Thanks for the hint. From the paper it seems it's highly implementation-dependent which drives can be compromised and there's no immediate way to tell. Still it seems OPAL 2.0 is good enough to deter data leaks in case of theft (excluding targeted attacks).