“Most TPM2 unlock setups fail to verify the LUKS identity of the decrypted partition.”
Linux TPM2 auto-unlock trusts whatever partition shows up. Swap in a fake LUKS volume with a known key and a malicious init, and the TPM hands over the real key. Ten minutes of physical access does it. The fix is a TPM PIN, which brings back the password the setup was meant to remove.