Why not use lazy rehashing? On login, the password is availible and so can be rehashed properly.
BCRYPT(MD5(Password))
Running BCrypt or SCrypt over the current MD5 hashes is easy, and they can do it right now for every password. If someone (else) grabs the database in ten days time they get no MD5 hashes of passwords instead of half of the userbase.They send a token hashed with the password and they have to keep the original md5'd password on file in order to allow these clients to work.