I like this, and I suppose it's a shame a Rasp Pi can't be WOL'ed.
But could another SFF single use/secured device on the same network that doesn't have FDE, also provide that key only if and when you wake it up (manually decrypt the file after ssh'ing into it too?) instead of having a USB drive directly plugged into the main server so, if a nefarious person does have away with the main bounty they're fugged without said second hidden device on the same network?
ninjaedit: I also at one point in the past did Wireless WOL (wireless NIC's with WOL were prohibitively expensive at the time of me playing) via a Travel router that was acting as an Access Point, simply to wake up forward the magic packet. You could really hide that thing π
That would be neat.
Like someone else said in here maybe the OP could use a really long cable to a USB drive away from the main server, but I do like the idea of something using hybrid wire(less) to auth.
They could even have a UPS underneath a Pi Zero and, have a PoE HAT too + travel router. Plug in LTE USB with backup SIM card, epoxy all that together and then hide it?
lol, paranoia fixed.