https://www.bleepingcomputer.com/news/security/tpm-chipsets-...
https://crocs.fi.muni.cz/public/papers/rsa_ccs17
It is really hard to see this as anything other than a bugdoor.
My laptop has this TPM chip. I am really glad I never used it, and even went so far as to disable support for it when I built my coreboot image.
Products sold with the buzzword "trusted" are a magnet for this sort of garbage. They've painted a "please bugdoor me" target on their back. The only thing you can hope to trust is general-purpose computing devices, with a large market, that obey their owner. Unfortunately it is increasingly difficult to find those.
Most FDE schemes don't run crypto ops on the TPM itself - key derivation occurs there, then the results are cached in RAM ( or sometimes, protected CPU registers, in which case they may be able to inject privileged code into the kernel address space? ).
LUKS on a colo will probably protect you if you're a fentanyl distributor or movie pirate. Probably not if you're a terrorist or a high-value nation-state target.