This hack seems to affect the Dropbox Sign application, which is based on HelloSign which they acquired a few years ago. It’s still running on the hellosign.com domain and seems mostly separate, so it wouldn’t surprise me if they also store passwords differently.
Useful because you can support existing passwords without requiring everyone to login or reset their password. Still has flaws though, like password shucking.