---- Data corruption investigation and fix attempts ----
There were basically a few bytes that changed its value, in second half of the address space.

I tried several times refreshing FRAM and cycling the meter, and much more frequently it failed when I was reading CAL constants, however without that it failed too, just with much lower chance.
I hooked logic analyzer, and it was obvious - digital levels were bouncing all around when powering off the meter. And after CAL constants reading memory chip was left with #CE=0, rocketing the chance of failure.
Thus, on power off we were writing data. The speed of FRAM chip and the fact that it works from 2.7V likely made this situation worse that could have been. But verdict is obvious - we cannot use FRAM as is with just converted C0 C1, need something else.
Next ides is obvious - ER3400 needs -30V for programming, and I verified that it's hooked up only at the moments of actual programming.
Thus, our schematics is getting a little upgrade - a mosfet that protects #WE from going low when -30V is not present.
Maybe not the best solution overall, but I wanted something simple, with parts I can reach. Very likely some very clever power supply monitoring IC should have been used instead, but I haven't tried this path.
(values are semi-random, likely not the ones I tried, I'm sure there are better combinations)

(actual photo, from first further attempt to condition #CE as well)

Wired. Let's test - and it worked ... for some time ... until it didn't fail again.
Similar failure, similar corruption.
Here how it looks like (I took some scope captures, no necessarily at exact corruption time, but something for reference better than nothing).
(Yellow: -30V, green: #WE)

(Yellow: -30V, green: +5V, blue: #CS at 1.5V)

And here we came to maybe the most strange part - implementation of this -30V supply and how it's hooked.

Eventually I spent quite some time looking at power off sequences, and how those glitches look like.
What we see is +28V line goes down, and D804, Collector-Base or TR804 and D805 become just 3 diodes in series, eventually pulling charged capacitor C804 to ground.
This way on power OFF ER3400 is actually supplied with -30V for a short period of time.
NOTE: When I was discussing all this wonderful situation with one person, they came up with awesome statement/idea - what if all this original ER3400 sudden 'death/corruption' was exactly this little chance of getting 'all stars aligned' - C0, C1, #CE, -12V and -30V in a way that initiated chip erase. That will exactly generate a garbage in it. That's insane still very viable theory.

Ok, so looking at -30V to protect #WE is useless. What else we have - -12V supply. Looking at pictures from the scope it was more or less consistent between how 5V and -12V disappear. -12V rail only has 1uF capacitor, so it goes to 0 much quicker than -30 or +5, so I still had a chance.

And I tried the same 'solution' as with -30V. Just in case of -12V what I didn't like from the very beginning is voltage margins.
What I didn't like is mosfet voltages margins. Vgs is usually -2V, for most of mosfets I have. So we need our gate to sit at least -2V in order to operate properly. With -12V it means I need 5V to disappear, so -12 + 5 = -7V.
But in order to reliably protect my #CE I need Source voltage to remain 3-4V to represent good logic 1. And so gate should be 2-3V to guarantee that. And this 2-3V is -3-2V at -12V line - almost when -12V hits ground, very long time from shutdown start. Still I decided to give it a try.
I did a lot of power switching activity, and even unfortunately broke original switch

(((

, but finally caught a failure - so this still does not work well enough.
Unfortunately at this point I'm not sure, whether it was just bad idea completely or it's all because I picked up (from what I only had) wrong mosfet - it had too high gate capacity.
And I never tried different mosfet - went straight to better version that use 2 mosfets - one protecting #CE and the other applies gate voltage.

So far this seems to work, at least I wasn't able to break it yet. Unfortunately that's the best I can tell, not 1000% guarantee.