

The MIG isn’t “any random cart”, it needs to be running its own firmware on its CPU to “defeat” the Lotus (cart slot) firmware’s security measures. And “defeat” is in quotes because what it’s actually doing is supplying the authenticator with the actual key it wants. It doesn’t “bypass” or “unlock” the console, it sends a real key to a real door in a way that “looks” identical to what a real cart would do. That key isn’t part of the ROM either, it’s a per-copy unique key that decrypts the ROM portion of that cartridge. You can’t take a key from one game and use it to unlock another, so MIG compatible (MIG generated) dumps need to also have the ‘key’ dumped. You also can’t use a MIG to run custom/modified code in any way, since no custom code has a valid auth signature. It’s only usable for spoofing a retail game cartridge.
Nintendo even tracks the usage of each unique copy of a cart on their backend, and uses some form of check to permaban “pirates’” entire consoles from online features. We don’t know exactly how this works, if it’s “this key is in use in two places at once” or “this key has been used by 1000 consoles” but there is evidence that shared MIG dumps do cause console bans. This theoretically also means bans for legitimate used copies could be issued: if I go to the GameStop and buy Mario Odyssey and dump it with a MIG, then share that dump online and it becomes “the common MIG dump”, then sell the game back to GameStop, the dude who buys that used copy will get “caught” as a pirate if Nintendo uses “played that specific copy of Mario Odyssey” as a ban criterion.
The firmware and CPU architecture on the MIG are proprietary and complex, which is why it’s currently just MIG and not “any random cart”.
The MIG cannot do any of that “other stuff”. Its only use case is piracy (technically, its only dubiously-legal use case is backing up your owned cartridges). The only code it can cause the Switch to execute is signed, official Nintendo code, exclusively when paired with a valid cartridge key. It can’t be used for music playback or emulation or alternate desktops or as an entry point for custom firmware or for homebrew applications. It can’t even load game updates or DLC. Your memory of DS carts is irrelevant, the MIG is a completely different type of product.
RCM on the Switch enables piracy (of dumped games from carts) and homebrew/emulators and mods and cheats and piracy of non-physical games/DLC. The MIG only enables piracy/backups of physical games and can never do anything else. You can’t even do save-based cheats with a MIG since the saves are stored on the console.
You criticize Nintendo’s security for “letting any random cartridge run software” when actually the Lotus firmware is still one of the most secure parts of the Switch. RCM access is a holy grail exploit and even with it supercharging any Switch reverse engineering for the whole console’s lifespan, the MIG is the only known thing that can pass a pirated game through the Lotus. And the MIG released really late into the Switch’s life cycle, so it required a ton of engineering to make. It’s nothing like the flashcarts from the NES-DS era at all. There is an analogous product to the MIG for the 3DS called the Sky3DS which similarly could only play pirated cartridge dumps and not be used for any custom code (though with the history of 3ds hacking, the Sky could be used for game-based entrypoints to full CFW like ninjhax or oothax).
I don’t know what your thing about playing old carts is supposed to mean. If it’s not clear, I’m pro homebrew and backups and believe that piracy (specifically, the defeat of DRM) is the only way to preserve software in any meaningful way. The MIG isn’t a product I use or own, my Switch is a first-gen with the bootloader vuln. Those Pokémon carts also “held up” fine? The save file is vulnerable to battery death but the cartridge still “works” and there are methods to back up the save file or even perform a battery replacement without damaging the save. But that’s got nothing to do with the MIG or the Switch.