I think OP is asking "In the worst case scenario of a malicious instance owner that is able to fork the Lemmy codebase (so could disable hashing) and intercept and record all communications going to and from their instance, what risk do I have as a user of that instance?"
The answer of course is yes, in theory a malicious instance owner could see the password you use and can see all your communications, votes, what you look at, etc. So use a unique password for that instance, and don't use the instance for private communucations whose interception could seriously harm you.