Well I guess AMD/Intel/Qualcomm/Infineon/Google people are at the greatest risk, with places like TSMC also in play. Infineon TPMs and smartcards in particular had so many flaws that I wonder if it already happened. Also, note that even if you don't have the keys you may still control the implementation, and potentially introduce flaws. Keep safe.
Is this is meaningfully different than the risk to any engineer working in security on ~central infrastructure?
> even if you don't have the keys you may still control the implementation
The sorts of places that care about remote attestation also care about insider risk.