See https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...
"8x Nvidia GTX 1080 Hashcat Benchmarks"
TL;DR:
Hashtype: MD5 Speed.Dev.#.: 200.3 GH/s
Hashtype: SHA1 Speed.Dev.#.: 68771.0 MH/s
Hashtype: bcrypt, Blowfish(OpenBSD) Speed.Dev.#.: 105.7 kH/s
Hashtype: scrypt Speed.Dev.#.: 3493.6 kH/s
Hashtype: PBKDF2-HMAC-SHA512 Speed.Dev.#.: 3450.1 kH/s
Hashtype: PBKDF2-HMAC-MD5 Speed.Dev.#.: 59296.5 kH/s
You can't protect against people using "password123" or "dadada" as their passwords, but for those of us using long randomly generated passwords bcrypt makes cracking it well outside the realms of possibility for anyone short of nation-state attackers. (I bet the NSA can get quite a lot more than 100kH/s for bcrypt if they're determined enough, but I wonder if even _they_ can throw 6 orders of magnitude more compute at the task?)