Also note that there are plenty of viable attack methods that don't even require key extraction, such as asking the TPM to sign arbitrary data.