Typically you want to do the lockout for a location, not the user, or you step up the auth level. 3 bad logins -> please mfa before trying again.
But yeah, letting an attacker do that at will is bad. I'm a fan of token bucket rate limiting with exponential back off. You get 10 attempts. A new attempt is added every second. An attempt while the bucket is empty makes that become two, then four and so on.
Most people never notice because a buffer of ten and a new attempt every second just never runs out. If you accidentally hold down enter you're only blocked for a few moments. A dumb attacker quickly locks themselves out forever.