They'd only need to make one payload that keeps the TPM happy, unlocks the disk and provides the files for export some way.
Far safer than a backdoor and no evidence.
But the slop in your comment here indicates you're arguing in bad faith.