Dear All - Your passwords should be considered compromised. Hashing is merely a deterrent, it does not prevent cracking.
6500 bcrypt(5) hashes/second with custom FPGA: http://ieeexplore.ieee.org/xpl/login.jsp?tp=&arnumber=703252...
But dictionary and password list-based attacks are expected to be quite effective anyways.
http://www.openwall.com/presentations/Passwords13-Energy-Eff...