I have an IBM Thinkpad with Coreboot installed. I use Linux and know my way around basic command line stuff, updating, installing apps etc. Would I be able to safely reinstall/flash Coreboot without any serious risk of bricking the laptop? Where do I find instructions for this?

Also, why aren’t all Bios write protected? Give the amount of bios vulnerabilities that can persist through OS updates and apparently even bios updates in some cases, this seems like an obvious security mitigation that would have been made standard a long time ago?

What is the model number of your Thinkpad? It is hard to point you to instructions without that.

Yes, it should be possible. Try this:

On Librem 14, there is a hardware kill switch for that. And also TPM with Librem Key for verification.