There is a hard limit of 80ms per attempt, from the number of PBKDF2 iterations tuned for the secure enclave.
It certainly seems like GrayKey bypassed a fundamental SEP protection, which would constitute a very serious flaw. The SEP protections are supposed to be a whole 'nother level (which is what this article gets at.. it's Hard to even get at the firmware).
If that aspect of the SEP is compromised, what else about it is? This is extra disturbing because Apple's "fix" was to disconnect unauthorized peripherals -- not, apparently, a fix to the SEP itself. This is why I am stunned there was not more coverage of this. It's smoke that indicates a really fundamental flaw in the SEP.
[1] https://www.apple.com/business/site/docs/iOS_Security_Guide.... (page 18)