My impression is that the Dev Team is always looking for a bootloader exploit so that they can permanently pwn the 3G/3GS, but that CPICH and others have been through the thing pretty thoroughly without success. The bootloader is a very small bit of code, with correspondingly few opportunities for exploitation.