Hi Daniel, I hope you're doing well!
Are you using KW41Z? If so, could you please take a look at this community post here?
The sniffer log you provided and the one discussed there look very similar, so the problem could be related to the same issue.
Like the answer in the post describes, the issue could be related to the Link Key not being erased for the device, and the device not being able to decrypt the Transport Key command. If the command is instead sent with the default trust center link key, then it will be able to decrypt the transport key command.
Please let me know if the fix described in the answer doesn't work for you.
Best regards,
Sebastian