SHRINCS: 324-byte stateful post-quantum signatures with static backups

That would be a nice simplification indeed, but if you restore a disk backup (with an old wallet state) on the same machine, the TPM would still have the decryption key or XMSS key. What would prevent reusing that old state for signing?