I guess it depends on what version you are talking about.
Classic used a flat file system and did not encrypt anything.
According to the change logs Threads 6.x at first used php crypt before going to MD5. I never used the 6.x threads series.
But I would think they should have been converted to md5 if you have a newer version since then. Maybe the users you have problems with have not visited your site since 2001. So their passwords have never been rebuilt.