So 128 bits? I'd guess they wouldn't use md5 (or any of the md family), which according to wiki leaves haval/ripemd/tiger. I'd go for ripemd-128 (on what the wiki says) although you would expect them to use a NSA blessed algorithm.
I don't think they're expecting it to be cracked, per se, just guessed. I don't have to have defeated the SHA-256 algorithm to find your hashed password in a rainbow table.