The best I've been able to come up with is bcrypting the md5's. But unfortunately, while bcrypt^-1(ALL STRINGS) is hard to compute, it's not clear that bcrypt^-1(range(md5)) is. I see no compelling reason why it wouldn't be, but I don't know enough about the subject to offer a strong claim.
Can any experts offer advice on this?
(I'd also replace the `bcrypt . md5` password with a regular bcrypt one after the user authenticates.)