Indeed this has been done: someone programmed an RPi/Arduino to cut power to the phone after PIN verification and before the PIN attempt was persisted. This effectively defeated rate limiting and the 10 attempt limit. However I believe that was the 5S, and that seems like a fixable bug (record the PIN attempt before verifying the PIN).
Yep, it was patched: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451