A researcher found that the communication lanes between the CPU and external TPM are completely unencrypted on bootup — enabling an attacker to sniff critical data as it moves between the two units, thus stealing the encryption keys.
I say its more likely the researcher found article from 2019 https://pulsesecurity.co.nz/articles/TPM-sniffing describing this very attack vector using FPGA dev board. The only novel thing here is price point going down by a factor of x10 to $5-10.