They literally freeze them with liquid nitrogen, which makes them preserve their state.
AMD calls that SME for example. https://www.amd.com/en/developer/sev.html
> The key is generated by the AMD Secure Processor at boot.
Wouldn't this key _also_ be accessible? Maybe not on the same _chip_ but it's still at some level in a memory chip somewhere, they would just need to find it?
This type of system has been used pretty successfully for nearly a decade on the AMD SOCs used in the XBOX consoles.
Look up Christopher Tarnovsky talks from Black Hat 2009, Black Hat 2010, DEF CON 20, hardwear.io 2019.