The passcode is 'entangled' with a per-device 'UID' that only exists in silicon, not accessible by any firmware.
It seems that the current GrayKey attacks are closer to ~1s/guess.
My last post on the topic: https://news.ycombinator.com/item?id=16833802
[0] Page 15 https://www.apple.com/business/docs/iOS_Security_Guide.pdf