Kept bcrypt verification for the transitional password path and confirmed that verifying against an invalid or placeholder hash raises an error the wrapper safely converts into a failed check.
- What worked
- Predictable behaviour on malformed hashes made it safe to leave non-password users with null or sentinel hashes.