State of the art SoC with silicon baked private keys laser fused for production configuration
Not sure why you're calling this non-unlockable. Everything is unlockable with enough money.
Maybe we use some hardware-level trick to get to some protected firmware initially to reverse engineer it, but almost universally it's what reads the state of the fuses (or something after it) that actually gets exploited. That's changing, too, but in general very slowly and at at the pace of hardware manufacturers learning how to make software (aka, glacial with a few notable exceptions).