I suspect that they attack the loader rather than NCK.
If NSK is 16 decimal digits long we need 10GMIPS*(instruction_per_checking_the_NCK) to break it in 10 days.
It can be realized e.g. with PLD hardware or distributed attack with
help of the Internet community. So, the vital question is if the NCK checking code exposed in the firmware.