Why? Just release Graphene without those security requirements. It must be a user's choice and responsibility. You sound exactly the people you fight against.

You understand that just having a firewall is a big step for security?

Diverting a massive amount of resources to devices where we can never provide decent updates and our core security features doesn't interest us. It would reduce the privacy, security, usability, app compatibility and robustness of GrapheneOS for users on the officially supported devices. It would also result in many people getting insecure devices. Many people would get those devices and then realize they made a poor decision later. We already see this happen with devices approaching end-of-life and already have to put significant work into avoiding people getting those.

GrapheneOS is permissively licensed so that people can do exactly that (and fork for different hardware platforms) if they want to. It is a donation-supported open source project with a small team, and it is not a crime or moral failing for them to put those resources into doing the best that they can, instead of spreading themselves thin on something they cannot be motivated or proud of.