I believe Lemmy has rate limits for requests by default, so it's not as easy to brute force a password as you suggest. But something like this is always a good feature for additional security.
I think forcing the user to reset their password because someone is trying to guess their password probably doesn't make sense unless they got it right. It would be annoying if a troll did this to your account.