dumped on the Apple AirTags)
The only mitigation is to use a chip that doesn’t suffer from this flaw or change the software to prevent “root” access even if an adversary has access to the entire firmware (ie do things server side)
Of course, the challenge there is that you've merely eliminated one glitching candidate.
Stuxnet had code blocks that encrypted by a hash of target hardware identifiers. No way to know what all code is contained, until it happens to run on the target system.
https://blog.quarkslab.com/bradley-hash-and-decrypt-gauss-a-...
The problem with mitigations is that they are just speed bumps.