I'm one of them :/<p>The haveibeenpwned description says password hashes are md5, which sucks. But phpBB has used bcrypt by default since version 3.1 (2014)... I wonder if all the hashes are md5 or only those for older accounts?<p><a href="https://haveibeenpwned.com/PwnedWebsites#XKCD" rel="nofollow">https://haveibeenpwned.com/PwnedWebsites#XKCD</a>