Three attempts to verify the PIN and the PIN is blocked. Three attempts to verify the PUK and the PUK is blocked. At this point the only option is to reset the PIV applet. Management Key is the only thing that can hypothetically be brute-forced, but the person with the management key can't use the certificate that's stored on the YubiKey. They would have to generate a new one to use the key. All scenarios are basically covered on our developer website. Recommend you start with
https://developers.yubico.com/PIV/Intro ... ccess.htmlThere is no way to render the PIV applet completely useless (otherwise lots of customers will experiment, lock the PIV applet permanently, and demand a replacement). This isn't like a basic smart card where you lock it and you have to throw it away and buy another one. There are several other manufacturers that offer those.