[deleted] the initial question was answered.
Nobody can give an 100% correct answer on what can be done against pixel in AFU mode. Because it can change right now.
The only 100% correct answer is make sure to always have control of the state the device is in. Use it only in AFU mode when you can make sure you are the one that can change it into BFU.
BFU with 128 bit of random entropy pass isn't possible to decrypt without the password.