They don't need to write anything. They just need to impose an increasing delay after every failure when the code is being supplied via USB or bluetooth. First failure, wait two seconds, fifth failure wait 30 seconds, eigth failure wait 90 seconds.
If they really wanted to write it to flash, they could make it so that the first failure isn't written at all, the second has a 50% chance, the third a 100% chance.
Or make it so that if the device has only been running a short period of time, then all failures require a thirty second wait until you can retry.
There are plenty of ways to make it impractical without necessarily reducing the lifetime of the device.
If they really wanted to write it to flash, they could make it so that the first failure isn't written at all, the second has a 50% chance, the third a 100% chance.
Or make it so that if the device has only been running a short period of time, then all failures require a thirty second wait until you can retry.
There are plenty of ways to make it impractical without necessarily reducing the lifetime of the device.