The minute the device was released in North America the lockout chip was already defeated by passthrough devices that took a "real" game and used that for the CIC bootup process. There were also multiple variants of voltage spike attacks and revisions of the console to guard against those, so it was certainly happening otherwise Nintendo wouldn't have wasted time changing the design.
Also, look at the timeline and the history behind Tengen which was essentially a company created by Atari specifically with the purpose of publishing their games on Nintendo and used essentially corporate espionage to get the underlying MPU used for the CIC logic that was a corporate secret. The actual lawsuits get filed a few years once Nintendo had enough evidence, but it was going on from the start of the lifespan of the console.
The NES was released in North America in late 1985. By 1987 there were commercially available games (from Tengen) that were playable without the permission of Nintendo. Tengen was not the only one or even the only method being used to break that console at that time.
And then there is Game Genie, which effectively can work around all of these problems. Sure, they included some logic to play nice and let the NES check the CIC again, but you can work around that with a game genie code itself! In the early days Game Genie and GameShark devices were well known for being vectors for piracy and they leaned into that.
*EDIT* This doesn't even get into the VAST array of devices that existed to clone cartridges or adapt floppy drives similar to how the Famicom did. At worst those required a stupid dummy cart to sit in them that never gets removed or the manufacturer did that for you and put a CIC in the device. Some used various attacks mentioned earlier to work around even having to do that.