Sounds like it would have also worked to replace the hard drive with an own one where the OS directly gives a root shell to read the TPM secret.
The solution is to bind the TPM secret to a measured boot state, but that requires a way of precalculation of the expected measurement values. Read more about signatures for these precalcuated measurement values here: https://0pointer.net/blog/brave-new-trusted-boot-world.html (TLDR: The publishing of prebuilt OS vendor kernel+initrds and signed PCR policies allows to bind the secret to the signature being valid, so that it still works when auto updates change the measurement as long as the vendor signature is also there.)