fTPMs also have similar issues. The real takeaway is that if your threat model includes actors capable of executing attacks against BitLocker you need to put a password/pin on it in addition to the TPM.
https://arxiv.org/pdf/2304.14717