If by "your system" you mean the one PC upon which you are typing your comments right now, the provided you have used a unique password for that system, and only that system, then yes, by the time they have the hash and salt, they've already gained access.
That's a targeted attack, and that is usually not the direction these GPU Hashcat rigs are aimed.
Instead the attacker is merely playing the odds. Those odds being that a rather good number of users of system X (gmail, for example) will reuse their gmail password at another website (Experian, for example).
So they will target that other website (Experian) and when they find a breach, will hoover out the user names, password hashes, salts, and will know the algorithm Experian used (because somewhere in the data trove they hoovered up, the algorithm was indicated).
They will then set their GPU Hashcat rig upon the Experian breach data, looking for input strings that hash to stored hashes from their data. They don't care which individuals, they care that they will find working password inputs for, say, 15% of their breach data. If their experian dataset was for 50M users, a 15% success rate gives them 7.5M pairs to use further.
Then, armed with user names and working passwords from their Experian breach data they set out trying those users and passwords against gmail. They don't trip any "ten tries and you are out" traps because they only do one try per cracked user/password pair. It the user/password pair fails they simply move on to the next user/password pair. But, if the user/password pair works, then they have now breached someone's gmail account, and can now set out about taking over their other accounts (because gmail is often their recovery email for those other accounts). Some of those other accounts will be the crackers real target, those userss banking/financial accounts.
But the crackers don't care who they are targeting, just that 15% of their Experian data will yield useful pairs, and that 15% of those pairs will work when tested on gmail (15% of 7.5M is 1.125M working gmail accounts they can take over). And that 15% of the gmail accounts they breach will have banking/financial accounts they can do a password reset upon (15% of 1.125M 168,750 users). And even if each user yields merely an average of $1k, that works out to a very nice take of $168M for the crackers.