I know Keybase (http://keybase.io) uses scrypt, but that's the only one I know of off the top of my head.
IMHO, MITM would be better defended against using HSTS, certificate pinning, and perhaps DNSSEC.
I assume the extra client-side hashing is done to keep the plaintext passwords out of the application memory, not protect it in transit.
To clarify, this is just an assumption. I have not read up on the topic nor do I claim to be a security expert. This is just what came to mind when I had the same thought as you.
Anyone else know for sure?
Meme reference aside, this is actually a sane way to do things.